Joshua Brauer: Never store tar backups in web accessible directory

Via Planet Drupal:

One blog is accumulating Google code searches that reveal information they shouldn’t. For example this search produces a list of some Drupal database usernames and passwords. Most are for distributions but a few folks have unwisely put backups of their configuration files in .tar files inside their web accessible directories.

Simply put, no file containing sensitive data should ever be stored in a web accessible directory unless it has the proper extension to prevent random browsing. Files like Drupal’s settings.php are OK because they must go through the PHP processor. Putting settings.php.txt or a .tar file with a settings.php in a web directory is a bad idea.

MacMegasite changes complete

I’ve installed the new theme at MacMegasite and I’ve also created a mobile edition, available at http://mobile.macmegasite.com/ which uses a minimalist theme with no graphics. I did it through the magic of Drupal’s multiple site feature. I copied settings.php from the default site to a new site directory and simply added an override for default_theme.

Now that I’ve finished these changes to MacMegasite I can turn my attention to WorldBeatPlanet, which I’ve been neglecting. WorldBeatPlanet is still running Drupal 4.6, because it’s a lot more complex than MacMegasite. I use a few custom modules and the e-commerce module, so I’ve avoided trying to upgrade it to 4.7. I’d also like to change the store section to allow artists to have their own store where they’ll get paid directly for file downloads.

New look for MacMegasite




New MacMegasite Theme

Originally uploaded by mike3k.

I’m working on a new look for MacMegasite, based on the Aquasoft theme for Drupal, as well as a lightweight theme for mobile viewing. MacMegasite also has an enthusiastic new staff member, etomic13, who’s bringing new life to the site.

OneWebDay

Today is . OneWebDay is one day a year when we all – everyone around the physical globe – can celebrate the Web and what it means to us as individuals, organizations, and communities. Read more about it here.

On OneWebDay, take one web-related action that helps someone else, such as:

  • teach someone to use an application (blog, wiki, Flickr) that is new to them
  • start a group blog about an issue you care about
  • help a grandparent get in touch with a grandchild online
  • help a young student find a new educational resource online
  • start a story online that other people add to
  • go to a local senior center and volunteer to help people get online
  • go to a local school and volunteer to help get better equipment in place
  • talk to your town about getting free wireless access in place
  • post a tribute to a friend online – interview him/her about his/her life
  • have a contest with a friend to collect and display the five most amazing things you can find online
  • go to a public wireless place and strike up a conversation about the web with someone near you
  • send a recipe to a friend and then make dinner together

For more ideas visit the OneWebDay Wiki.

OneWebDay

Spam flood

Did anyone else get hit with a flood of comment spam today? I got about 20, all referencing GeoCities pages. This is an unusually large amount for one day. Thankfully all of them were held for moderation and never appeared.

Categories Web

Windows X net

Windows x net is a new Drupal-based Mac-friendly Windows site. Unfortunately they screwed up the Drupal configuration badly — all users have FULL administrative access! I took advantage of having administrative access to fix it by turning off all administrative options for regular users.

Blogged with Flock

Domain Transfer Completed

The domain transfer I started a few days ago finally completed today, after numerous emails to Melbourne IT & GoDaddy. This whole episode convinced me to never use Yahoo’s services again. When I first registered this domain, I had a hard time getting email to work using Dreamhost’s server instead of Yahoo. That also took several emails both to Yahoo & Dreamhost to resolve. I no longer have any domains registered with Yahoo.

Blogged with Flock

Domain Registry Hell

Last year I registered a domain name at Yahoo Domains for my condo community site. When it came up for renewal a few days ago I decided to move it to GoDaddy, where I have the rest of my domains registered. Ever since then I’ve had nothing but grief.

I initiated the transfer and paid for the renewal at GoDaddy. I got an email with the authorization code for the transfer by the administrative contact, which I entered at GoDaddy. After that it was awaiting approval from the current registrar (yahoo domains, which goes through Melbourne IT). After several emails to Yahoo’s domain support I cancelled the service at Yahoo, after which the control reverted to Melbourne IT. I entered the authorization code at Melbourne IT and verified that the domain is unlocked, but there’s still nothing I can do to complete the transfer. I think it’s up to Melbourne IT to finally approve the transfer.

Blogged with Flock

Categories Web

Trying out Flock

I’m now trying out Flock as my default browser. The only thing that I don’t like is Favorites. It doesn’t seem to be possible to nest folders and I can’t put a folder in the favorites toolbar. In Firefox & Safari I like to keep folders of bookmarks to open in tabs in the toolbar. The Favorites menu looks ugly with all of my formerly nested folders listed separately.

Blogged with Flock