Jump to content

wimg

Clients
  • Posts

    739
  • Joined

 Content Type 

Downloads

Release Notes

IPS4 Guides

IPS4 Developer Documentation

Invision Community Blog

Development Blog

Deprecation Tracker

Providers Directory

Forums

Events

Store

Gallery

Everything posted by wimg

  1. Thank you, Marc! And so am I! Took quite a long session with Support, they had trouble finding it too - not too familiar with the second security system yet. Kind regards, WIm
  2. I will do so. I never had this problem in the past, however. I also noticed in the mean time, that there are now 2 'Standard' methods under Login & Registration, aklthough we have only a single one activated, essentially the old one. I'll report back on any findings.
  3. Since the upgrade we did, going from ICS 4.6.8 to 4.6.10 and then 4.7.10, on May 15, we noticed that new registrations appear 3 times in the Member list, and upon checking the database, the same is actually true for the core_members table itself. IOW, since the upgrade, every new member registration creates 3 new members with exactly the same data. Any idea what is going on here? Thank you in advance. Kind regards, Wim
  4. Looks like the problem is solved now. It was a combination of a Joomla plugin exploit bug which appears to be used by Marketplace, and an upload problem, and covered by both security modules which are installed as a standard on our server, although they deal slightly differently with it. Disabling the rules in mod_security and in the 2nd security module fixed this. For mod_security, upload, it was: Request: POST /forum/admin/?app=core&module=applications&controller=applications&appKey=news&do=upload Action Description: Access denied with code 406 (phase 2). Justification: File "/tmp/20230520-145930-ZGjgUoQWffAZPv8BC0az9wACVBc-file-yAgo53" rejected by the approver script "/etc/cxs/cxscgi. And for Marketplace, the Joomla exploit problem, which actually results in 3 error messages: Request: GET /forum/admin/?app=core&module=applications&controller=plugins&do=doInstall&file=/tmp/IPSMPKovG0x&key=d20a4618bdf9a0118256585816f3a9ab&id=10&csrfKey=c76034ce3b5af74eb2764c97bab4ca77&marketplace=7542&mr=0&_mrReset=1&csrfKey=c76034ce3b5af74eb2764c97bab4ca77 Action Description: Access denied with code 406 (phase 2). Justification: Pattern match "(/tmp|/proc|/dev)" at REQUEST_URI. We still have one other problem, but that has to do with image uploads to the Gallery and is very specific. I will have to investigate that first myself, to see if I can recreate that. Anyway, thanks for all the support from everybody, much appreciated! Kind regards, WIm
  5. Yes, I did. It is not their software. No idea yet what causes it. I have now uninstalled almost every bit of software that has this problem, except 2 add-ons which have a version that works just fine without the update, and is PHP 8-compliant anyway, even though the others were too. The reason for keeping those is for testing purposes as well, to see if I can finally get rid of the problem. O, the apps that work fine are from the same authors. No idea why some, a minority, work and others don't. I did find that we are running an additional security package on our server in the mean time, one we did not have on our previous server, and it is something we cannot control like you do with mod_security. So i have created a ticket for hosting support as a result. In the mean time, any ideas are welcome. I will try a manual upload as far as possible, but I need a reply from one of the authors first. No idea where to upload the contents of an unzipped .tar file to. It is not clear from the directories it creates. Kind regards, Wim
  6. Hi Randy, I have been looking around, but other than the menu settings for FURLs, I have no idea what I should eb looking for. As the error logs mostly showed data from dates prior to the upgrade, I cleared the logs, to ssee what will show up next when I try again, but so far, nothing. The weird thing is that some of the upgrades worked just fine, but now i am stuck with 30+ which do not, but should according to Marketplace. There always is an Install or Upload option, and when I use those, something will start up, but the moment it goes away to do its thing, within a couple of seconds it turns up the error message. As mentioned, I turned off Mod_security, but as that didn't change anything, and i noticed a few attempts at invalid data insertions, I turned it on again, especially as we did have a hacking problem, be it people taking over accounts from not very security conscious members, and posting spam like crazy. If you have any suggestions, I would appreciate it. Kind regards, WIm
  7. Well, Mod_security was on, indeed, but switching it off, and rebooting, made no difference. If anybody has another idea of what could be causing this, I'd appreciate it. Thank you very much in advance! Kind regards, WIm P.S.: I did reboot the server after resetting and saving the Mod_security settings.
  8. We have gone through extensive testing and checks. Only 2 were not compatible, and those were disabled anyway. And yes, 60 is a lot. As mentioned, we currently only use 35 of them , which stiil is a lot. It just shows that the 3rd party community provides a very useful service, the way we see it 😃. We manage our own server, but we do have full support if so required. I just realized we moved to a new server a couple of months ago, as a first step to doinG complete upgrades for everything, including PHP and database. It could well be that mod_security has been enabled for everything again - that was one are we did not check. I'll report back if that indeed solves the issue. Thank you for the heads-up and quick reply, much appreciated! Kind regards, WIm
  9. We upgraded from Sunday on Monday from 4.6.8 to 4.6.10 and next to 4.7.10. That went well no problems with the Community Suite so far. However, trying to upgrade many of our addons, applications and plugins, resulted in multiple errors, with an error message "Sorry! The page you requested does not exist", while we still have a valid subscription, and an Install option for each of them. We have 60 add-ons, of which we are currently using 35 actively. The inactive ones, as far as we tried, give the same results.. Any idea what could be causing this and what we need to do to solve this problem? This happened both in 4.6.10 and in 4.7.10, whatever we tried. Prior to doing the ICS-upgrade we did test everything, because of the required upgrade to PHP 8.x, and it did the same during our tests, although all apps and plugins did not stop working. What we did notice, however, is that we did not get a proper default theme, as it still contains the additions we made to it, for Google and advertising. Could it possibly be that this is what is causing the trouble? Thank you very much in advance! Kind regards, Wim
  10. OK. Could you maybe ask him to clear all browser history, cookies and temp files, and see if it still happens? If you haven't that is. Many people never do this, or not often enough, and I have seen weird things happen as a result, f.e., a user who got the wrong pictures in a post he was reading, and that is just the tip of the iceberg. People who couldn't save anything, etc. HTH, kind regards, Wim
  11. Did you check if thsi works OK in a normal post?
  12. Hi guys, thank you both! Marc already replied to the Support Request I created around 5 am local time, out of desperation. It appears that that was a column in core_pfields from more than 11 years ago, StopForumSpam, which we used when there wasn't much else, with version 2.x of the forum software. It looks like it never did uninstall properly when we moved on, and it has been hiding there for all those years, and now finally causing problems with the very much stricter MariaDB 10.3 version when it comes to non-default values :). It looks fixed now I deleted the column, but I will keep an eye on it :). Kindest regards, Wim
  13. When trying to ad a new member via the ACP, I get the following errors: And: IOW, that is an error when it tries ot insert it more than once, as far as I can see. Oh, the user does get added, BTW. Really strange. No idea why. My.cnf has been minimalized now, so MariaDB is runnign more or less with defaults as far as possible with a large database (11 GB) and 114K registered members. We are using Centos 7.9 and cPanel latest version, with 4xSSD in RAID for data and another 4xSSD for the database, also RAID, 128GB DRAM, 32 cores (ntel Dual Xeon Gold 6226R), and a spindle drive for back-ups. If anybody has an idea, it would be greatly appreciated. Kind regards, Wim P.S.: replaced actual user with "user" and the database name with "database".
  14. I spoke too soon, it still happens with Classifieds as well.
  15. Yes, for every account since upgrading to MariaDB 10.3 about 14 hours ago. I did soem test myself over th elast few hours, and now it either rejects completely, or adds 3 registrations. I think the error triggers because it registers each registration 3 times. They do not go through email validation anymore either, they are promoted straight to the first member group upon validation. Really weird. I am digging into configuration settings in my.cnf, but so far have not found anything yet. The weird thing is that this actually happened in the Classifieds add-on, and only there, prior to upgrading, but that appears to be fine now. The error there was a 1054. Kind regards, Wim
  16. Hi All, After upgrading from MariaDB 10.0 to 10.3 I suddently get errors when new members register. The following error message is dispalyed: Now, what happens behind the scenes is that every new registration is recorded in triplicate, IOW, 3 new registrations for each registration attempt, so the error message is very likely caused by the system trying to register the same info three times, with keys staying the same, and hence causing this error. Any idea how I could solve this? Is this maybe a setting in my.cnf, and if so what? I tried playing around with the settings, but cannot solve it somehow. Thank you very much in advance for any assistance with this problem. Kind regards, Wim
  17. Thank you, CoffeeCake, your assistance with this problem is very much appreciated! I'll make sure to follow your instructions! I'll also report back my results here, both on GA, script and pageviews, as on the other scripts. Warm regards, WIm
  18. Ok, thank you. I still want GA to deal with every page, so I guess I should use the GA option for ddynamically generated pages, and then put everything else in the globalTemplate header (Alexa and advert scripts). Correct? My only hassle is that one of the two advert scripts deals with pages on a similar basis as the GA pages - otherwise I will get paid for 1.2 to 2 million views rather than 11.8 million 🙂. Should I try putting it in the GA box, inderneath the GA script, and see what it does? Kind regards, Wim
  19. Thank you, CoffeeCake. I'll switch of Ajax pagination to start with, and check what that will do to GA for pageviews. As to the advertising code: I need to call a piece of standard js, which has to be in the header, and per advert a div with a unique identifier which that js actually knows. This is not Google Adsense, BTW, something different. Neither am I using the default advertising stuff as far as it is part of the ICS. I am actually using a very versatile custom made add-on, which allows me to do a lot more, and have easy control over displaying a variety of adverts, in a variety of positions, forums, apps, member groups, themes, allowing all ads to be switched off or specific ones, etc., etc. This for each advert individually, or for groups of advert, or both. Anyway, what you are basically saying, if I understand it correctly, is to switch of Ajax pagination for GA, and put my advertising javascript code in the headers of each and every theme - exactly that which I wanted to avoid :). I really thought the analytics stuff was goign to help, basically as what it should do, and as far I understand does as well, is place the specific piece of code in the header of each page, where I would want it. Please do correct me if I am wrong. Kind regards, WIm
  20. Thank you for your quick reply, much appreciated! Yes, I have. Should I switch that off? I also have fluid wdth switched on.which is the next option. In addition, the one thereafter, "Javascript include location" is set to "Just before </body> tag". Should I switch this to "Inside the <head>"? Thank you in advance! Kind regards, Wim
  21. Hi All, GA (Google Analytics) currently reports about 1.5 to 2 million pageviews per month for my site, while AWstats actually reports 11.8 million, this with ICS 4.5.4.2. The discrepancy is huge, IOW, a multiple of what it was with 3.4.x, when the factor difference was about 2. On the Analytics page in the ACP, you can actually enter GA code, Matomo, etc. However, it appears to be muttually exclusive because it empties the 2nd and 3rd block when you use any of the other options. Which means the only choice is to use the "Other" field and copy all of your code there. This is needed too, I guess, for advertising scripts and such, which require parts to be in the header. In the past I used to put all of these codes in each theme separately, in the globalTemplate for each theme. Storing these codes in a single, general ACP space is much more convenient, because it does not require you to alter themes over and over again after an update or upgrade.So, I really like the new option to do this :). It appears however, that the different spaces for the different analytics services are mutually exclusive. I also realize there is the option now to add the GA code in a separate space, which is supposed to put it in every generated page - that should get around the reported pageviews problem. However, whenever I try that, the site just hangs. This may be caused because of the other js code I also put in these spaces, or I am maybe overlookign something, but it really only happens upon copying the GA code to that area. Below is the "Other" option in Analytics, with advertising script added. Now, if you add that code to the pagination block as well, you get the following: So, 4 blocks all of a sudden. Now the question rises, where would I have to put what, and do I have to repeat any of the code? Do I put GA code in the top block, and in the 4th from the top, or just at the top? Where do I put any Matomo code? Only in the 2nd block, or in 2nd and 4th? And advertising js, for which I have 2 scripts, where would I put that? Only in the 3rd block, or in 3rd and 4th? Or all different again? Any help with this would greatly be appreciated. Thank you in advance. Kind regards, Wim P.S.: Putting the advertising scripts in block 4 makes the site hang too, even if it is the only place where it is present.
  22. H C, you are a saint as to how patient you are. As to problems I have found so far: What about the triple saves of each classified? What about loss of images if a user edits a classified? Why does it allow to save a classified with added, mandatory fields not filled? Why is there a selection column in ACP f.e. in deleted classifieds which serves no purpose? Still lhave to delete them one by one. Why can I only show 10 classifieds at a time in ACP? Why can I not show a mix of all classifieds over different categories in one view? Etc., etc., etc. I am really getting frustrated waiting for a fix for some of the bugs, let alone essential functionality. I bought 2 copies, one for testing, but I don't need to test, my users do it for me. And they are not happy. Neither am I. I only noticed this stuff was in beta when I installed my copies. How the heck can you actually sell something that is in beta? Come on. BTW, I would call this alpha, not beta. All it does is look pretty, but not much else, and not even that pretty. Andy Milne's Classifieds for 3.4.x worked way better, even though that had a few tiny bugs, and really only because it was noi longer supported for the latest versions of 3.4.x. What a mess. I am deeply disappointed. Regards, Wim
  23. That is marvelous, thank you. Since you mention PHP-configuration, which variables need to be configured (while we wait for 4.5.5)? I am asking because we have a very large board, (4.3 million posts) with many add-ons, we upgraded from 3.4.8 to 4.5.4, and find that as the only real admin, I need to answer a lot of questions to explain stuff to our memebrs, while in the mean time trying to configure everything correctly and conform our wishes through the ACP. Thank you very much in advance! Kindest regards, Wim
  24. Any solution yet? I am really gettign stupidly annoyed by it. In addiion, I hat losing changes when still typing and or checkign out things. I donn't particularly want to save every few minutes if I am still figurign out what I need to set up. Also, the time-out is way less than 30 minutes on my installation of 4.5.4. Thank you in advance! Kind regards, Wim
  25. Thank you, Steph. Where do I actually report bugs, do you know? I found it actually stores each classified 3 times, and gives an error because it uses the same index values each time. I actually have it in production. It is being sold here in the Market Place, so I expected it to be stable. Thank you in advance! Kindest regards, Wim
×
×
  • Create New...