♦ REFRESH to rotate MAAMAW'S CLICKY NOTES thru this space..... Timely Tips, Best of the Boards & More ♦ |
Be sure to visit the Current Message Board when you're finished here. We're very friendly, so don't be shy... just jump right in and post your question. Scams outnumber legitimate biz ops about a bzillion to one, so it's well worth your time. |
| View Thread | Return to Index | Read Prev Msg | Read Next Msg | |
---|
FIB - Scams 101 - Ye Olde Archives
Posted By: S. Tanna In Response To: How Do I Block IP Addresses? (Michelle Nightengale)
Wednesday, 28 June 2006, at 8:03 a.m.
> How do I block an IP address?
On Apache, create a file called .htaccess (with that leading dot) in Notepad and upload it to the main folder of your site. To check it's working, do a test blocking your own IP, visit the site, hit refresh and you should see an error. Then edit the file to block the IPs you want blocked, and upload the new version. Instructions here: http://www.javascriptkit.com/howto/htaccess5.shtml
or just google something like "htaccess block ip"
> They also suggested that my scripts are not "vulnerable to accepting
> values not originated from [my] site." Huh??? How do I do that??? My
> designer did all of my design work, including the PHP scripts. I honestly
> have no idea how to do all of this.
You should be worried about that.
Here's the type of scenario
Imagine you have a form on your site.
The form allows the user to input 1, 2, 3, 4 or 5 and a CGI/PHP script on your site does something predictable in response to each of those inputs.
Now imagine that entering 6 would crash your server, or wipe your files, or give away your password, or something else nasty or unpredictable. Imagine that the CGI/PHP script doesn't include error checks for 6, because the web designer thought "Why worry because the form on the site only allows users to enter 1, 2, 3, 4, or 5"....or the the web-designer never even considered the possibility of entering a 6.
...Along comes Mr Hacker. He wants to break your site. He knows that he needs to enter 6 to make it happen. But your form doesn't allow 6. So what he does is create a form on his web site, or on his own computer, but links the form to your CGI/PHP script (use the ACTION= parameter in the FORM tag).
Then Mr Hacker enters 6 into his private version form, 6 is passed to your CGI/PHP script, which runs on your server, and Mr Hacker is in...
The solution:
Make sure every piece of user input (form fields, URLs, query parameters, cookies, referral fields, even IP addresses, etc.) that is processed by CGI/PHP scripts on your site is validated, especially if it is eventually used as a parameter to another command.
Killer PHP scripts for your site
| View Thread | Return to Index | Read Prev Msg | Read Next Msg | |
---|
FIB - Scams 101 - Ye Olde Archives is maintained with WebBBS 3.11.
|
PLEASE READ THIS LEGAL NOTICE CAREFULLY BEFORE YOU FILE A LAWSUIT OR EVEN WASTE TIME THINKING ABOUT IT. It has been done before, but never successfully. In fact, the last dodobird who tried it ended up being ordered to pay more than $77,000 in attorney fees ($65,000+ to my attorneys and $12,000+ to my co-defendant's legal advisor).
If your attorney is worth his salt, he's going to tell you that the expense of filing a lawsuit you can't win is a whole lot worse than any "damages" resulting from messages posted on this insignificant little chunk of cyberspace. NEWS FLASH: I didn't just climb down off that ol' turnip truck yesterday. I'm well aware that expressing a negative opinion, relating one's personal experience, and restating provable facts are all legal in this country and do not constitute libel, slander, or defamation -- so you don't want to play games with me, and you sure don't want to start something you aren't prepared to finish. I don't take threats lightly, and I don't accept bribes (or did you call it a "mutually-beneficial arrangement"?). I'll turn you in faster than you can yell, "ARREST ME, I'M SCUM!!" Do yourself a favor and turn your legal team loose in greener pastures. Although we may, from time to time, monitor or review discussions, postings and the like on the Friends In Business (Scams 101) Message Board, we are under no obligation to do so. We are not responsible or liable for any claim arising from the content of any such discussions or postings or for any error, defamation, libel, slander, omission, falsehood, obscenity, pornography, profanity, danger, or inaccuracy contained in any information contained within such locations on the Site. You are prohibited from posting or transmitting any unlawful, threatening, libelous, defamatory, obscene, scandalous, inflammatory, pornographic, or profane materials or any material that could constitute or encourage conduct that would be considered a criminal offense, give rise to civil liability, or otherwise violate any law. You are likewise prohibited from posting any false claims against any company or individual. We will fully cooperate with any law enforcement authorities or court order requesting or directing us to disclose the identity of anyone posting any such information or materials. By posting messages and/or content on the Friends In Business (Scams 101) Message Board, you give permission for Lesley Fountain/Friends In Business/Shoestring Success Publications to display, distribute and use the posting and content for publication, advertising, promotion, excerption or example. You grant Lesley Fountain/Friends In Business/Shoestring Success Publications complete, perpetual, but non-exclusive rights to use, archive, reproduce, adapt, modify, distribute, sub-license, repurpose, rework, compile, or offer for sale or resale the messages, postings or content appearing on this site in whole or in part, throughout the world and universe, on a royalty-free basis without remuneration. If you cannot accept or agree with the terms of service for this website and discussion board, you are advised not to post on this board. In closing, I would like to remind you once again that it is still legal, in this great country of ours, to express a PERSONAL OPINION, as long as it is presented as opinion and not as fact. And finally, all you scammers out there will do well to remember that TRUTH IS AN ABSOLUTE DEFENSE against charges of libel, defamation, and slander... so if you're operating just a hop, skip, and jump ahead of the law, you might want to think twice before doing anything stupid... (AND SHAME ON YOU!!). |