Guppy CMS Portal WEB in php free without BDD

  Welcome  BloggY  News  Download  Links  Guestbook  Forum
News

GuppY - Patch_nc_4.6.24 (2013.06.07) - by GuppYTeam 07/06/2013 @ 17:55

caution.gif
GuppY - Patch_nc_4.6.24


We release this non-cumulative patch for 4.6.24 GuppY with several changes, all aimed at spam-fighting.

We recommend that you install this emergency security patch.


For two months up to now, we have been facing:

- 1 - Spam on the guestbook or news, blocked so far by Cryptographp
- 2 - Requests from spambots from postguest.php to the guestbook and news.

Here are some kind of calls for GuppY

http://monsite.fr/postguest.php?lng=en&typ=gb
http://monsite.fr/postguest.php?lng=en&typ=ne
http://monsite.fr/postguest.php?lng=fr&typ=gb
http://monsite.fr/postguest.php?lng=fr&typ=ne

Scripts robots do not indeed type randomly but keep trying on standard file names that are in open source CMS scripts - for GuppY is not the only target.
These queries lead to shared server overload and depending on which hosts, sites can be suspended, postguest blocked in chmod 200 or else renamed.

The 4.6.24 patch allows renaming of files and integrates Cryptographp to provide answers to both problems (Thanks Saxbar).
All changes to files are about renaming files, integrating Cryptographp with functional default configuration, except the file
s admin/inc/upload.inc (correction of a misprint line 219 and table display from line 220 to 225 – thanks Laroche) and admin/inc/nwllist.inc (adding a search in the list of newsletter subscribers – thanks Saxbar)

- Renaming files postguest.php, user.php and newsletter.php to a custom name for each site, is in our opinion, essential.
- Renaming guestbk.php also owing to the number of requests to the guestbook, even if it has an impact on the ranking of the guestbook.
- Renaming blogs.php, blog.php, forum.php, fortopic.php, thread.php, news.php can be at the discretion of the webmaster or according to calls on the website because the impact on SEO is much more important.


If users do rename their files unpredictably, there will be thousands or tens of thousands files with different names and even when robots scan the net, they will get millions of returns to their servers which is a fair payback for their attacks.

You'd better have your site a little less well-referenced rather than closed down by the hosters.
In fact they are looking for ways out of this problem because eventually the invasion of spam and requests will turn customers away.

Before installing the patch, you should read the pdf tutorial included in the patch: "Configure ANTI-SPAM" and follow it to the letter.

As with each new version, do not forget to update your plugins, reinstall your forks, and revalidate your configuration pages.
To upgrade from the 4.6.23.1 version to 4.6.24 version, you must use this patch_nc_4624.


Thank you to all participants in this patch.


The Guppy Team




Top

© 2005-2026

Document generated in 0 second