Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-02-2008, 10:27 AM   #1
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
:stop World's first PHP FIREWALL Script - Perfect to protect against attackers



FireWall Script

FireWall Script is the world's first fully configurable PHP-based website firewall. It can work with any PHP application, and we even offer "packs" of pre-written rules to protect some of the most popular software such was Wordpress, Invision Power Board, Mambo, Joomla, Drupal, and more! It is so easy beginners can install and use it.

Protect against:

- DDOS Attacks
- Webapp exploits
- Security scans of your assets
- Hackers & common embedding viruses

Features of FireWall Script:
* Can work with any PHP script
* Included admin control panel allows full configuration of the software
* Support for multiple administrators. You can add, edit, and delete accounts from the admin panel.
* Admin panel update notification and news feeds keep you up to date on FWS
* Fully configurable DOS protection allows you to block access to your site for a user when they have multiple requests in a short period of time
* Fully configurable rules
* CAPTCHA support in rules allows you to show a CAPTCHA verification on any matched request
* Akismet integration allows you to do everything you can with rules when submitted text is identified as spam
* Admin login logs allow you to keep track of which administrators are using the admin panel
* Traffic logs for all traffic on your site (archived daily)
* Blocked request logs show you what was blocked and show you everything PHP had available during the request so you can review blocked requests
* Spam logs show you requests identified as spam through Akismet
* DOS logs show you requests identified as DOS attacks and subsequently blocked
* Help section gives you quick access to support for the software
* Specify rule title, notes and category for your own referencing and categorization
* Ability to log requests blocked by rule
* Ability to get email notifications for requests blocked by rules
* For requests matching a rule you can allow the request, exit script execution, show an error, show specified HTML, redirect to another page, execute a custom php plugin, or even show a CAPTCHA verification
* Ability to look in all PHP superglobals
* Full regex power gives you the ability to look for what you want, where you want

Check out FireWall Script for more information and product pricing.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:30 AM   #2
digifan
The Profiler
 
digifan's Avatar
 
Industry Role:
Join Date: Oct 2002
Location: ICQ 76281726 and I'm female
Posts: 14,618
$85... it will sell. Good luck!
__________________
[email protected]
Webair Rocks
digifan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:32 AM   #3
bareskin
Confirmed User
 
bareskin's Avatar
 
Join Date: Nov 2006
Location: Pimpin in socal
Posts: 619
NIce good luck
__________________
Globat.com hosting company has shitty customer service skills :: please be advised::

Icq# 394599740
bareskin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:34 AM   #4
ScriptWorkz
Confirmed User
 
Industry Role:
Join Date: Jul 2007
Location: Intraweb
Posts: 274
What kind of overhead does all this nifty stuff before each request cause?
ScriptWorkz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:35 AM   #5
Nookster
Confirmed IT Professional
 
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
A firewall coded in PHP? That's definitely a first.
Nookster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:40 AM   #6
macker
Confirmed User
 
macker's Avatar
 
Join Date: Jul 2003
Location: www.FetishAssets.com
Posts: 2,161
I like the sound of this script
macker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:42 AM   #7
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
LOL it's not first there is already tons of script as this.And they are free.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:48 AM   #8
StuartD
Sofa King Band
 
StuartD's Avatar
 
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
100% protection guaranteed

Bold statement. And if you're proven wrong, how much will that cost you?
StuartD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:49 AM   #9
Nookster
Confirmed IT Professional
 
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
Quote:
Originally Posted by KlenTelaris View Post
LOL it's not first there is already tons of script as this.And they are free.
Uhm, not quite. There's generators, but not full-blown firewalls. Point some out if you think I'm wrong. And by the way, a firewall coded in PHP is vulnerable to everything PHP is. I would have coded one in C if you wanted to get the job done right.
Nookster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 10:53 AM   #10
payd2purv
Too lazy to set a custom title
 
payd2purv's Avatar
 
Join Date: Jan 2008
Location: Toronto
Posts: 2,727
Sounds interesting!
__________________
payd2purv is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 11:16 AM   #11
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by digifan View Post
$85... it will sell. Good luck!
Thank you for the kind words.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:02 PM   #12
ScriptWorkz
Confirmed User
 
Industry Role:
Join Date: Jul 2007
Location: Intraweb
Posts: 274
Quote:
Originally Posted by Nookster View Post
Uhm, not quite. There's generators, but not full-blown firewalls. Point some out if you think I'm wrong. And by the way, a firewall coded in PHP is vulnerable to everything PHP is. I would have coded one in C if you wanted to get the job done right.
I think firewall is more of a marketing term, it's supposed to be blanket protection for php scripts, etc.. but either way your right, it's still vulnerable to everything php is (as far as actual php exploits, not saying it's coded poorly and allows mysql injection, etc..). And also, if it's written in php, unless they've found some crazy voodoo shit, this code is being executed ontop of the script already being executed for anything it's protected, which could be an issue on high traffic sites (wish we could get an answer on overhead).

Either way, i agree, if you wanted to do this right, you should of wrote an apache module / php extension or something w/ a compiled language, this isn't something i feel should be scripted.
ScriptWorkz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:10 PM   #13
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
i doubt that php script can block a major ddos attack.

dont provide promises you cant keep
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:13 PM   #14
StuartD
Sofa King Band
 
StuartD's Avatar
 
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
Quote:
Originally Posted by Fris View Post
i doubt that php script can block a major ddos attack.

dont provide promises you cant keep
Heh, I was just going to ask how a php script manages to prevent packet bombardment, billions of ping requests or even img sourcing.

A ddos attack happens at the server level, long before any php script ever gets run.
StuartD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:18 PM   #15
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by ScriptWorkz View Post
I think firewall is more of a marketing term, it's supposed to be blanket protection for php scripts, etc.. but either way your right, it's still vulnerable to everything php is (as far as actual php exploits, not saying it's coded poorly and allows mysql injection, etc..). And also, if it's written in php, unless they've found some crazy voodoo shit, this code is being executed ontop of the script already being executed for anything it's protected, which could be an issue on high traffic sites (wish we could get an answer on overhead).

Either way, i agree, if you wanted to do this right, you should of wrote an apache module / php extension or something w/ a compiled language, this isn't something i feel should be scripted.
This isn't something to be run on a standard site such as a TGP or paysite. This is to protect common webapps such as wordpress, invision power board, vbulletin, joomla, which have widespread use and are often mass defaced or compromised. Custom rulesets are available for free in the members area for each application.

There is obviously a small amount of overhead, but unless you are pushing 25mb/s traffic all day you will not notice any impact.

Regarding PHP vulnerabilities, it has nothing to do with the script and is entirely PHP. If you are running the latest stable version of PHP and apply updates as they are released you will not have any problems. PHP is the issue, not the script, and saying that this script will not improve security is very misleading.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:23 PM   #16
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
Three words:
Atomic Secured Linux

Filter this shit out in the kernel.
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:25 PM   #17
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by Fris View Post
i doubt that php script can block a major ddos attack.

dont provide promises you cant keep
Thinking this is comprable to a $50,000 hardware appliance is ignorant. It will block small ddos attacks directed at your website, not a bandwidth consumption ddos attack.

As mentioned this is a script to provide additional security for blogs, forums, and template type websites that use joomla, mambo, etc.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:48 PM   #18
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
firewall written in php makes as much sense as a solar powered flashlight...
but I guess there are ton of clueless idiots out there, it should sell well
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 12:57 PM   #19
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by woj View Post
firewall written in php makes as much sense as a solar powered flashlight...
but I guess there are ton of clueless idiots out there, it should sell well

you are obviously one of them, you do not even understand the practical uses for this. go crying to the forums next time your blog gets hacked.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 01:00 PM   #20
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by Nookster View Post
Uhm, not quite. There's generators, but not full-blown firewalls. Point some out if you think I'm wrong. And by the way, a firewall coded in PHP is vulnerable to everything PHP is. I would have coded one in C if you wanted to get the job done right.
Whatever,since i installed script which i use for security,i have no problems with hackers anymore.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 01:49 PM   #21
Sansa
Confirmed User
 
Join Date: Apr 2007
Posts: 293
Hate to rain on your parade... http://php-ids.org/
Sansa is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 01:54 PM   #22
Thumbnailer
Confirmed User
 
Thumbnailer's Avatar
 
Join Date: Jun 2003
Posts: 127
if you want to protect mambo, joomla or wordpress blog... install some antispam protection OR hire a pro to modify your server/script
__________________
FREE DOMAINS (3rd level) - USA.CC and more -- it should be free in The Communist Era
Thumbnailer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 02:45 PM   #23
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Quote:
Originally Posted by onlineriches View Post
you are obviously one of them, you do not even understand the practical uses for this. go crying to the forums next time your blog gets hacked.
You clearly have no clue who he is.

He has forgotten more about coding than you will ever know. He's widely known to be one of the best programmers in the business. Now, who are you?
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 02:48 PM   #24
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by Sansa View Post
Hate to rain on your parade... http://php-ids.org/
Nice,i wonder does it have anything more of script which i use.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 02:50 PM   #25
tomud
Confirmed User
 
Join Date: Jun 2002
Location: $$$
Posts: 7,993
nice, good job

Tomud
__________________


AFF – up to $1.50 per free join, $130 per order ! NASTYDOLLARS - 35$ PPS ! Free hosted galleries !
ADULTDATELINK$42 PPS, 50% REV ! DATINGGOLD - 100% !!! REV, $4 per email !
Adult Sponsors Reviews – take a look at the best adult programs !
Epassporte Sponsors

ICQ: 160168237
tomud is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 02:59 PM   #26
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by Sansa View Post
Hate to rain on your parade... http://php-ids.org/
Hate to rain on your parade, but IDS = intrusion DETECTION system will let you know you are getting hacked, but will do nothing stop the attacks.

Quoted directly from their website:

"The IDS neither strips, sanitizes nor filters any malicious input, it simply recognizes when an attacker tries to break your site and reacts in exactly the way you want it to. Based on a set of approved and heavily tested filter rules any attack is given a numerical impact rating which makes it easy to decide what kind of action should follow the hacking attempt."
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 03:01 PM   #27
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by Thumbnailer View Post
if you want to protect mambo, joomla or wordpress blog... install some antispam protection OR hire a pro to modify your server/script
antispam will do nothing to stop your site or blog from being compromised, it will just filter out annoying spam messages.

Why hire a pro to manage your blog when this software does everything you need?
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-02-2008, 08:26 PM   #28
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
dont waste your money
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:07 AM   #29
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
I'm still waiting for the punchline.
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:13 AM   #30
JDog
Confirmed User
 
Join Date: Feb 2003
Location: Canby, OR
Posts: 7,453
Quote:
Originally Posted by ScriptWorkz View Post
Either way, i agree, if you wanted to do this right, you should of wrote an apache module / php extension or something w/ a compiled language, this isn't something i feel should be scripted.
I fully agree, that if you're going to try to add "protection" that you shouldn't make a PHP script, it should be a actual extension to PHP or better yet what you mentioned apache module, which I, myself, feel would be better than a extension to PHP. It could do better. I honestly wouldn't pay $85 for a php script called a "firewall".
__________________
NSCash now powering ReelProfits.com
ALSO FEATURING: NSCash.com :: SoloDollars.com :: ReelProfits.com :: BiminiBucks.com :: VOD
PROGRAMS COMING SOON: Greedy Bucks :: Vengeance Cash
NOW OFFERING OVER 60 SITES
CONTACT :: JAMES SMITH :: CHIEF TECHNOLOGY OFFICER :: ICQ (711385133)
JDog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:16 AM   #31
JDog
Confirmed User
 
Join Date: Feb 2003
Location: Canby, OR
Posts: 7,453
One great apache module that will prevent most of the sql injection is MOD_SECURITY for apache. Much better than going with this will do, and it is FREE!
__________________
NSCash now powering ReelProfits.com
ALSO FEATURING: NSCash.com :: SoloDollars.com :: ReelProfits.com :: BiminiBucks.com :: VOD
PROGRAMS COMING SOON: Greedy Bucks :: Vengeance Cash
NOW OFFERING OVER 60 SITES
CONTACT :: JAMES SMITH :: CHIEF TECHNOLOGY OFFICER :: ICQ (711385133)
JDog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:20 AM   #32
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Mine's free.

<?php
$badFunctions = array( "a...", "dom_import_simplexml", "domattr", "domattribute_name", "domattribute_set_value", "domattribute_specified", "domattribute_value", "domcharacterdata", "domcomment", "domdocument", "domdocument_add_root", "domdocument_create_attribute", "domdocument_create_cdata_section", "domdocument_create_comment", "domdocument_create_element", "domdocument_create_element_ns", "domdocument_create_entity_reference", "domdocument_create_processing_instruction", "domdocument_create_text_node", "domdocument_doctype", "domdocument_document_element", "domdocument_dump_file", "domdocument_dump_mem", "domdocument_get_element_by_id", "domdocument_get_elements_by_tagname", "domdocument_html_dump_mem", "mysql_get_client_info", "mysql_get_host_info", "mysql_get_proto_info", "mysql_get_server_info", "mysql_info", "mysql_insert_id", "mysql_list_dbs", "mysql_list_fields", "mysql_list_processes", "mysql_list_tables", "mysql_num_fields", "mysql_num_rows", "mysql_pconnect", "mysql_ping", "mysql_query", "mysql_real_escape_string", "mysql_result", "mysql_select_db", "mysql_set_charset", "mysql_stat", "mysql_tablename", "mysql_thread_id", "mysql_unbuffered_query", "mysqli", "mysqli_bind_param", "mysqli_bind_result", "mysqli_client_encoding", "mysqli_disable_reads_from_master", "mysqli_disable_rpl_parse", "mysqli_driver", "mysqli_enable_reads_from_master", "mysqli_enable_rpl_parse", "mysqli_escape_string", "mysqli_execute", "mysqli_fetch", "mysqli_get_metadata", "mysqli_master_query", "mysqli_param_count", "mysqli_report", "mysqli_result", "mysqli_rpl_parse_enabled", "mysqli_rpl_probe", "mysqli_rpl_query_type", "mysqli_send_long_data", "mysqli_send_query", "mysqli_set_opt", "z...");
foreach ($badFunctions as $disable) {
if (function_exists("$disable"))
die("Unsafe function '$disable' found. Aborting!\n");
}
?>
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:22 AM   #33
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Yes, the first version of my post had every known PHP function. Obviously, the board puked on a message that long.
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:28 AM   #34
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
Quote:
Originally Posted by GrouchyAdmin View Post
I'm still waiting for the punchline.
I didn't write this script and collected good revenue from this post.

Anyone bashing this script either didn't read the full thread or doesn't understand it's purpose.
This is NOT a full security solution designed to replace premium hardware appliance firewalls. This is NOT a single solution, but works well as a layer in a multiple layer of defense setup.

I agree that "firewall" isn't an appropriate term for the script, although it does provide good protection for vulnerable and commonly targeted webapps.

Lastly, you get what you pay for, and anyone mentioning any sort of script as a total solution is a fuckin' idiot who isn't fit to tie their own shoe laces let alone give network security advice. If you want 100% protection unplug the power.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 12:29 AM   #35
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
If you want protection, and you pay $85 for a PHP script, I have a wooden knob that makes your sound more true with a digital amp..
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 10:49 AM   #36
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,229
Quote:
Originally Posted by Fris View Post
i doubt that php script can block a major ddos attack.

dont provide promises you cant keep
They can't block a major ddos attack. I've been coding for years and I don't see any possible way outside of this being a module for apache. The server will still get the requests, still process them and this script will still have to use overhead on top of what the regular requests already do.

Last edited by k0nr4d; 05-03-2008 at 10:51 AM..
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 11:12 AM   #37
StuartD
Sofa King Band
 
StuartD's Avatar
 
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
Quote:
Originally Posted by onlineriches View Post
Lastly, you get what you pay for, and anyone mentioning any sort of script as a total solution is a fuckin' idiot who isn't fit to tie their own shoe laces let alone give network security advice. If you want 100% protection unplug the power.
Your site states:
"100% protection guaranteed
When properly configured, FWS can block any attacks on your site, guaranteed."

StuartD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 11:19 AM   #38
onlineriches
Confirmed User
 
Join Date: Apr 2006
Posts: 308
where did I say I wrote the script or this was my site?

I don't even know why I bother responding, not one person in here has read all my responses to the questions in the thread.
onlineriches is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 11:29 AM   #39
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,229
Quote:
Originally Posted by StuartD View Post
Your site states:
"100% protection guaranteed
When properly configured, FWS can block any attacks on your site, guaranteed."

proper configuration being "deny from *.*.*.*"
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 04:27 PM   #40
brandonstills
Confirmed User
 
brandonstills's Avatar
 
Join Date: Dec 2007
Location: Chatsworth, CA
Posts: 1,964
Is this a joke? Protecting from DDOS in PHP? Yeah right!
brandonstills is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 04:35 PM   #41
ro8in
Confirmed User
 
ro8in's Avatar
 
Industry Role:
Join Date: Sep 2006
Posts: 1,542
Ok so its protecting the exploits on current scripts but this script can have exploits on its own.. This is filling water to a leak bottle if you ask me..
__________________
------
Offcourse its a dude posting here. Probably a fut ugly one too. Fuck still people falling for this 100 year old trick
ro8in is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-03-2008, 04:42 PM   #42
ro8in
Confirmed User
 
ro8in's Avatar
 
Industry Role:
Join Date: Sep 2006
Posts: 1,542
Quote:
Originally Posted by onlineriches View Post
I didn't write this script and collected good revenue from this post.
Suddenly you have nothing to do with this sca errr script?? hmmm I guess this is the punchline lol
__________________
------
Offcourse its a dude posting here. Probably a fut ugly one too. Fuck still people falling for this 100 year old trick
ro8in is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2008, 04:38 AM   #43
StuartD
Sofa King Band
 
StuartD's Avatar
 
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
Quote:
Originally Posted by onlineriches View Post
where did I say I wrote the script or this was my site?

I don't even know why I bother responding, not one person in here has read all my responses to the questions in the thread.
Do you also create php scripts for backpeddling?
StuartD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2008, 06:59 AM   #44
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
Quote:
Originally Posted by GrouchyAdmin View Post
Mine's free.

<?php
$badFunctions = array( "a...", "dom_import_simplexml", "domattr", "domattribute_name", "domattribute_set_value", "domattribute_specified", "domattribute_value", "domcharacterdata", "domcomment", "domdocument", "domdocument_add_root", "domdocument_create_attribute", "domdocument_create_cdata_section", "domdocument_create_comment", "domdocument_create_element", "domdocument_create_element_ns", "domdocument_create_entity_reference", "domdocument_create_processing_instruction", "domdocument_create_text_node", "domdocument_doctype", "domdocument_document_element", "domdocument_dump_file", "domdocument_dump_mem", "domdocument_get_element_by_id", "domdocument_get_elements_by_tagname", "domdocument_html_dump_mem", "mysql_get_client_info", "mysql_get_host_info", "mysql_get_proto_info", "mysql_get_server_info", "mysql_info", "mysql_insert_id", "mysql_list_dbs", "mysql_list_fields", "mysql_list_processes", "mysql_list_tables", "mysql_num_fields", "mysql_num_rows", "mysql_pconnect", "mysql_ping", "mysql_query", "mysql_real_escape_string", "mysql_result", "mysql_select_db", "mysql_set_charset", "mysql_stat", "mysql_tablename", "mysql_thread_id", "mysql_unbuffered_query", "mysqli", "mysqli_bind_param", "mysqli_bind_result", "mysqli_client_encoding", "mysqli_disable_reads_from_master", "mysqli_disable_rpl_parse", "mysqli_driver", "mysqli_enable_reads_from_master", "mysqli_enable_rpl_parse", "mysqli_escape_string", "mysqli_execute", "mysqli_fetch", "mysqli_get_metadata", "mysqli_master_query", "mysqli_param_count", "mysqli_report", "mysqli_result", "mysqli_rpl_parse_enabled", "mysqli_rpl_probe", "mysqli_rpl_query_type", "mysqli_send_long_data", "mysqli_send_query", "mysqli_set_opt", "z...");
foreach ($badFunctions as $disable) {
if (function_exists("$disable"))
die("Unsafe function '$disable' found. Aborting!\n");
}
?>


I'll do you one better... hit the button called Power - now that's the ultimate firewall.
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-04-2008, 08:08 AM   #45
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
ust to add a serious re-reply in this thread.

If you're interesed in this type of functionality, consider getting Atomic Secured Linux.
http://www.atomicrocketturtle.com/Jo...t/view/137/34/

It's very, very affordable [think $130], runs in the *kernel* layer, [as opposed to php - muffled giggles], and will protect you from ddos to sql injection.

I happen to know the guy who writes it - his credentials include 5 years in the whitehouse heading digital security.

'Onlineriches' credentials? who knows...
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.