![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
![]() ![]() FireWall Script FireWall Script is the world's first fully configurable PHP-based website firewall. It can work with any PHP application, and we even offer "packs" of pre-written rules to protect some of the most popular software such was Wordpress, Invision Power Board, Mambo, Joomla, Drupal, and more! It is so easy beginners can install and use it. Protect against: - DDOS Attacks - Webapp exploits - Security scans of your assets - Hackers & common embedding viruses Features of FireWall Script: * Can work with any PHP script * Included admin control panel allows full configuration of the software * Support for multiple administrators. You can add, edit, and delete accounts from the admin panel. * Admin panel update notification and news feeds keep you up to date on FWS * Fully configurable DOS protection allows you to block access to your site for a user when they have multiple requests in a short period of time * Fully configurable rules * CAPTCHA support in rules allows you to show a CAPTCHA verification on any matched request * Akismet integration allows you to do everything you can with rules when submitted text is identified as spam * Admin login logs allow you to keep track of which administrators are using the admin panel * Traffic logs for all traffic on your site (archived daily) * Blocked request logs show you what was blocked and show you everything PHP had available during the request so you can review blocked requests * Spam logs show you requests identified as spam through Akismet * DOS logs show you requests identified as DOS attacks and subsequently blocked * Help section gives you quick access to support for the software * Specify rule title, notes and category for your own referencing and categorization * Ability to log requests blocked by rule * Ability to get email notifications for requests blocked by rules * For requests matching a rule you can allow the request, exit script execution, show an error, show specified HTML, redirect to another page, execute a custom php plugin, or even show a CAPTCHA verification * Ability to look in all PHP superglobals * Full regex power gives you the ability to look for what you want, where you want Check out FireWall Script for more information and product pricing. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
The Profiler
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
|
$85... it will sell. Good luck!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Nov 2006
Location: Pimpin in socal
Posts: 619
|
NIce good luck
__________________
Globat.com hosting company has shitty customer service skills :: please be advised:: ![]() Icq# 394599740 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Jul 2007
Location: Intraweb
Posts: 274
|
What kind of overhead does all this nifty stuff before each request cause?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed IT Professional
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
|
A firewall coded in PHP? That's definitely a first.
__________________
The Best Affiliate Software, Ever. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Confirmed User
Join Date: Jul 2003
Location: www.FetishAssets.com
Posts: 2,161
|
I like the sound of this script
![]()
__________________
![]() ForcedMen | AsianViolation | WorkMyCock | TickleAsian | MasturbationInstructors | AssCleaners | TickleTorment | Fetish4Download (VOD) | PantyhosePlaza | FemaleDomination mick[at]fetishassets.com | ICQ: 395-117 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
LOL it's not first there is already tons of script as this.And they are free.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
100% protection guaranteed
Bold statement. And if you're proven wrong, how much will that cost you? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Confirmed IT Professional
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
|
Quote:
![]()
__________________
The Best Affiliate Software, Ever. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Too lazy to set a custom title
Join Date: Jan 2008
Location: Toronto
Posts: 2,727
|
Sounds interesting!
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Confirmed User
Industry Role:
Join Date: Jul 2007
Location: Intraweb
Posts: 274
|
Quote:
Either way, i agree, if you wanted to do this right, you should of wrote an apache module / php extension or something w/ a compiled language, this isn't something i feel should be scripted. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,372
|
i doubt that php script can block a major ddos attack.
dont provide promises you cant keep
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() WP Stuff |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
Quote:
A ddos attack happens at the server level, long before any php script ever gets run. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 | |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
Quote:
There is obviously a small amount of overhead, but unless you are pushing 25mb/s traffic all day you will not notice any impact. Regarding PHP vulnerabilities, it has nothing to do with the script and is entirely PHP. If you are running the latest stable version of PHP and apply updates as they are released you will not have any problems. PHP is the issue, not the script, and saying that this script will not improve security is very misleading. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
Three words:
Atomic Secured Linux Filter this shit out in the kernel. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
Quote:
As mentioned this is a script to provide additional security for blogs, forums, and template type websites that use joomla, mambo, etc. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
<&(©¿©)&>
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
|
firewall written in php makes as much sense as a solar powered flashlight...
but I guess there are ton of clueless idiots out there, it should sell well ![]()
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000 Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager ![]() Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
Quote:
you are obviously one of them, you do not even understand the practical uses for this. go crying to the forums next time your blog gets hacked. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Whatever,since i installed script which i use for security,i have no problems with hackers anymore.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Confirmed User
Join Date: Apr 2007
Posts: 293
|
Hate to rain on your parade... http://php-ids.org/
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Jun 2003
Posts: 127
|
if you want to protect mambo, joomla or wordpress blog... install some antispam protection OR hire a pro to modify your server/script
__________________
FREE DOMAINS (3rd level) - USA.CC and more -- it should be free in The Communist Era |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 | |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
Quote:
![]() He has forgotten more about coding than you will ever know. He's widely known to be one of the best programmers in the business. Now, who are you?
__________________
I like pie. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Confirmed User
Join Date: Jun 2002
Location: $$$
Posts: 7,993
|
nice, good job
Tomud
__________________
![]() AFF – up to $1.50 per free join, $130 per order ! NASTYDOLLARS - 35$ PPS ! Free hosted galleries ! ADULTDATELINK – $42 PPS, 50% REV ! DATINGGOLD - 100% !!! REV, $4 per email ! Adult Sponsors Reviews – take a look at the best adult programs ! Epassporte Sponsors ICQ: 160168237 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 | |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
Quote:
Quoted directly from their website: "The IDS neither strips, sanitizes nor filters any malicious input, it simply recognizes when an attacker tries to break your site and reacts in exactly the way you want it to. Based on a set of approved and heavily tested filter rules any attack is given a numerical impact rating which makes it easy to decide what kind of action should follow the hacking attempt." |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 | |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
Quote:
Why hire a pro to manage your blog when this software does everything you need? |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Now choke yourself!
Industry Role:
Join Date: Apr 2006
Posts: 12,085
|
I'm still waiting for the punchline.
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Confirmed User
Join Date: Feb 2003
Location: Canby, OR
Posts: 7,453
|
I fully agree, that if you're going to try to add "protection" that you shouldn't make a PHP script, it should be a actual extension to PHP or better yet what you mentioned apache module, which I, myself, feel would be better than a extension to PHP. It could do better. I honestly wouldn't pay $85 for a php script called a "firewall".
__________________
NSCash now powering ReelProfits.com ALSO FEATURING: NSCash.com :: SoloDollars.com :: ReelProfits.com :: BiminiBucks.com :: VOD PROGRAMS COMING SOON: Greedy Bucks :: Vengeance Cash NOW OFFERING OVER 60 SITES CONTACT :: JAMES SMITH :: CHIEF TECHNOLOGY OFFICER :: ICQ (711385133) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Join Date: Feb 2003
Location: Canby, OR
Posts: 7,453
|
One great apache module that will prevent most of the sql injection is MOD_SECURITY for apache. Much better than going with this will do, and it is FREE!
__________________
NSCash now powering ReelProfits.com ALSO FEATURING: NSCash.com :: SoloDollars.com :: ReelProfits.com :: BiminiBucks.com :: VOD PROGRAMS COMING SOON: Greedy Bucks :: Vengeance Cash NOW OFFERING OVER 60 SITES CONTACT :: JAMES SMITH :: CHIEF TECHNOLOGY OFFICER :: ICQ (711385133) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
Now choke yourself!
Industry Role:
Join Date: Apr 2006
Posts: 12,085
|
Mine's free.
<?php $badFunctions = array( "a...", "dom_import_simplexml", "domattr", "domattribute_name", "domattribute_set_value", "domattribute_specified", "domattribute_value", "domcharacterdata", "domcomment", "domdocument", "domdocument_add_root", "domdocument_create_attribute", "domdocument_create_cdata_section", "domdocument_create_comment", "domdocument_create_element", "domdocument_create_element_ns", "domdocument_create_entity_reference", "domdocument_create_processing_instruction", "domdocument_create_text_node", "domdocument_doctype", "domdocument_document_element", "domdocument_dump_file", "domdocument_dump_mem", "domdocument_get_element_by_id", "domdocument_get_elements_by_tagname", "domdocument_html_dump_mem", "mysql_get_client_info", "mysql_get_host_info", "mysql_get_proto_info", "mysql_get_server_info", "mysql_info", "mysql_insert_id", "mysql_list_dbs", "mysql_list_fields", "mysql_list_processes", "mysql_list_tables", "mysql_num_fields", "mysql_num_rows", "mysql_pconnect", "mysql_ping", "mysql_query", "mysql_real_escape_string", "mysql_result", "mysql_select_db", "mysql_set_charset", "mysql_stat", "mysql_tablename", "mysql_thread_id", "mysql_unbuffered_query", "mysqli", "mysqli_bind_param", "mysqli_bind_result", "mysqli_client_encoding", "mysqli_disable_reads_from_master", "mysqli_disable_rpl_parse", "mysqli_driver", "mysqli_enable_reads_from_master", "mysqli_enable_rpl_parse", "mysqli_escape_string", "mysqli_execute", "mysqli_fetch", "mysqli_get_metadata", "mysqli_master_query", "mysqli_param_count", "mysqli_report", "mysqli_result", "mysqli_rpl_parse_enabled", "mysqli_rpl_probe", "mysqli_rpl_query_type", "mysqli_send_long_data", "mysqli_send_query", "mysqli_set_opt", "z..."); foreach ($badFunctions as $disable) { if (function_exists("$disable")) die("Unsafe function '$disable' found. Aborting!\n"); } ?>
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Now choke yourself!
Industry Role:
Join Date: Apr 2006
Posts: 12,085
|
Yes, the first version of my post had every known PHP function. Obviously, the board puked on a message that long.
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
I didn't write this script and collected good revenue from this post.
![]() Anyone bashing this script either didn't read the full thread or doesn't understand it's purpose. This is NOT a full security solution designed to replace premium hardware appliance firewalls. This is NOT a single solution, but works well as a layer in a multiple layer of defense setup. I agree that "firewall" isn't an appropriate term for the script, although it does provide good protection for vulnerable and commonly targeted webapps. Lastly, you get what you pay for, and anyone mentioning any sort of script as a total solution is a fuckin' idiot who isn't fit to tie their own shoe laces let alone give network security advice. If you want 100% protection unplug the power. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Now choke yourself!
Industry Role:
Join Date: Apr 2006
Posts: 12,085
|
If you want protection, and you pay $85 for a PHP script, I have a wooden knob that makes your sound more true with a digital amp..
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,229
|
They can't block a major ddos attack. I've been coding for years and I don't see any possible way outside of this being a module for apache. The server will still get the requests, still process them and this script will still have to use overhead on top of what the regular requests already do.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 | |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
Quote:
"100% protection guaranteed When properly configured, FWS can block any attacks on your site, guaranteed." ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
Confirmed User
Join Date: Apr 2006
Posts: 308
|
where did I say I wrote the script or this was my site?
I don't even know why I bother responding, not one person in here has read all my responses to the questions in the thread. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 | |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,229
|
Quote:
![]() ![]() ![]()
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 |
Confirmed User
Join Date: Dec 2007
Location: Chatsworth, CA
Posts: 1,964
|
Is this a joke? Protecting from DDOS in PHP? Yeah right!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#41 |
Confirmed User
Industry Role:
Join Date: Sep 2006
Posts: 1,542
|
Ok so its protecting the exploits on current scripts but this script can have exploits on its own.. This is filling water to a leak bottle if you ask me..
__________________
------ Offcourse its a dude posting here. Probably a fut ugly one too. Fuck still people falling for this 100 year old trick |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#42 |
Confirmed User
Industry Role:
Join Date: Sep 2006
Posts: 1,542
|
Suddenly you have nothing to do with this sca errr script?? hmmm I guess this is the punchline lol
__________________
------ Offcourse its a dude posting here. Probably a fut ugly one too. Fuck still people falling for this 100 year old trick |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#43 |
Sofa King Band
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
|
Do you also create php scripts for backpeddling?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#44 | |
Too lazy to set a custom title
Join Date: Dec 2006
Posts: 23,400
|
Quote:
![]() ![]() ![]() I'll do you one better... hit the button called Power - now that's the ultimate firewall.
__________________
i like waffles |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#45 |
Confirmed User
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
|
ust to add a serious re-reply in this thread.
If you're interesed in this type of functionality, consider getting Atomic Secured Linux. http://www.atomicrocketturtle.com/Jo...t/view/137/34/ It's very, very affordable [think $130], runs in the *kernel* layer, [as opposed to php - muffled giggles], and will protect you from ddos to sql injection. I happen to know the guy who writes it - his credentials include 5 years in the whitehouse heading digital security. 'Onlineriches' credentials? who knows... |
![]() |
![]() ![]() ![]() ![]() ![]() |