Web Host Chat
Bringing Hosts & Customers together since 2001
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Advertising
User Information
»REGISTER NOW!

Go Back   Web Host Chat > Web Hosting Chat > Hosting Software and additional add-on products
Reply
 
LinkBack Thread Tools
Old 2nd May 2005   #1 (permalink)
I am Staff at
xoozoo Ltd
About My Company!

Certified Host
Join Date: Nov 2001
Location: Totnes
Posts: 860
dch is on a distinguished road
iHTML Security Alert

Just incase any of you out there use iHTML...

Quote:
Dear Inline/iHTML User,

It has come to our attention that by using Google
it is possible to get database login information in
mainly older versions of the iHTML Merchant. This
could affect any iHTML based site though that uses
iERROR and i_errordetail in the iERROR tag.

The following course of action is HIGHLY recommended.

1. block out the values of the DBNAME and LOGIN directive in your
error messages. This can be done like this (you need iHTML
Enterprise) as basically the first thing in the iERROR block


NEWTEXT=`DBNAME="[ removed ]"` OUTVAR="i_errordetail">
NEWTEXT=`LOGIN="[ removed ]"` OUTVAR="i_errordetail">

2. Change your database user/pass IMMEDIATELY. You can check google
to see if you are exposed by doing this in Google

"dbname" filetype:ihtml intext:LOGIN inline.net

(replace inline.net with your domain)

You can get updated errorblock.inc files for the merchant at

ftp://ftp.inline.net/public/client/s...errorblock.inc
(same file works in 2.0 as 2.5 and mall)

If you are running an older version of the iHTML Merchant, upgrades
to the latest version are free and also recommended.

To unsubscribe from getting these emails from Inline, go to the myiHTML
(http://www.ihtml.com/myihtml) system. All users have an account and
you can have the system automatically email you the user/pass at the
above link.

Russ Cobbe, President
Inline Internet Systems, Inc.
Mississauga & Niagara Canada
1-905-680-0436x211 http://www.inline.net
Providing Comprehensive E-Business Solutions
__________________
» Sean Andrews,
» xoozoo.com ltd - www.xoozoo.com
» Free DNS Report tools - dr.xoozoo.com
» Company no:6482396
__________________
Web Host - Certified Member
dch is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[NEWS] Info Security Product Guide Selects Comodo For 2006 ?Hot Company ... - Help Net Security [NEWS] Hosting and Tech News 0 2nd February 2006 01:06 AM


Some great companies!


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0