blog site locked down again

Web hosting discussion, programming, and shared and dedicated servers.
13 posts Page 2 of 2
by bob noble » Wed Jan 04, 2017 1:03 am
Hi Joe,
As near as I can tell it's working ok now. My firewall seems to be up and blocking the bad guys. The software doesn't seem to indicate a manual install and only says the .htaccess file doesn't have permissions for them to write to it when their wizard is ran.
Never the less, I think the deed is done.
Thanks,
Bob
by bob noble » Wed Jan 04, 2017 6:10 pm
Hi Joe,
Doing some more research on the firewall thing. The firewall is working, but not the part that enhances the firewall. The enhancement is supposed to start firewall protection before they get into the Wordpress directory. I thought it might be working, but it's not. This is the part that we tried the manual stuff on. I've got this system config file from Wordfence that shows where it is getting it's info from which should show you what's wrong, as I'm sure all this will make more since to you.
I'm especially seeing this:
Configuration File (php.ini) Path /opt/php53/lib
Loaded Configuration File /nfs/www/httpd/cgi-bin/php.ini
<<
I tried to modify the php.ini file above, but cannot. I think it's the one Wordfence can't write to in their error when I try to set this up automatically.
There's more to the file below that I can send if you need it.
thanks,
Bob

From the Wordfence system configuration file:
System Linux a.custweb.sonic.net 2.6.9-89.0.9.ELhugemem #1 SMP Mon Aug 24 08:06:39 EDT 2009 i686
Build Date Aug 14 2014 12:20:17
Configure Command ./configure --prefix=/opt/php53 --with-gd --enable-ftp --with-zlib-dir --with-jpeg-dir --enable-gd-native-ttf --with-freetype-dir --with-pspell --with-xmlrpc --with-mhash --with-mcrypt --with-curl=/opt/curl-7.21.6/ --with-openssl=/opt/openssl-0.9.8r --with-gettext --with-mysql=/usr/bin/mysql_config --with-xsl --with-tidy --with-gd --enable-sockets --with-imap=shared,/usr/src/c-client/ --with-imap-ssl=/opt/openssl-0.9.8r --enable-exif=shared --enable-mbstring=shared --with-pdo-mysql=shared,/usr --with-mysqli=shared,/usr/bin/mysql_config --enable-bcmath=shared --enable-calendar --enable-soap=shared
Server API CGI/FastCGI
Virtual Directory Support disabled
Configuration File (php.ini) Path /opt/php53/lib
Loaded Configuration File /nfs/www/httpd/cgi-bin/php.ini
Scan this dir for additional .ini files (none)
Additional .ini files parsed (none)
PHP API 20090626
PHP Extension 20090626
Zend Extension 220090626
Zend Extension Build API220090626,NTS
PHP Extension Build API20090626,NTS
Debug Build no
Thread Safety disabled
Zend Memory Manager enabled
Zend Multibyte Support disabled
IPv6 Support enabled
Registered PHP Streams https, ftps, compress.zlib, php, file, glob, data, http, ftp, phar, zip
Registered Stream Socket Transports tcp, udp, unix, udg, ssl, sslv3, sslv2, tls
Registered Stream Filters zlib.*, convert.iconv.*, mcrypt.*, mdecrypt.*, string.rot13, string.toupper, string.tolower, string.strip_tags, convert.*, consumed, dechunk


Zend logoThis program makes use of the Zend Scripting Language Engine:
Zend Engine v2.3.0, Copyright (c) 1998-2014 Zend Technologies




PHP Credits


Configuration

bcmath

BCMath support enabled



Directive

Local Value

Master Value

bcmath.scale 0 0


calendar

Calendar support enabled


cgi-fcgi


Directive

Local Value

Master Value

cgi.check_shebang_line 1 1
cgi.discard_path 0 0
cgi.fix_pathinfo 1 1
cgi.force_redirect 1 1
cgi.nph 0 0
cgi.redirect_status_env no value no value
cgi.rfc2616_headers 0 0
fastcgi.logging 1 1


Core

PHP Version 5.3.29



Directive

Local Value

Master Value

allow_call_time_pass_reference On On
allow_url_fopen On On
allow_url_include Off Off
always_populate_raw_post_data Off Off
arg_separator.input & &
arg_separator.output & &
asp_tags Off Off
auto_append_file no value no value
auto_globals_jit On On
auto_prepend_file wordfence-waf.php no value
browscap no value no value
default_charset no value no value
default_mimetype text/html text/html
define_syslog_variables Off Off
disable_classes no value no value
disable_functions no value no value
display_errors On On
display_startup_errors Off Off
doc_root no value no value
docref_ext no value no value
docref_root no value no value
enable_dl On On
error_append_string no value no value
error_log no value no value
error_prepend_string no value no value
error_reporting 4983 no value
exit_on_timeout Off Off
expose_php On On
extension_dir /opt/php53/lib/php/extensions/no-debug-non-zts-20090626 /opt/php53/lib/php/extensions/no-debug-non-zts-20090626
file_uploads On On
highlight.bg #FFFFFF #FFFFFF
highlight.comment #FF8000 #FF8000
highlight.default #0000BB #0000BB
highlight.html #000000 #000000
highlight.keyword #007700 #007700
highlight.string #DD0000 #DD0000
html_errors On On
ignore_repeated_errors Off Off
ignore_repeated_source Off Off
ignore_user_abort Off Off
implicit_flush Off Off
include_path .:/opt/php53/lib/php .:/opt/php53/lib/php
log_errors Off Off
log_errors_max_len 1024 1024
magic_quotes_gpc On On
magic_quotes_runtime Off Off
magic_quotes_sybase Off Off
mail.add_x_header Off Off
mail.force_extra_parameters no value no value
mail.log no value no value
max_execution_time 0 30
max_file_uploads 20 20
max_input_nesting_level 64 64
max_input_time -1 -1
max_input_vars 1000 1000
memory_limit 128M 128M
open_basedir no value no value
output_buffering 0 0
output_handler no value no value
post_max_size 50M 50M
precision 14 14
realpath_cache_size 16K 16K
realpath_cache_ttl 120 120
register_argc_argv On On
register_globals Off Off
register_long_arrays On On
report_memleaks On On
report_zend_debug On On
request_order no value no value
safe_mode Off Off
safe_mode_exec_dir /usr/local/php/bin /usr/local/php/bin
safe_mode_gid Off Off
safe_mode_include_dir no value no value
sendmail_from no value no value
sendmail_path /usr/sbin/sendmail -t -i /usr/sbin/sendmail -t -i
serialize_precision 17 17
short_open_tag On On
SMTP localhost localhost
smtp_port 25 25
sql.safe_mode Off Off
track_errors Off Off
unserialize_callback_func no value no value
upload_max_filesize 50M 50M
upload_tmp_dir no value no value
user_dir no value no value
user_ini.cache_ttl 300 300
user_ini.filename .user.ini .user.ini
variables_order EGPCS EGPCS
xmlrpc_error_number 0 0
xmlrpc_errors Off Off
y2k_compliance On On
zend.enable_gc On On
by joemuller » Thu Jan 05, 2017 10:51 am
Bob,

I tried poking at your .htaccess and .user.ini a bit more. I bumped the selected PHP version to 5.5 - most guides I see online reference PHP 5.4 and higher as being recommended for WordFence. When I checked the phpinfo() output, the auto_prepend_file field was being set to include wordfence-waf.php. There should be some sort of indicator in the settings page for WordFence that shows whether or not the firewall is working.
I'm a proud employee of Sonic.net! :-)
13 posts Page 2 of 2

Who is online

In total there are 19 users online :: 0 registered, 0 hidden and 19 guests (based on users active over the past 5 minutes)
Most users ever online was 999 on Mon May 10, 2021 1:02 am

Users browsing this forum: No registered users and 19 guests