News:

Wondering if this will always be free?  See why free is better.

Main Menu

SMF issues with DotDefender?

Started by ModelitMatt, October 31, 2008, 01:04:49 AM

Previous topic - Next topic

ModelitMatt

I have a host that currently purchased DotDefender a script that searches for open holes.

This script does Cross-Site Scripting, SQL Injection, Probing, Known Worms Signatures, Anti-Proxy Protection, Compromised/Hacked Servers, Known Spammer Crawlers, MPack Spammer Crawlers,  MPack Protection.

The question is why is it when this is enabled the forums that all use SMF disable the entire comment section.

All bold, italics, font sizes, everything gets screwed up once that is enabled.

This is a huge issue for my host as they are wanting to keep this script enabled.
This is a huge issue for me as I want the functionality to still exist and I want to continue using SMF.

Please post any information you believe will solve this issue as I have had this issue on a recent freshly installed version of your SMF 2.0 Beta 4.

It seems to block because of a bug somewhere.
Is there a patch I've missed ?

http://mygripetoday.com/gripes/

H

Are you using 1.1.6 or 2.0b4?

Scripts like this are really only useful on sites where there is no user-generated-content (forums, submission forms, etc).

Often words are blocked that could be used to 'hack' the server. However these words are also needed for normal things. Some of these words are things like get and post.

Unless they can provide a better link of what is blocked, they're going to need to disable this script atleast for your site or you'll need to switch hosts.
-H
Former Support Team Lead
                              I recommend:
Namecheap (domains)
Fastmail (e-mail)
Linode (VPS)
                             

ModelitMatt

2.0 b4

Says on very bottom of Gripe Archives.
I had them disable it but I still have no spell check and issues with my quick reply quote... why is it that I'd have to switch hosts should this beta not be secured?

H

Quotewhy is it that I'd have to switch hosts should this beta not be secured?

There is no way for a script to know what is and what is not a security issue. Therefore it is blocking things that could be, but aren't security problems.

Quote
I had them disable it but I still have no spell check and issues with my quick reply quote.

Spell check requires the php pspell extension. Have you checked phpinfo.php to ensure that your host has this? See: What is phpinfo.php?

What is the issue with the quick reply quote?
-H
Former Support Team Lead
                              I recommend:
Namecheap (domains)
Fastmail (e-mail)
Linode (VPS)
                             

ModelitMatt

Having them check phpinfo.php

QuoteWhat is the issue with the quick reply quote?

When set profile to Quick Reply, and attempt it just shows loading bar at top and never sends data to the quick reply box.

Had to make all clients switch off quick reply in profile for quote function to work.

greyknight17

Something is interfering with the quick reply. It works fine here and on my live forum when I do a quick reply quote. What mods do you have installed and did you make any modifications to any of the SMF files? It should work right out of the box....

ModelitMatt

#6
lol I've modded the site multiple times but ever since we transferred the data to a new server spell check has disappeared and the quick reply quote all of a sudden stopped working it was working when we had modded everything successfully.

These issues happened after we transferred the data and are wondering if its files missing or some code corrupted or something.

Edit - Quote issue.:
The Quote function is only disrupted when Quick Reply is enabled.
It works by it self without quick reply enabled but It seems to cause errors when It's enabled and the
Quotebutton is pressed.

Once pressed you see the loading bar but no text is transferred to the input box.

Spell check is back working =) Thanks for the help regarding that issue.

H

Hi, do you still require assistance with this?
-H
Former Support Team Lead
                              I recommend:
Namecheap (domains)
Fastmail (e-mail)
Linode (VPS)
                             

ModelitMatt


Advertisement: