Præsentation
Udviklings Teamet
Kalender
RSS Nyheder
TopArtikler
Artikler ialt: 51
Top 5 læste - laesmig.txt - CHMOD - På Din Computer - Plugin, forks og scripts - Start eller opgrader Seneste 3 tilføjet - Versioner - Musik kode - Hosting-pakker |
GuppY Ver. 4.5.x - Sikkerhed &
Corrections that should be applied to skins and plugins, Generalities Because of these ending, there are now some incompatibilities with existing skins and plugins. This note explains the security rules that are used and the corrections that have to be done to skins and plugins Rules < ?php This script prevents those repertories from being explored so that nobody can list the files they contain. Guppy v4.0 was already following this rule almost totally ,. Guppy v4.5 respects it completely. 2 - Rule 2 if (stristr($_SERVER["SCRIPT_NAME"], "Nom this heading avoids a direct call like for exemple : http://mon.site.com/inc/functions.php The « breaker » is then simply sent to the home page . 3 - Rule 3 This control is done to avoid any ending of the « the script file name», for ex. by typing parameters on the addres line of the navigator. This control can be avoided if it is impossible to modify the argument. It is recommended to use PHPconstant for all the invariable values during the execution of the script. Guppy v4.5 has replaced most of the « invariables » variables with PHP constants. The most known and most vulnerable of these « invariables » variables is $chemin. Corrections to be done 1 - Rule 1 2 - Rule 2 3 -Rule 3 Use of variables « invariables » Definition of « invariables » variables
Guppy 4.5 can function with PHP adjustment Register_reglobals = OFF, It can bring problems to some plugins.All plugins that need seizing datas through forms, out of administration scripts, are potentially prone to these problems. :include(CHEMIN."inc/includes.inc") ; after the CHEMIN constant and before any other file inclusion Af dato : 08/09/2005 @ 10h03 | Shoutbox
Kun for medlemmer Tilslutter...
[ Tilmeld Her! ] Medlemmer online: Anonyme online: 8 Besøg i alt: 407565 Webmaster - Info
Med-Redaktøre
Klik på knappen herunder for at logge ind som Med-Redaktør på FreeGuppY.dk Søg
Professionel
Vi tilbyder bl.a.:
Læs mere om MicCo WebDesign og se prøver på skin til GuppY CMS, fremstillet af MicCo WebDesign. |


aldweb

GuppY
Medlemmer online:
Anonyme online: 8
Besøg i alt: 407565 
Top