GITK Services
Verified User
I've requested DA updates itself. I'll let you know if it works.
fusionictnl said:Check the main config /usr/local/directadmin/plugins/awstats/hooks/cgi-bin
and there should be some file named: awstats.none.conf
Edit this, and look for a row that says:
EnableLockForUpdate=1
Set this to Zero.
remove all .conf files in the /etc/awstats dir and reinstall on all domains.
Good Luck
# Relative or absolute web URL of your awstats icon directory.
# If you build static reports ("... -output > outputpath/output.html"), enter
# path of icon directory relative to the output directory 'outputpath'.
# Example: "/awstatsicon"
# Example: "../icon"
# Default: "/icon" (means you must copy icon directories in "/mywwwroot/icon")
#
DirIcons="http://awstats.sourceforge.net/icon"
AWStats 6.3 final is ready
Fri, 28 Jan 2005 23:06:36
Warning, a security hole was recently found in AWStats versions from 5.0 to 6.2 when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody").
If you use AWStats with another version or with option AllowToUpdateStatsFromBrowser to 0, you are safe. If not, it is highly recommanded to update to 6.3 version that fix this security hole.
awstats successfully downloaded
Error unpacking /usr/local/directadmin/plugins/awstats/plugin.tar.gz : Error restoring file /usr/local/directadmin/plugins/awstats/plugin.tar.gz :
GameDNA said:When i install the awstats plugin, i get the following output
Is this normal?
Chrysalis said:Last stable version is 6.3 - 2005-01-28 14:33
I would like this integrated please I feel very uneasy using 6.2 on a production server.
phpBB's web site got compromised, and it is currently unavailable. phpBB is a popular web based discussion system.
According to the statement on their front page at the moment, the intrusion has nothing to do with the phpBB software itself. Instead there is an unconfirmed report that compromise may have been done using a security vulnerability in Awstats instead.
At present www.phpbb.com is offline due to a group of politically motivated hackers wishing to use an opensource project to push their agenda ... shame on them.
I will take this opportunity to note that given currently available information this hacking episode does not appear to be due to phpBB itself. Instead a third party application looks to have been the problem. Other sites were attacked at the same time as www.phpbb.com by the same group displaying the same information and in these cases the same third party application has been suggested as the common factor (thus far). Equally we are not aware of any other phpBB boards being attacked and we have not been notified of any valid security issues recently. Obviously we will have more details when we've reviewed just what happened.
We are working to recover the server but this may take some time. Meanwhile users can visit our development board, area51.phpbb.com where they can receive support for phpBB 2.0.x. Of course you can also view the next version of phpBB, 3.0 "Olympus" in the process (minus the new style of course!)
We are also maintaining our IRC support channel, #phpbb on the irc.freenode.net network
We apologise for any problems this may cause our userbase. We obviously take the huge support our community gives phpBB very seriously. And we will do our best to return to "normal operations" just as soon as we can.