Home
Articles
Forums
Resources
Downloads
Search
Last Visit
IP To Country
Get Album Art
Embed Codes
Music Playlists
Music Search
Music Players
Member Links
Photo Gallery
Random Pic
Support The Cause
Who's Online

Home arrow Last Visit arrow Security arrow Last Visit - Security
Last Visit - Security PDF Print E-mail Submit this story to Propeller
User Rating: / 0
PoorBest 
Last Visit User's Guide - Security
Written by Jason   
Jan 01, 2008 at 04:42 PM

Security is of the utmost importance to me and I have taken additional measures to ensure Last Visit™ is safe from hackers. The only potential security threat I have found so far would be a possible attack on the Last Visit™ job file. Although it has not been an issue in the past, that does not indicate that it never will be an issue in the future. In my experience, I have learned that if it can be exploited it will be exploited. I will not go into describing how the job files can be used in an attack, but I will tell you how to prevent it from happening.

There are 3 files in the root PHP-Nuke directory which control the Last Visit™ processing job. These files are listed below with a description of what you should do to secure them.

  1. lastvisit-job-image.php (rename file and adjust HTML image code to match - the code you installed in the footer message in PHP-Nuke preferences)
  2. lastvisit-job.inc.php (nothing - leave alone or the program will malfunction)
  3. lastvisit_job.php (rename file and adjust setting in Last Visit™ settings panel to match.)

The files can be renamed to anything, but be sure to also adjust your Last Visit™ settings to match in the Last Visit™ settings panel.

How does this help?
This makes it virtually impossible for a hacker to search for your website using the Last Visit™ image code as a key. It also makes it unlikely that hackers would even know you are using Last Visit™ because there would be no such indicator in your website's HTML source code. A hacker cannot exploit the file if he doesn't even know it's name.
User Comments
Please login or register to add comments