Page 2 of 2 FirstFirst 12
Results 21 to 32 of 32
  1. #21
    Join Date
    May 2007
    Location
    Cambridge, UK
    Posts
    1,593

    Default

    The way I would suggest doing it would be to have some kind of forum entry or similar saying something like if you are having security/error issues with a CMS find more info here. Basically, in that section say google the program name and the error - that's the way I normally find out what the issue is as there are too many programs out there for support to know how to fix them all...
    Jonathan Crass
    Joint Partner in Checker Design
    Joint Partner in Jst Hosting

    UK Website design
    UK based monitoring
    Cheap UK Web Hosting

    eUKhost Forum Moderator

  2. #22
    Join Date
    Sep 2005
    Posts
    6,039

    Default

    Quote Originally Posted by jc8654 View Post
    The way I would suggest doing it would be to have some kind of forum entry or similar saying something like if you are having security/error issues with a CMS find more info here. Basically, in that section say google the program name and the error - that's the way I normally find out what the issue is as there are too many programs out there for support to know how to fix them all...
    Yes.

    All senior staff members from our support department have started posting list of common errors on our internal forum. We will make one single article out of all those errors and include link to that article in welcome email for new customers.
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

  3. #23
    Join Date
    Apr 2007
    Location
    Manchester, United Kingdom
    Posts
    8,440

    Default

    Good idea Jonathan. Google is God for sorting out problems!
    David Smith
    DPS Computing
    http://www.dpscomputing.com (Computing, Reviews, News) - We're still plodding on adding new content and features (August 2011)
    http://www.djdavid.co.uk - Massive update! (September 2011) - It's now not neglected!!
    http://davidsmith.dpscomputing.com (My Personal Website) - New Site (10/2009)

  4. #24
    Join Date
    Dec 2008
    Posts
    12

    Default

    Quote Originally Posted by jc8654 View Post
    The way I would suggest doing it would be to have some kind of forum entry or similar saying something like if you are having security/error issues with a CMS find more info here. Basically, in that section say google the program name and the error - that's the way I normally find out what the issue is as there are too many programs out there for support to know how to fix them all...
    In two of the three cases there were no errors reported by the server and in the third case the error was rather unhelpful 403. I wouldn't complain if mod_security or suhosin reported anything but they didn't.

  5. #25
    Join Date
    Apr 2007
    Location
    Manchester, United Kingdom
    Posts
    8,440

    Default

    Quote Originally Posted by vladimir View Post
    In two of the three cases there were no errors reported by the server and in the third case the error was rather unhelpful 403. I wouldn't complain if mod_security or suhosin reported anything but they didn't.
    Unfortunately that is down to the developers of the respective software and not eUKhost .
    David Smith
    DPS Computing
    http://www.dpscomputing.com (Computing, Reviews, News) - We're still plodding on adding new content and features (August 2011)
    http://www.djdavid.co.uk - Massive update! (September 2011) - It's now not neglected!!
    http://davidsmith.dpscomputing.com (My Personal Website) - New Site (10/2009)

  6. #26
    Join Date
    Sep 2005
    Posts
    6,039

    Default

    try searching any error in google with following keywords :-

    site:.eukhost.com "your error comes here"

    You will find solution for every error on our forums. We will be adding a search box on our website which will take you to all articles on our forum related to the error.
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

  7. #27
    Join Date
    Apr 2007
    Location
    Manchester, United Kingdom
    Posts
    8,440

    Default

    Sounds like a great idea Mark. I will definitely use that feature .
    David Smith
    DPS Computing
    http://www.dpscomputing.com (Computing, Reviews, News) - We're still plodding on adding new content and features (August 2011)
    http://www.djdavid.co.uk - Massive update! (September 2011) - It's now not neglected!!
    http://davidsmith.dpscomputing.com (My Personal Website) - New Site (10/2009)

  8. #28
    Join Date
    May 2007
    Location
    Cambridge, UK
    Posts
    1,593

    Default

    I think I'll still use Google as it includes eUK as well as other sources of info.
    Jonathan Crass
    Joint Partner in Checker Design
    Joint Partner in Jst Hosting

    UK Website design
    UK based monitoring
    Cheap UK Web Hosting

    eUKhost Forum Moderator

  9. #29
    Join Date
    Apr 2007
    Location
    Manchester, United Kingdom
    Posts
    8,440

    Default

    Quote Originally Posted by jc8654 View Post
    I think I'll still use Google as it includes eUK as well as other sources of info.
    Other sources?? Other websites???....

    lol
    David Smith
    DPS Computing
    http://www.dpscomputing.com (Computing, Reviews, News) - We're still plodding on adding new content and features (August 2011)
    http://www.djdavid.co.uk - Massive update! (September 2011) - It's now not neglected!!
    http://davidsmith.dpscomputing.com (My Personal Website) - New Site (10/2009)

  10. #30
    Join Date
    Nov 2005
    Location
    Maidenhead UK
    Posts
    33

    Default

    Well I'm just posting a short message to test the paranoid security. It says "Welcome back Richard" at the top so i should be logged in. Last time I posted a quick reply I got told I wasn't logged in.

  11. #31
    Join Date
    Nov 2005
    Location
    Maidenhead UK
    Posts
    33

    Default

    Why does this box tell me to "Please click one of the Quick Reply icons in the posts above to activate Quick Reply." when if I click on a quick reply button I get taken to the full fat reply page, and quick reply seems to be activated anyway?

    Anyway back to the topic. I've had a full raft of problems with mod_security, mostly since switching to a reseller package. These include getting locked out every time I tried to execute an admin function on my forum (Perl, not php), and not being able to access my sites from one browser. These were eventually resolved and my sites have been running smoothly for some time. However I have to agree with Vladimir that the security measures were a bit heavy handed and needed to be backed off quite a lot.

    One of my sites did get hacked but I think that was a straightforward ftp login hack and I have now set a stronger password.

  12. #32
    Join Date
    Sep 2005
    Posts
    6,039

    Default

    Hi Richard,

    mod_security has been designed to block execution of insecure code and there's nothing that can be done to force mod_security to block insecure code of one application and allow similar code of other. We have tweaked mod_security to allow applications which can never result in hacking of websites through browser based injection, but mod_security won't stop mysql or ftp based injections. We have different set of rules in my.cnf and csf.conf to prevent mysql or ftp hacking. What happened before couple months with all those FTP password hacking attempts was due to weak passwords set on some shared hosting accounts. We had to disable main cpanel account FTP access on most of our cpanel shared hosting servers due to this problem.

    We now have better protection against such FTP hijacks and our servers are safe enough against the browser based or mysql injections due to the high level of security we have on our servers.

    It hardly takes some time to remove bad code from your website, but it takes long time to recover lost data once your website gets hacked and the backup you get turns out to be 1 week old.
    UK Web Hosting || Business Hosting || eUKhost Knowledgebase
    Toll Free : 0808 262 0255 || Skype : mark_ducadi
    A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
    __________________________________________________

    Please email cmo[at]eukhost.com if you have any questions or need my assistance

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •