From the category archives:

Tips

Proteksi folder chmod 777 dengan htaccess

by Perk1z on April 1, 2008

Folder dengan chmod 777 = bisa di tulis, baca dan di eksekusi oleh “siapa saja”

Biasanya kelemahan ini dianggap sepele (terabaikan begitu saja), padahal ini bisa berakibat fatal dari sisi sekuriti web, terutama pada folder upload/images. Sebaiknya jika menngunakan fasilitas upload untuk umum seperti upload file, image avatar, image profile, dll. Folder tujuan sebaiknya difilter, diantaranya menggunakan file htaccess. Berikut sedikit tips yang mungkin bisa membatasi akses ke folder tersebut :

Create file .htaccess di folder yang bersangkutan dan isi dengan :

php_flag engine off
<Files ~ "\.(php*|s?p?html|cgi|pl)$">
deny from all
</Files>

Penjelasan :
.htaccess diatas akan menolak (Deny) akses ke folder tersebut terhadap extensi file php,shtml,phtml,cgi,pl

Catatan :
Anda bisa menambah,modif FIle yang diinginkan/ditolak sesuai dengan kebutuhan

Popularity: 31% [?]

{ 0 comments }

Exim Error log : Gid 99 is not permitted to relay mail

by Perk1z on February 14, 2008

Exim Error Log :

2008-02-12 14:37:04 1JOphQ-0007td-6w <= nobody@titik.org U=nobody P=local S=629 T=”Testing Kirim Email”
2008-02-12 14:37:04 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1JOphQ-0007td-6w
2008-02-12 14:37:04 1JOphQ-0007td-6w ** me@titik.org R=checkspam2: Gid 99 is not permitted to relay mail, or has directly called /usr/sbin/exim instead of /usr/sbin/sendmail.
2008-02-12 14:37:04 1JOphQ-0007td-6w ** me@titik.org R=checkspam2: Gid 99 is not permitted to relay mail, or has directly called /usr/sbin/exim instead of /usr/sbin/sendmail.
2008-02-12 14:37:04 cwd=/var/spool/exim 7 args: /usr/sbin/exim -t -oem -oi -f <> -E1JOphQ-0007td-6w

Try :

1. Check in WHM under Tweak Settings(under Email) if the box for “Prevent the user “nobody” from sending out mail to remote addresses ” is checked, if it is uncheck that box and click save at the bottom of the page.

GID 99 is for apache(username=nobody) .

2. check and make sure that you have the domain name listed in the file “/etc/localdomains ” to allow relaying of mails.

Popularity: 53% [?]

{ 0 comments }

Install phpBB SEO

by Perk1z on February 3, 2008

Install phpBB SEO
1> Backup all your files;
2> Download phpbbseo :
http://www.phpbb-seo.com/boards/advanced-seo-url/advanced-phpbb3-seo-url-vt1219.html
3> extract

[phpBBc@titik www]$ unzip adv_phpbb3_mod_rewriteV0-4-0.zip
[phpBBc@titik www]$ cd root/
[phpBBc@titik www]$ mv phpbb_seo ../

4> CHMOD the phpbb_seo/cache/ folder to 0777;

[phpBBc@titik www]$ chmod 777 phpbb_seo/cache/

5> Empty the phpBB/cache/ folder : just delete all files EXCEPTS the .htaccess.

[phpBBc@titik www]$ rm -f cache/*.*

6> Copy Files

[phpBBc@titik www]$ cd contrib/phpBB_3.0.0_modified_files/root/
[phpBBc@titik www]$ cp -R ../../../
[phpBBc@titik www]$ cp ./root/language/en/acp/phpbb_seo.php ./language/en/acp
[phpBBc@titik www]$ cp ./root/includes/acp/info/acp_phpbb_seo.php ./includes/acp/info/
[phpBBc@titik www]$ cp ./root/includes/acp/acp_phpbb_seo.php ./includes/acp/

7> Go to www.yoursite.com/phpBB/phpbb_seo/phpbb_seo_install.php and follow the install instruction
8> Go to phpBB ACP : It’s now time to play with settings described bellow;
9> Generate your personalized .htaccess and upload or move it following the instructions;

Popularity: 100% [?]

{ 2 comments }

Upgrade wordpress via ssh

by Perk1z on October 10, 2007

1.Login via SSH to your host

2.Create abd Go to a temporary directory: cd /tmp (example)
me@titik.org [~/www]# mkdir tmp
me@titik.org [~/www]# cd tmp/

3.Grab the latest WP archive: wget http://wordpress.org/latest.tar.gz

4.Extract the archive contents latest.tar.gz
me@titik.org [~/www/spa/tmp]# wget http://wordpress.org/latest.tar.gz
–15:28:54– http://wordpress.org/latest.tar.gz
=> `latest.tar.gz’
Resolving wordpress.org… 72.233.56.139, 72.233.56.138
Connecting to wordpress.org|72.233.56.139|:80… connected.
HTTP request sent, awaiting response… 200 OK
Length: unspecified [application/x-gzip]

[ <=> ] 870,766 11.39K/s

15:30:28 (9.17 KB/s) - `latest.tar.gz’ saved [870766]

[click to continue...]

Popularity: 39% [?]

{ 0 comments }

Teliti Sebelum dan Sesudah Membeli !!! … (Info Seputar Domain)

by Perk1z on January 14, 2007

Beberapa hal yang perlu diperhatikan sebelum dan sesudah membeli domain :

1. Cek ketersediaan domain yang anda inginkan (.com atau .net dsb) sebelum membeli. Misalnya melalui Whois Lookup
2. Jika Domain yang anda inginkan tersedia, lalu lakukan order ke provider domain/hosting favorite anda.

* Ingat !!! bahwa kalau hanya melakukan order, itu tidak berarti anda memesan domain tersebut dengan asumsi anda bisa membelinya kapan saja. Sebaiknya setelah order, langsung lakukan pembayaran untuk aktivasi domain untuk menghindari domain yang anda order tersebut dibeli orang lain. Karena domain tidak bisa dibooking (order, domain langsung aktif tanpa membayar atau bayar belakangan terkecuali provider domain tempat anda order bisa ngutang …) karena domain yang statusnya free/available sifatnya “terbuka” dalam artian siapa, kapan dan dimana saja bisa membeli domain tersebut.

3. Setelah Domain anda aktif, cek informasi domain tersebut melalui Whois lookup seperti domain tools, Whois titik dan sebagainya. Pastikan info domainnya sesuai dengan kepemilikan anda. mulai dari Registrant Details , Admin Details, Technical Details, Billing Details sampai pada Name servernya sesuai dengan yang anda inginkan/order.

* Pastikan anda memiliki akses control panel untuk me”manage” domain anda. Mulai dari lock/unlock, modify contact detail, sampai mengubah name server domain anda. Jika anda tidak memiliki hak akses, jangan ragu untuk menanyakan ke pengelola domain anda.

4. Selamat berkreasi dengan domain² anda …

TLD umum

  • .arpa : Address and Routing Parameter Area
  • .biz : bisnis
  • .com : komersial
  • .info : informasi
  • .int : internasional
  • .museum : museum
  • .name : nama perorangan
  • .net : jaringan
  • .org : organisasi
  • .pro : profesi
  • .travel : industri wisata

* TLD adalah singkatan dari “Top Level Internet Domain” (Ranah Internet Tingkat Teratas). Istilah “nama ranah” ini merujuk kepada beberapa huruf terakhir setelah tanda dot (titik) dalam sebuah alamat situs web, misalkan untuk Indonesia, kode ini adalah “.id” (dibaca: dot I D).

Popularity: 7% [?]

{ 0 comments }

5 safety tips for using a public computer

by Perk1z on December 23, 2006

1. Don’t save your logon information. Always log out of Web sites by clicking “log out” on the site. It’s not enough to simply close the browser window or type in another address.

Many programs (especially instant messenger programs) include automatic login features that will save your user name and password. Disable this option so no one can log in as you.

2. Don’t leave the computer unattended with sensitive information on the screen. If you have to leave the public computer, log out of all programs and close all windows that might display sensitive information.

3. Erase your tracks. Web browsers such as Internet Explorer keep a record of your passwords and every page you visit, even after you’ve closed them and logged out.

To disable the feature that stores passwords
Before you go to the Web, turn off the Internet Explorer feature that “remembers” your passwords.

1. In Internet Explorer, click Tools, and then click Internet Options.

2. Click the Content tab, and then click AutoComplete.

3. Click to clear both check boxes having to do with passwords.

To delete your temporary Internet files and your history
When you finish your use of a public computer, you should delete all the temporary files and your Internet history.

1. In Internet Explorer, click Tools, and then click Internet Options.

2. On the General tab, under Temporary Internet files, click Delete Files, and then click Delete Cookies.

3. Under History, click Clear History.

To delete other files saved by corporate portals, such as Sharepoint Portal Server
If you’re using a corporate Web site that allows you to view internal corporate documents, you may be inadvertently storing sensitive documents on the public computer.

1. Delete all the files in the temporary folder of your user account which you can find by browsing to C:\Documents and Settings\username\Local Settings\Temp.

2. If your company uses Microsoft Office SharePoint Portal Server, empty the temporary folder (My Documents\SharePoint Drafts).

4. Watch for over-the-shoulder snoops. When you use a public computer, be on the look out for thieves who look over your shoulder or watch as you enter sensitive passwords to collect your information.

5. Don’t enter sensitive information into a public computer. These measures provide some protection against casual hackers who use a public computer after you have.

But keep in mind that an industrious thief might have installed sophisticated software on the public computer that records every keystroke and then e-mails that information back to the thief.

Then it doesn’t matter if you haven’t saved your information or if you’ve erased your tracks. They still have access to this information.

If you really want to be safe, avoid typing your credit card number or any other financial or otherwise sensitive information into any public computer.

Original Page : MicrosoftÂ

Popularity: 6% [?]

{ 0 comments }

Too Much Love? Outlook Can Automatically Delete Unwanted E-mail

by Perk1z on August 11, 2006

The Outlook Rules Wizard paid off for me during the recent influx of unwanted ILOVEYOU messages. With the Rules Wizard, I have been automatically deleting any e-mail messages I receive with the following keywords in the Subject box: “ILOVEYOU,” “I LOVE YOU,” and “FWD: JOKE.” Now they don’t clog up my Inbox, and I can’t open them up accidentally.

To use the Rules Wizard to automatically delete any e-mail with the subject “ILOVEYOU”:

  1. Click Inbox. Then, on the Tools menu, click Rules Wizard.
  2. Click New.
  3. Click check messages when they arrive, and then click Next.
  4. Select the check box next to with specific word in the subject.
  5. In the text area below, click the blue, underlined phrase specific words.
  6. Here you can specify which words Outlook should look out for. For example, in the Add New text box, enter ILOVEYOU and then click Add. Repeat for any additional terms you want to check for. When you’re done, click OK and then click Next.
  7. Select delete it.
  8. Click Finish.

To apply the rule to e-mail already in your Inbox, click Run Now. In the Select rules to run list, select the check box next to the rule you just created, and click Run Now. This will delete all e-mail in your inbox with the subject “ILOVEYOU.” When the process is complete, click OK.

Now, anytime you get e-mail with the subject “ILOVEYOU,” Outlook will automatically move it to your Deleted Items folder. The e-mail will still be available in your Deleted Items until you empty the folder.

Note: This tip will not protect you from all types of e-mail-borne viruses. To guard against viral attacks that travel in e-mail attachments, Microsoft strongly recommends that you download the Outlook E-mail Security Update from the Office Download Center. Users should review the documentation before installing.

Author : Dave Kaiser, Crystal River, Florida

Popularity: 6% [?]

{ 0 comments }

How to Find Somebody’s Email Address by Searching the Web

by Perk1z on August 11, 2006

Finding somebody’s email address can be difficult. If you know something about the person whose address you are looking for (the name, for example), you can treat this problem of search like any other: pour what you have into a good search engine and hope that it will come up with something relevant.To find somebody’s email address via the web:

  • Start by typing the person’s name in one of the major search engines like Google or Yahoo!.
  • The pages that come up may not only contain your search target’s name but also their email address.

If you get lots of results or are not sure you have indeed found the person you are looking for:

  • Try adding other other data you might know to your query.
    • Maybe you know the person’s profession, a nickname, a pet’s name, a hobby, friends, addresses, or something similar.

From Heinz Tschabitscher

Popularity: 6% [?]

{ 0 comments }

Phising

by Perk1z on May 29, 2006

Hati-hati jika Anda akan mereply e-mail yang meminta informasi tentang rekening Anda, seperti; User ID, PIN, nomor rekening/nomor kartu, atau pemberitahuan untuk melakukan transfer karena memenangkan undian tertentu. Bisa jadi ini adalah ulah orang yang tidak bertanggung jawab untuk mengelabui Anda. Modus penipuan seperti ini dikenal sebagai phising.

[click to continue...]

Popularity: 6% [?]

{ 0 comments }

Trik Menggunakan Mesin Pencari Google

by Perk1z on May 9, 2006

Pada kesempatan ini akan dipaparkan penggunaan mesin pencari informasi Google, untuk mendapatkan informasi yang tersembunyi dan sangat penting. Dimana informasi tersebut tidak terlihat melalui metode pencarian biasa. Artikel ini berdasarkan pada FAQ dan diskusi pada milis situs keamanan jaringan komputer http://bugtraq.org dan http://insecure.org tentang metode pengumpulan informasi berkaitan dengan aktifitas webhacking .

[click to continue...]

Popularity: 19% [?]

{ 7 comments }