Welcome, Guest. Please Login or Register.
April 26, 2025, 06:49:10 PM
Home Help Search Log in Register
News: If you are still using YaBB SE, please consider upgrading to SMF as soon as possible.

YaBB SE Community  |  General Category  |  Feedback  |  Are you sure that your safemode version is secure ? « previous next »
Pages: [1] Reply Ignore Print
Author Topic: Are you sure that your safemode version is secure ?  (Read 1085 times)
betatest
Noobie
*
Posts: 15


Shut a crappity smack up !

ICQ - 65164987astagor@hotmail.com WWW
Are you sure that your safemode version is secure ?
« on: February 10, 2003, 01:07:54 AM »
Reply with quote

Just because on my "high" (hope so) secure server (some improvements and restrictions like safemode) I'm unable to install your version 'safemode' he make a message error like this :

YaBB SE Safe Mode Installer
Error: No Database Selected

(on step 7 to create the user)

also when I make the user manualy I get this error on the index :

An Error Has Occurred!

2: mysql_fetch_array(): supplied argument is not a valid MySQL result resource
(/users/forum/yabbse/Sources/Subs.php ln 186)

Also why every of version of YaBB SE need to automaticaly replace the http user & group & chmods (on an unsecure way) ?

I really like the design and the functions of YaBB but they are some things stranges I see  :-X

The current open beta isn't yet ported to safemode (also why to make two different versions one normal and one safemode ? All other BB concurent don't need this and run perfectly in normal&safemode with the same code like phpbb/vb &co)

So if a devel have 2sec to look what's wrong with the security part of YaBB & compatibility in safemode (I tested 4 boards on the same server, phpbb run, vbulletin run, phorum run, YaBB failed (noarmal&safemode version) so it can't be the server) it will be glad because I'll really would like to use YaBB and no other BB  ;)

Thanks for support

(ps : why do you need to make system calls to use /var for example, think that if the httpd is chrooted in a jail you can't use this  :P)
« Last Edit: February 10, 2003, 01:40:56 AM by betatest » Logged

WOoT
Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:Are you sure that your safemode version is secure ?
« Reply #1 on: February 10, 2003, 01:53:29 AM »
Reply with quote

So it sounds like the Settings.php file was written and that's why it said no database was selected. How the hell does that make it not secure?
Logged

betatest
Noobie
*
Posts: 15


Shut a crappity smack up !

ICQ - 65164987astagor@hotmail.com WWW
Re:Are you sure that your safemode version is secure ?
« Reply #2 on: February 10, 2003, 02:05:43 AM »
Reply with quote

the security problem that I talked about wasn't about the no database error but for other points I said (http user/group, chmods, /tmp,...)

I'm not saing that YaBB isn't secure or this way of things no, I just would like to have my YaBB woring correctly in safemode restrictions (godness what a headache lol).

But mhh... I don't understood what's the problem so settings.php was written okay, but after ? Why the forum don't work ? Something wrong with the installer or ? Also you said settings.php was written but the user isn't created into the database :/ Huh really I dunno what to do :/

free tour here  ;) :

http://dmon.ath.cx/~forum/ (yabbse)

thanks one more time for help support & yabbse project
Logged

WOoT
Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:Are you sure that your safemode version is secure ?
« Reply #3 on: February 10, 2003, 02:38:16 AM »
Reply with quote

Sounds like that after install, the installer couldn't write the Settings.php file which stored the database settings. I could be wrong though...
Logged

betatest
Noobie
*
Posts: 15


Shut a crappity smack up !

ICQ - 65164987astagor@hotmail.com WWW
Re:Are you sure that your safemode version is secure ?
« Reply #4 on: February 10, 2003, 11:02:27 AM »
Reply with quote

okay so the file settings.php wasn't written I modified them manualy so now he connect but he display nothing.

You know, I think that YaBB SE couldn't support chmod 644 for files & 755 for folders I don't see any other explication (using any other chmods will be dangerous).

Also I found a mistake, why to put the "enableCompressedOutput" into the database (in settings.php will be better I think) & also why to active the gzip compression by default because some hosters put the php zlib compression already so if both are activated the forum couldn't be displayed, so I think it will be better to desactivate it by default to let the user choose in function of what kind of hosting he use, don't you think so ?

Well I hope that I can help you with all my problems&opinions into this feedback for YaBB SE2 to be better and more secure  :)
Logged

WOoT
betatest
Noobie
*
Posts: 15


Shut a crappity smack up !

ICQ - 65164987astagor@hotmail.com WWW
Re:Are you sure that your safemode version is secure ?
« Reply #5 on: February 12, 2003, 04:17:47 PM »
Reply with quote

nobody an idea really ?  :-\
Logged

WOoT
andrea
Global Moderator
YaBB God
*****
Posts: 4400


Peace on Earth

WWW
Re:Are you sure that your safemode version is secure ?
« Reply #6 on: February 12, 2003, 05:06:10 PM »
Reply with quote

Quote from: betatest on February 10, 2003, 11:02:27 AM
You know, I think that YaBB SE couldn't support chmod 644 for files & 755 for folders I don't see any other explication (using any other chmods will be dangerous).

This is not true, when the installation is complete you can use those chmod settings without problems.

There are some minimal chmod requirements contained in this faq:
http://www.yabbse.org/community/index.php?board=135;action=display;threadid=15904
Logged

Pages: [1] Reply Ignore Print 
YaBB SE Community  |  General Category  |  Feedback  |  Are you sure that your safemode version is secure ? « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 2.084 seconds with 16 queries.