1 edb Sep 25, 2005 07:22
3 edb Sep 25, 2005 18:16
It was hard doing the mouse and keyboard with my fingers crossed, and it didn't help. "unable to write blahblah conf/_advanced" which I'm guessing is due to permissions of either the folder (755) or file (644). Dunno what those should be changed to, but now you got me thinking. What if conf/_advanced said get the name from the settings table, then change_it changed the appropriate field? Permissions are probably the right place to be, but as a rule I don't dabble in there so...
4 yabba Sep 25, 2005 18:27
Lol, ooops, yeah, forgot to mention that some sort of write access is need to htsrv folder (not the files within) and admin/_advanced.php. I use a windoze server so I dunno what chmod # you need.
I agree, all settings should be in the db, it'd make changes like this far easier to code.
I'm sorry you gnarled your hands due to incomplete instruction, I'll try and do better next time ;)
¥
5 edb Sep 25, 2005 18:50
No problem! As a general rule I'm pretty twisted most of the time anyway ;)
I added this to my watched list, which is mostly how I remember I want to come back to it.
Oh plus adding it to the tools tab was pretty trick. Gonna hafta remember that one...
6 yabba Sep 25, 2005 21:14
Cool, I just used an ftp client (I normally work directly on the server) and it shows chmod#'s.
both folder and file are set @ 554 on my system.
Glad to hear you coped with the gnarled hands, but I already knew you were twisted :P
¥
*edit*
if you're gonna be adding a few hacks to the tools tab, you're probably better changing :-
param('action'..etc
and
$action...etc
to something more "tool specific" ie
param('mytool_action'...etc
and
$mytool_action...etc
or maybe i need to rearrange the order of sleep, alcahol and caffine in my body???
¥
7 esanchez Apr 08, 2006 21:44
have there been any updates to this backoffice hack?
8 yabba Apr 10, 2006 09:04
I haven't done any updates to it.
From what I can tell, spammers now parse your page for the htsrv url, so it kind of makes this hack obsolete.
If you're still interested, then Stk has a [url=http://randsco.com/index.php/2005/11/18/anti_spam_script]this hack[/url] for automatically renaming the htsrv folder.
¥
9 stk Apr 17, 2006 05:22
Fer once, ßlåßßå is correct. ;) (sorry ßlåßßå)
Changing the HTSRV is passe. I do it, using my auto perl script, every 6 hours, but it matters not to slammers. (They must be parsing for file names that are CONTAINED inside the HTSRV folder, which makes the folder name containing them, irrelevant).
On another note ... changing the name of the commenting_posting.php file DOES seem to be (still) foiling the slammers, as ßlåßßå's recent hackage seems to indicate.
He's one smart cookie, our ßlåßßå. :D
admin/_tools.php
create admin/change_it.php
Cross your fingers and hit the back office ;)
¥