|
|||||||
![]() |
Forum Index > glFusion > glFusion Support |
|
|
Media Library for fckeditor
|
|||
| First | Previous | 1 2 3 | Next | Last | | | Printable Version |
|
muntada | ||||||||
|
I tried to upload some images for a story through the fckeditor. It kept churning and churning away so I guessed something was wrong with permissions. I did the following where <domainname> is the actual site name:
________________________
Abdul Rashid Abdullah Muntada, LLC http://www.muntada.com |
![]() Active Member Group Comfort Level:: +2 ![]() ![]()
Registered: 07/11/07 |
||||||||
|
|||||||||
|
Geiss | ||||||||
This was an install from the 1.0.2 tarball.
|
![]() Admin Group Comfort Level:: +57 ![]() ![]()
Registered: 02/15/07 |
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
Eric ... PHP Formatted Code ALERT - Include filename ('../../../../../lib-common.php') contains too many '../' (attacker '10.10.10.9', file '/www/xxx/public_html/fckeditor/editor/filemanager/connectors/php/config.php', line 25), referer: http://www.xxx.org/fckeditor/editor/dia ... image.html[Sun Aug 10 22:34:09 2008] [error] [client 10.10.10.9] ALERT - Include filename ('../../../../../lib-common.php') contains too many '../' (attacker '10.10.10.9', file '/www |
|
||||||||
|
|||||||||
|
muntada | ||||||||
|
Yes, I meant 1.0.1.
________________________
Abdul Rashid Abdullah Muntada, LLC http://www.muntada.com |
![]() Active Member Group Comfort Level:: +2 ![]() ![]()
Registered: 07/11/07 |
||||||||
|
|||||||||
|
Geiss | ||||||||
|
Wayne,
|
![]() Admin Group Comfort Level:: +57 ![]() ![]()
Registered: 02/15/07 |
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
I will keep looking and post findings here. |
|
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
btw Line 25 referred in the errror PHP Formatted Code /public_html/fckeditor/editor/filemanager/connectors/php/config.php', line 25)
PHP Formatted Code require ('../../../../../lib-common.php');
|
|
||||||||
|
|||||||||
|
Mark | ||||||||
|
Wayne, This is another error caused by your Subhosin PHP Security patch. It is not caused by glFusion or the FCKeditor. One of the options of the Subhosin PHP security patch is to dis-allow requests that include a certain number of ../../ in the path. The idea being that too many is probably an attacker trying to read your passwd file or some other system file. glFusion - Enhanced Content Management |
![]() Admin Group Comfort Level:: +104 ![]() ![]()
Registered: 10/21/05 |
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
Eric |
|
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
Hi Mark Quote by: MarkWayne, This is another error caused by your Subhosin PHP Security patch. It is not caused by glFusion or the FCKeditor. One of the options of the Subhosin PHP security patch is to dis-allow requests that include a certain number of ../../ in the path. The idea being that too many is probably an attacker trying to read your passwd file or some other system file. |
|
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
Mark PHP Formatted Code suhosin.executor.func.blacklist=exec, shell_exec, system, passthru, show_source, proc_open, popen, highlight_file, phpinfo, ini_set, ini_restore
PHP Formatted Code suhosin.executor.func.whitelist=
|
|
||||||||
|
|||||||||
|
jmucchiello | ||||||||
|
glFusion should only need ini_set out of that list. |
![]() Active Member Group Comfort Level:: +2 ![]()
Registered: 05/15/07 |
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
Many thanks will set all the others to rem and set ini_set to blacklist. |
|
||||||||
|
|||||||||
|
Anonymous: filipino | ||||||||
|
Unfortunately setting set_ini in the blacklist creates the 'This page cannot be rendered error' with the following error in the Apache error log: PHP Formatted Code ALERT- function within blacklist called: ini_set() (attacker 'X-FORWARDED-FOR not set', file '/www/xxxx/public_html/lib-common.php', line 168)
PHP Formatted Code if( ini_set( 'include_path', $_CONF['path_pear'] . $separator. $curPHPIncludePath ) === false ) { COM_errorLog( 'ini_set failed - there may be problems using the PEAR classes.', 1);
|
|
||||||||
|
|||||||||
|
Mark | ||||||||
|
Wayne, I believe Joe was stating that glFusion needs to call ini_set(), so it should not be in the blacklist. glFusion - Enhanced Content Management |
![]() Admin Group Comfort Level:: +104 ![]() ![]()
Registered: 10/21/05 |
||||||||
|
|||||||||
|
| First | Previous | 1 2 3 | Next | Last |
| All times are CDT. The time is now 01:29 pm. |
|
|