Web Host Chat - The UK hosting forum
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Game Servers
Go Back   Web Host Chat > Web Hosting Chat > Hosting Software and additional add-on products
Reply
 
LinkBack Thread Tools
Old 2nd May 2005   #1 (permalink)
dch
 
Join Date: Nov 2001
Location: Totnes
Posts: 965
dch is on a distinguished road
iHTML Security Alert

Just incase any of you out there use iHTML...

Quote:
Dear Inline/iHTML User,

It has come to our attention that by using Google
it is possible to get database login information in
mainly older versions of the iHTML Merchant. This
could affect any iHTML based site though that uses
iERROR and i_errordetail in the iERROR tag.

The following course of action is HIGHLY recommended.

1. block out the values of the DBNAME and LOGIN directive in your
error messages. This can be done like this (you need iHTML
Enterprise) as basically the first thing in the iERROR block


NEWTEXT=`DBNAME="[ removed ]"` OUTVAR="i_errordetail">
NEWTEXT=`LOGIN="[ removed ]"` OUTVAR="i_errordetail">

2. Change your database user/pass IMMEDIATELY. You can check google
to see if you are exposed by doing this in Google

"dbname" filetype:ihtml intext:LOGIN inline.net

(replace inline.net with your domain)

You can get updated errorblock.inc files for the merchant at

ftp://ftp.inline.net/public/client/s...errorblock.inc
(same file works in 2.0 as 2.5 and mall)

If you are running an older version of the iHTML Merchant, upgrades
to the latest version are free and also recommended.

To unsubscribe from getting these emails from Inline, go to the myiHTML
(http://www.ihtml.com/myihtml) system. All users have an account and
you can have the system automatically email you the user/pass at the
above link.

Russ Cobbe, President
Inline Internet Systems, Inc.
Mississauga & Niagara Canada
1-905-680-0436x211 http://www.inline.net
Providing Comprehensive E-Business Solutions
__________________
» Sean Andrews,
» xoozoo.com ltd - www.xoozoo.com
» Free DNS Report tools - dr.xoozoo.com
» Company no:6482396
dch is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[NEWS] Info Security Product Guide Selects Comodo For 2006 ?Hot Company ... - Help Net Security [NEWS] Hosting and Tech News 0 2nd February 2006 12:06 AM

User Information
»REGISTER NOW!
Hosting Software and additional add-on products Visit here to discuss all aspects of hosting software including control panels, webmail and support systems


Quick forum search
 

Special Hosting Offers

Hot Stuff


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0