possible attack - Installation 7Rc not finalized

I confirm the problem reported by Eli. You can not finalize the installation of 7.0 RC (but also happened with the latest beta version) due to a possible attack in progress. My Bluehost hosting is the U.S. Bluehost. I look forward to your instructions. Greetings from Italy

Quote · 13 Nov 2009

Thanks man for confirming that :) , what a releif ouch !

Thank you very much .

Eli.

Proud Hosted by Zarconia.net
Quote · 13 Nov 2009

We hope to soon have a solution to the problem because we are almost at the point of departure. I believe that the safety precautions recommended by the expert consulted by Bonnex have damn complicated the path of this blessed dolphin 7, waited almost like the return of Jesus

 

Quote · 13 Nov 2009

lol man the same as here , am getting stressed in one point here , i did already report this bug befor the release of RC1 but no one did anything about it !

let see if this time thing's are going to get better !

Eli

Proud Hosted by Zarconia.net
Quote · 13 Nov 2009

here is the report of what happened during installation (Installation not finalized):

 

Total impact: 12
Affected tags: sqli, id, lfi

Variable: REQUEST.seIM_userConfig | Value: {\"enableAudio\":true,\"enableTimestamp\":false}
Impact: 6 | Tags: sqli, id, lfi
Description: Detects classic SQL injection probings 2/2 | Tags: sqli, id, lfi | ID: 43

Variable: COOKIE.seIM_userConfig | Value: {\"enableAudio\":true,\"enableTimestamp\":false}
Impact: 6 | Tags: sqli, id, lfi
Description: Detects classic SQL injection probings 2/2 | Tags: sqli, id, lfi | ID: 43
Centrifuge detection data  Threshold: 3.49  Ratio: 2.5

REMOTE_ADDR: XX.XX.XX.XXX
HTTP_X_FORWARDED_FOR:
HTTP_CLIENT_IP:
Quote · 13 Nov 2009

mostly the same report as mine ! hopefully they will fix it .

Proud Hosted by Zarconia.net
Quote · 13 Nov 2009

Have you read the install documentation? I guess no, It sugest to disable mod_security, get yourself a VPS or Dedicated Server, they are cheap nowdays

Quote · 13 Nov 2009

 

Have you read the install documentation? I guess no, It sugest to disable mod_security, get yourself a VPS or Dedicated Server, they are cheap nowdays

 I am not an expert but I've never had any problems like that with dolphin, with both versions 6 and 7 (at least until beta 7). With regard to the installation documentation if you are referring to That Which applies also 6x version, then I will point out that my php.ini is configured PRECISELY  comply with those directions. But if there is a specific installation manual for version 7, then indeed I am not aware.

Quote · 13 Nov 2009

Have you read the install documentation? I guess no, It sugest to disable mod_security, get yourself a VPS or Dedicated Server, they are cheap nowdays

Check my post about Possible Attack and try that and let me know if it does show possible attack for you or not then if not i will get my self a VPS or dedicated server !

Proud Hosted by Zarconia.net
Quote · 13 Nov 2009

im on VPS, how do i disable mod_security?

Quote · 14 Nov 2009

only attack im getting is when using f.fox

ie opera chrome works fine

Quote · 14 Nov 2009

Installation completed using the Firefox browser. But if I try to rerun the installation with Explorer 8 (a mess, I know), the operation is not finalized, signaling a possible attack. Although I have solved the problem with some changes, I think the question should nevertheless be taken into consideration and resolved.
As I imagined, the problem does not affect the security settings of your server, but rather those of dolphin 7.

Quote · 14 Nov 2009

No comment

Hi Eli!  What's up?

Well I am having a lot of issues with anything that Dolphin has with a 7 LMMFAO

Anything in 6 all works.  so I will just wait until they have something stable.  The RC isn't stable.

Quote · 14 Nov 2009

No comment

Hi Eli!  What's up?

Well I am having a lot of issues with anything that Dolphin has with a 7 LMMFAO

Anything in 6 all works.  so I will just wait until they have something stable.  The RC isn't stable.

RC (Release Candidate) versions are not stable public distribution-ready solutions. Want stable and virtually trouble-free D7 solution for your site? Wait for Dolphin 7.1.1. Should be awesome.

If you are having "a lot of issues", please report them properly so a ticket can be created.

Hijacking topics intended to focus on problem-solving and using them to rant on how stable a final version of the software vs an RC is does not help. These forums are already a mess to navigate and organize information.

There are a few of us who are actually investing a bit of time trying to follow-up on bugs, and it is nerve-racking to see how topics get distorted with posts like these.

Rant all you want, but please, do so in your own threads and blogs. Please.

Quote · 14 Nov 2009

here is the report of what happened during installation (Installation not finalized):

Total impact: 12
Affected tags: sqli, id, lfi

Variable: REQUEST.seIM_userConfig | Value: {\"enableAudio\":true,\"enableTimestamp\":false}
Impact: 6 | Tags: sqli, id, lfi
Description: Detects classic SQL injection probings 2/2 | Tags: sqli, id, lfi | ID: 43

Variable: COOKIE.seIM_userConfig | Value: {\"enableAudio\":true,\"enableTimestamp\":false}
Impact: 6 | Tags: sqli, id, lfi
Description: Detects classic SQL injection probings 2/2 | Tags: sqli, id, lfi | ID: 43
Centrifuge detection data  Threshold: 3.49  Ratio: 2.5

REMOTE_ADDR: XX.XX.XX.XXX
HTTP_X_FORWARDED_FOR:
HTTP_CLIENT_IP:

Where exactly do you get this error ? What module were you installing  ?

Rules → http://www.boonex.com/terms
Quote · 17 Nov 2009
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.