Adobe Dreamweaver Forums



Last 10 THreads :         Problem fetching policy-file-request (Last Post : greenx - Replies : 0 - Views : 1 )           »          Coldfusion Login (Last Post : ProjectedSurplus - Replies : 0 - Views : 1 )           »          FTP Error Occurred - Cannot make connection (Last Post : ostephy - Replies : 2 - Views : 3 )           »          Opening a flash movie in dreamweaver (Last Post : Nancy O - Replies : 1 - Views : 3 )           »          Re: Unable to authenticate installer (Last Post : D Sparks - Replies : 1 - Views : 2 )           »          Microphone in the latest beta (Last Post : 0x656b694d - Replies : 0 - Views : 1 )           »          Please help me (Last Post : HalfNelson - Replies : 0 - Views : 1 )           »          Re: Fireworks screws up colors from photoshop (Last Post : chirp88 - Replies : 5 - Views : 6 )           »          CFdirectory recurse error (Last Post : Adam Cameron - Replies : 1 - Views : 2 )           »          Coldfusion Login (Last Post : ProjectedSurplus - Replies : 0 - Views : 1 )           »         


Home Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
User Info Statistics
Go Back   Adobe Dreamweaver Forums > Dreamweaver: Main > Dreamweaver Extensions
 
Tags: ,

Reply
  #1 (permalink)  
Old 06-09-2008, 03:38 PM
david@bridgemics.co.
 
Posts: n/a
Diggs:
Default PHP security

I have posted this question elsewhere by mistake - sorry.
My ISP says that I most likely have a security hole in my website PHP coding.
My website uses PHP to call pages, overall it was written using dreamweaver.
I am not very familiar with either PHP or Dreamweaver, although I did write
the website, so I have no one else to blame but myself.
I have had a few rogue websites set up using my webspace. After deleting the
sites and uploading the original files and changing my password they still
arrived. My ISP says there is most likely a security hole in my PHP coding and
I should apply the most recent patches.
I don't know/understand how to do this, my ISP doesn't support PHP or any
website building really.
I am currently running the most recent version of PHP on my PC, but wasn't
when I wrote the website. How do I update my web pages to be using this most
recent version of PHP.
If I only send simple code to my webspace is it not the ISP PHP parser that
needs updating? (This probably shows my lack of knowledge)
Any help would be gratfuly received.

Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 06-09-2008, 11:04 PM
Steve
 
Posts: n/a
Diggs:
Default Re: PHP security

David,

The first thing that I would check is the directory/file permissions on your
web space. If others are posting files there, they must be wide open.

The subject of updating PHP is a little more complex than can be handled in
this forum. You absolutely need to have an ISP that can assist you with
this. In fact, I'm surprised that tou are able to use it at all if the ISP
doesn't support it. How did you install it on the server?

Could you provide a link to the site?

Respectfully,

Steve

"david@bridgemics.co." <webforumsuser@macromedia.com> wrote in message
news:g2jhnb$akv$1@forums.macromedia.com...
>I have posted this question elsewhere by mistake - sorry.
> My ISP says that I most likely have a security hole in my website PHP
> coding.
> My website uses PHP to call pages, overall it was written using
> dreamweaver.
> I am not very familiar with either PHP or Dreamweaver, although I did
> write
> the website, so I have no one else to blame but myself.
> I have had a few rogue websites set up using my webspace. After deleting
> the
> sites and uploading the original files and changing my password they still
> arrived. My ISP says there is most likely a security hole in my PHP coding
> and
> I should apply the most recent patches.
> I don't know/understand how to do this, my ISP doesn't support PHP or any
> website building really.
> I am currently running the most recent version of PHP on my PC, but wasn't
> when I wrote the website. How do I update my web pages to be using this
> most
> recent version of PHP.
> If I only send simple code to my webspace is it not the ISP PHP parser
> that
> needs updating? (This probably shows my lack of knowledge)
> Any help would be gratfuly received.
>



Reply With Quote
  #3 (permalink)  
Old 06-10-2008, 09:19 PM
david@bridgemics.co.
 
Posts: n/a
Diggs:
Default Re: PHP security

Hi Steve,
My ISP doesn't support PHP in as much as they won't help with any PHP
problems, the webspace has PHP installed and enabled for use.
My site is at www.hebdensound.co.uk
When you say file/directory permissions, is this beyond the ISP only allowing
logged in users to ftp to a site?
I have just now changed permissions to my directories to have a username and
password, I am not sure how this gets envoked however, but is this what you
mean? When I use an ftp program I can still get into these directories without
any extra password.

Thanks for your help



Reply With Quote
  #4 (permalink)  
Old 07-19-2008, 06:32 PM
Steve
 
Posts: n/a
Diggs:
Default Re: PHP security

David,

I checked your site, and your FTP service is requesting a User ID and
password. I suspect that you re getting in through as you've cached the
authentication already. One way to check this is to clear your browser's
cache/cookies and try logging in again. You should get prompted.

This should stop users from posting files on your site unless you have
created an upload page that they can access. I didn't see one when I looked
at your site. You need to set the file/directory permissions on all of your
directories so that the users can read/execute PHP pages, but not write. If
you do create an upload page, point any uploads to a directory that can be
written to by the users, but won't give them execute scripts permissions.
Otherwise they can upload a script and then execute it, and then you're in
trouble.

The ISP needs to apply the latest patches to PHP on the server. This is not
something you can do. If you upgrade PHP on your workstation, any changes
that you make to yuour pages locally can be FTP'd to the server. However, if
you are coding to a later version of PHP than the ISP, some of your pages
may not work. I always try to stay in sync with the ISP to avoid this.

From the sound of it, you would be much better off getting a different ISP.
There are thousands out there, and most offer much better support than your
current one.

Steve

"david@bridgemics.co." <webforumsuser@macromedia.com> wrote in message
news:g2mqb3$40e$1@forums.macromedia.com...
> Hi Steve,
> My ISP doesn't support PHP in as much as they won't help with any PHP
> problems, the webspace has PHP installed and enabled for use.
> My site is at www.hebdensound.co.uk
> When you say file/directory permissions, is this beyond the ISP only
> allowing
> logged in users to ftp to a site?
> I have just now changed permissions to my directories to have a username
> and
> password, I am not sure how this gets envoked however, but is this what
> you
> mean? When I use an ftp program I can still get into these directories
> without
> any extra password.
>
> Thanks for your help
>
>
>



Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



© Camley Interactive (camley.info) 2008 - all logos and images are copywrite their respective owners.
Proud member of the Camley Interactive Network
All times are GMT. The time now is 10:35 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
Inactive Reminders By Mished.co.uk