彭哥的IDC私房菜

畅游网络,点滴积累,享受交流、分享的快乐

WordPress IP验证不当漏洞修复

WordPress目前的版本(4.9.6及以前)有WordPress IP验证不当漏洞,主要是由WordPress目录下的wp-includes/http.php文件中的wp_http_validate_url函数对输入IP验证不当,导致黑客可构造类似于012.10.10.10这样的畸形IP绕过验证,进行SSRF。

修复方案:找到/wp-includes/http.php这个文件,在文件的533行附近找到:
$same_host = strtolower( $parsed_home['host'] ) === strtolower( $parsed_url['host'] );
改成: 阅读全文…]

WordPress <= 4.9.6 任意文件删除漏洞

WordPress是如今使用最为广泛的一套内容管理系统。根据 w3tech 统计,全世界大概有30%的网站运行着WordPress程序。

昨日RIPS团队公开了一个Wordpress的任意文件删除漏洞(需要登录),目前该漏洞仍然未修复(2018年06月27日),该漏洞影响 WordPress 最新版 4.9.6.

修复方法:

找到当前主题下的functions.php文件,在最后添加:
add_filter( 'wp_update_attachment_metadata', 'rips_unlink_tempfix' ); 阅读全文...]

WHMCS安装完插件访问提示The file is corrupted.

WHMCS装了一个转移产品的插件ImportAssist,在WHMCS后台点击Addon Modules想激活,却报错:The file  XXX/modules/addons/import_assist/import_assist.php is corrupted.

原因:ioncube loader版本过低导致。原来版本为v5.1.1:

解决:将ioncube loader升级为 阅读全文…]

CentOS安装CSF防火墙

CentOS安装CSF(ConfigServer Security&Firewall)防火墙,方法如下:
# wget https://download.configserver.com/csf.tgz
# tar -xzf csf.tgz
# cd csf
# sh install.sh

如果是cPanel服务器,装好CSF之后可以在WHM的Plugins里面点击ConfigServer Security&Firewall进行图形化界面管理,默认情况下,需要打开的端口 阅读全文…]

WHMCS购物车提示Service Unavailable The server is temporarily unable to service your request due to maintenance downtime

访问whmcs的购物车页面出错:

Service Unavailable
The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.
Additionally, a 503 Service Unavailable error was encountered while trying to use an ErrorDocument to handle the request. 阅读全文…]

WHMCS编辑产品出错Oops! Something went wrong and we couldn’t process your request

WHMCS编辑产品出错 Oops! Something went wrong and we couldn’t process your request.Please go back to the previous page and try again.Apache错误日志也没记录具体错误原因。
解决方法:在WHMCS后台的General Settings>>Other下勾选 阅读全文…]

cPanel授权是激活状态但是WHM登录却提示License File Expired

cPanel授权是激活状态但是WHM登录却提示:
License File Expired: LTD: 1456454149 NOW: 1398366120 FUT!
To access the interface, you must install the license and ensure that the license is active.

SSH到服务器中也能成功激活:
#/usr/local/cpanel/cpkeyclt
Updating cPanel license...Done. Update succeeded.
Building global cache for cpanel...Done

最后发现是服务器的 阅读全文…]

CentOS 7 cPanel服务器安装CloudLinux 7指南

CentOS 7 cPanel服务器安装CloudLinux 7指南:
基于key授权的CloudLinux:

#wget http://repo.cloudlinux.com/cloudlinux/sources/cln/cldeploy
#sh cldeploy -k
#reboot

基于IP授权的CloudLinux:

#wget http://repo.cloudlinux.com/cloudlinux/sources/cln/cldeploy
#sh cldeploy -i
#reboot

网络任我行(www.urbansh.com)原创,转载请注明出处http://www.urbansh.com/centos-7-cpanel-cloudlinux-7.html

XenServer 6.2英文原版镜像下载

XenServer 6.2英文原版镜像下载地址:http://downloadns.citrix.com.edgesuite.net/7281/XenServer-6.2.0-install-cd.iso
XenCenter英文下载地址:http://www.networktalking.com/thread-7024-1-1.html
XenCenter中文版下载地址:http://www.networktalking.com/thread-7023-1-1.html

附上XenCenter管理界面:
XenCenter

CentOS服务器挂载超过2T硬盘

磁盘分区格式MBR限制了单块磁盘大小为2TB,如果想挂载超过2TB的磁盘,就要换成其他格式如GPT格式。因为帮助客户使用OnApp搭建云平台,存储先用6TB在测试,所以需要通过其他格式来挂载这6TB的磁盘。分享下Linux上(我用的CentOS5.9 x86_64)挂载使用6TB的Dell MD3600f硬件存储的方法:
[root@demo ~]# parted /dev/sdb #使用parted来对GPT磁盘操作,进入交互式模式
GNU Parted 1.8.1
Using /dev/sdb
Welcome to GNU Parted! Type ‘help’ to view a list of commands.
(parted) mklabel gpt # 将MBR磁盘格式化为GPT
Warning: The existing disk label on /dev/sdb will be destroyed and all data on this disk will be lost. Do you want to continue?
parted: invalid token: gpt
Yes/No? yes
New disk label type? [gpt]? 按下Enter键
(parted) print 阅读全文…]

Page 1 of 2012345...1020...Last »