• English version
  • Version française
  • Versión española

Archives for March, 2009

Apache AddHandler moved to AddType due to security considerations

Posted on Sunday 29 March 2009

Hi,

Due to security considerations, AddHandler should not be used in apache configuration files. As uncovered by an old thread on the suphp mailing list, this would allow any files containing ".php" to be executed by php (for example example.php.jpg, trust me, this is not what you want ;) ).

As using AddHandler was sadly advised in our FAQ example, most of our hosted people were using it in their .htaccess. To fix this security flaw, we have added full support to AddType, modified our FAQ and run a script to widely and roughly modify all .htaccess files to retroactively fix the problem on TuxFamily.

If you were using a custom .htaccess file containing AddHander/AddType instructions, please check that everything is still working fine as our script may have introduced some side effects.

If you are automatically upgrading your website through rsync or such, please fix your local copy of .htaccess according to the new version of the FAQ.

However, we are not the only one to blame, because the Apache documentation is very unclear on this particular point, as you can see on the addhandler and addtype descriptions.

Your admins

NFS crash

Posted on Saturday 28 March 2009, at 03:10 UTC

Hi,

Mail, web, downloads, svn/git/cvs, MX and DNS services are currently down, we managed to crash the main NFS server this night :(.

MX and DNS secondary services are still working, so you won't loose your mails.

We will keep you informed.

We apologize for the inconvenience.

Your admins

Edit: Okay, everything should be back online :) enjoy !

Good bye PHP4

Posted on Tuesday 10 March 2009

As most of you know, PHP5 has been available for 5 years now, hence PHP4 is obsolete and will not be available once we move on to Debian lenny.

So, please check if your website works with PHP5, and to fix it if necessary, you can learn how to do that on the FAQ

PHP5 will be set as the default language next week, you will still be able to fallback to PHP4, but hurry up, that should not stay long.

RSS Feed