introduction screenshots faq forum blog modules components download
Please use the search function and/or read the FAQ first.

Go to Topic: PreviousNext
Go to: Message ListNew TopicSearchLog InPrint View

why easyPhp check hash.dat on http://yarglah.free.fr/check/hash.dat



Posted by: telnes
June 12, 2008 10:40AM
hello

I just see that, when i run easyPhp it check this url to validate the hash !

that's fucking bad

i download my version on easyphp.org

google say to me that this url appear in this code

[instantrails.rubyforge.org]

why are the original ligne commanted ?
-------------------------------------------------
// _snprintf(szURL, sizeof(szURL), "[www.easyphp.org];, CLangue::GetLang(CLangue::GetCurrentLang()));
strncpy(szURL, "[yarglah.free.fr];, sizeof(szURL)-1);
-------------------------------------------------

best regard
Options: ReplyQuote
Posted by: Thierry
June 12, 2008 02:02PM
The idea is to have files for upgrades and hash file on 2 disctinct servers to avoid, if easyphp.org is compromise by hackers, to distribute corrupted versions of upgrade files.

yarglah.free.fr is my "web page".
(and of course, home page is a joke)
Options: ReplyQuote
Posted by: telnes
June 12, 2008 07:51PM
ok
Options: ReplyQuote
Posted by: JBrenton
October 23, 2008 10:06PM
You really need to advertise this functionality more clearly, it sets off a lot of security concerns.
Options: ReplyQuote


Go to: Message ListSearchLog In
Your Name: 
Your Email: 
Subject: 
Spam prevention:
Please, enter the code that you see below in the input field. This is for blocking bots that try to post this form automatically. If the code is hard to read, then just try to guess it right. If you enter the wrong code, a new image is created and you get another chance to enter it right.