<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title><![CDATA[Dom Delimar's Little Web Playground Articles]]></title><description><![CDATA[Articles]]></description><link>http://domdelimar.com/</link><copyright><![CDATA[Copyright Dom Delimar's Little Web Playground]]></copyright><generator>sNews CMS</generator><item><title><![CDATA[Additional Article Position Options mod for sNews 1.6]]></title><content:encoded><![CDATA[ <p> Without a doubt, I made my only notable mod so far,  <a href="http://domdelimar.com/snews/additional-article-position-options-mod-snews/"> Additional Article Position Options for sNews 1.5 </a>  out of a necessity. </p> 

 <p> It shows you just how much I need this mod that even though a new version of sNews (1.6) has been out since May 16, 2007 it took me until two weeks ago to migrate from version 1.5.31 to sNews 1.6.0 - all because I had to have my mod even in the new version - and didn't have time to deal with porting it to the new version of sNews. </p> 

 <p> As I was called by  <a href="http://snewscms.com/forum/index.php?topic=1762.msg33046#msg33046" onclick="javascript:urchinTracker('/outgoing/solucija_com_forum_ravingfans');"> raving fans from sNews community </a>  that I make this mod functional for sNews 1.6, I set out to do it. Thanks to that, this website is now on the latest sNews version and other sNews users can now follow the  <a href="http://snewscms.com/forum/index.php?topic=5407" onclick="javascript:urchinTracker('/outgoing/solucija_com_forum_aapo-mod-v16');"> instructions on how to apply the Additional Article Position Options mod </a>  to their sNews 1.6 websites. </p> 

 <p> You have the option of simply taking an already modified clean snews.php file from here: </p> 
  
 <p>  <a href="http://domdelimar.com/goodies/snews.php_add_article_position_mod_v16.tar.bz2" onclick="javascript:urchinTracker('/download/snews.php_add_article_position_mod.tar.bz2');"> snews.php_add_article_position_mod_v16.tar.bz2 </a>  - 22,5KB </p> 
 <p>  <a href="http://domdelimar.com/goodies/snews.php_add_article_position_mod_v16.zip" onclick="javascript:urchinTracker('/download/snews.php_add_article_position_mod.zip');"> snews.php_add_article_position_mod_v16.zip </a>  - 25,3KB </p>  <p> (both files have identical content) </p>   

 <p> I apologize for the wait to everybody using this mod and it would be great to know how many sNews users depend on me to continue developing this mod or at least would like me to do that. </p> 

 <p> Yes, you can tell me by commenting on this article. </p> 
]]></content:encoded><pubDate>Sun, 22 Jul 2007 19:10:06 +0000</pubDate><link>http://domdelimar.com/snews/additional-article-position-options-mod-for-snews-16/</link><guid>http://domdelimar.com/snews/additional-article-position-options-mod-for-snews-16/</guid></item><item><title><![CDATA[dont get mad | you have been hacked]]></title><content:encoded><![CDATA[ <p>   dont get mad | you have been hacked | your security=0 y3v.h4x   was the message I found today after deleting a pornographic banner from the header of my site (sorry for that) and another fishy php file I found on my server. </p> 

 <p> How can I not get mad? When I see a pornographic banner on top of my site. I AM mad. I am VERY mad but I'm going to focus my energy into getting even a more secure system, learning about and promoting security to others. <br /> 
But here is the thing, I've already been quite security aware and my home system is quite secure, if I may say so - definitely more secure than most of them out there. But it seems it wasn't my system that was breached into - it was a  <a href="http://www.solucija.com/forum/viewtopic.php?id=2976" onclick="javascript:urchinTracker('/outgoing/solucija_com_forum');"> vulnerability in the CMS </a>  I use, sNews. </p> 

 <p> I'm thankful to Luka and Mika, main developers of sNews CMS for supplying us all with a patch in less than 24 hours and everybody else who helped solving this. Bravo! </p> 

     <p> I was actually among the fortunate ones as my site didn't go down like it did to a friend of mine  <a href="http://p-ahlqvist.com/" onclick="javascript:urchinTracker('/outgoing/p-ahlqvist_com');"> Patric </a>     for whom I feel very sorry. And everybody else who got somebody crack into their site - that's right, my site wasn't hacked into - as hacking is not all about breaking into other people's sites and posting inadequate content or doing any other harm. These are crackers who just know how to click "OK" and execute some exploit somebody else made. Ha! Hackers - you wish! </p> 

 <p> The first thing you should do now, after applying the patch from  <a href="http://www.solucija.com/forum/viewtopic.php?id=2976" onclick="javascript:urchinTracker('/outgoing/solucija_com_forum');"> sNews forum </a> , and which I recommend to everybody using the sNews CMS is to remove that little notion that says your site was barbecued by this CMS. It's the most obvious one and it won't solve your problem but that's probably the easiest way these crackers can find most of the sNews sites. Everything indicates that these crackers have used that to find sNews sites in this particular case: my logs say that the person who did this came from Google searching for this phrase and the exploit to which  <a href="http://www.solucija.com/forum/viewtopic.php?pid=21036#p21036" onclick="javascript:urchinTracker('/outgoing/solucija_com_forum');"> Luka at sNews Forum indicates </a>  looks like it's made to search for just that. I'll soon put a little picture there instead. </p> 

 <p> As far as I know for now, the cracker left one suspicious php file that my hosting says could be some kind of a shell script used to manipulate with my files but nothing like that happened because my server has phpsuexec option in PHP turned on, whatever that means. </p> 

 <p> Now I've got some questions that are bothering me:
 <ul>  <li> How did the cracker exactly gain control over my site? </li> 
 <li> What exactly did the cracker gain control over? If it was just over my CMS, how did the cracker change my index.php file then? </li>  </ul>  </p> ]]></content:encoded><pubDate>Mon, 15 Jan 2007 00:41:23 +0000</pubDate><link>http://domdelimar.com/snews/dont-get-mad-you-have-been-hacked/</link><guid>http://domdelimar.com/snews/dont-get-mad-you-have-been-hacked/</guid></item><item><title><![CDATA[Additional Article Position Options Mod for sNews 1.5]]></title><content:encoded><![CDATA[ <p> I've been wanting to write a full explanation for this mod where I outline and teach you all the php functions I've learned while cracking this mod, but that turned out to be an awfully lengthy and tedious process for which I don't have time right now. </p> 

 <p> So what I've done is I've implemented the mod into the fresh install of the latest sNews stable version (developers version 1.5.30) which you can download easily and use it as you please.  </p> 

 <p> While I've done everything in my power to make this work, please don't hold me responsible if something doesn't work or if something brakes.  <br />  <strong> It is vital that you backup your snews.php file and your existing MySQL database </strong> , just to be safe and that you can switch back if you wish so later. (Just rename your existing snews.php file into something else and upload this modified one. And I've found some  <a href="http://www.devshed.com/c/a/MySQL/Backing-up-and-restoring-your-MySQL-Database/" onclick="javascript:urchinTracker('/outgoing/devshed_com');"> instructions for backing up your MySQL database </a>  for you if you've never done it before - it's a piece of cake, especially if you have PHPMyAdmin.) </p> 

 <p> I'd appreciate if you'd let me know if you find this mod useful. </p> 

  
 <p>  <a href="http://domdelimar.com/goodies/snews.php_add_article_position_mod.tar.bz2" onclick="javascript:urchinTracker('/download/snews.php_add_article_position_mod.tar.bz2');"> snews.php_add_article_position_mod.tar.bz2 </a>  - 19,9KB </p> 
 <p>  <a href="http://domdelimar.com/goodies/snews.php_add_article_position_mod.zip" onclick="javascript:urchinTracker('/download/snews.php_add_article_position_mod.zip');"> snews.php_add_article_position_mod.zip </a>  - 22,4KB </p>   
 <br /> 
 <p> P.S. I haven't given up from writing the full explanation yet, it's just that this is immediate and the full explanation will have to wait a bit more... </p> 
]]></content:encoded><pubDate>Fri, 08 Dec 2006 22:50:15 +0000</pubDate><link>http://domdelimar.com/snews/additional-article-position-options-mod-snews/</link><guid>http://domdelimar.com/snews/additional-article-position-options-mod-snews/</guid></item></channel></rss>