Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Unable to authenticate in backend demo
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Nicolas.  
View profile  
 More options Apr 12 2012, 11:59 am
From: "Nicolas." <nclap...@gmail.com>
Date: Thu, 12 Apr 2012 08:59:05 -0700 (PDT)
Local: Thurs, Apr 12 2012 11:59 am
Subject: Unable to authenticate in backend demo
Hello everyone,

I am interested in Diem project and would like to try the online demo
but when I attempt to authenticate in backend panel with admin / admin
as noted in demo page, I always have the error message "The username
and/or password is invalid.". Could you please post the right
username / password?

Thanks!


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
4levels  
View profile  
 More options Apr 12 2012, 12:32 pm
From: 4levels <4lev...@gmail.com>
Date: Thu, 12 Apr 2012 18:32:41 +0200
Local: Thurs, Apr 12 2012 12:32 pm
Subject: Re: [diem-users] Unable to authenticate in backend demo

Hi Nicolas,

We had to disable the demo due to abuse causing the server to be hacked.
Since the code editor allows you to change php files one could practically
do anything with it.

I'll be looking into blocking the potential harmfull actions in the demo to
be able to open the demo for public use.  But since one can add php code in
every widget, this is not so easy..

The best way to try Diem however is by cloning it from git, running the
setup and off you go.  If you don't have a linux box available, consider
playing around with Virtualbox or Vmware to run one inside your current os..

Kind regards,

Erik Van Kelst
IT specialist - OpenSource developer
--
sent from my mobile phone
On Apr 12, 2012 5:59 PM, "Nicolas." <nclap...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nicolas.  
View profile  
 More options Apr 12 2012, 4:27 pm
From: "Nicolas." <nclap...@gmail.com>
Date: Thu, 12 Apr 2012 13:27:51 -0700 (PDT)
Local: Thurs, Apr 12 2012 4:27 pm
Subject: Re: Unable to authenticate in backend demo
Thank you for the quick answer! Sad there are people abusing the demo.
I will follow your advice and clone Diem from git to test it. Thanks
again for the reply.

On Apr 12, 12:32 pm, 4levels <4lev...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Evgeny Sinitsyn  
View profile  
 More options Apr 13 2012, 5:31 am
From: Evgeny Sinitsyn <cuh...@gmail.com>
Date: Fri, 13 Apr 2012 17:31:00 +0800
Subject: Re: [diem-users] Re: Unable to authenticate in backend demo

Hi
@Erik is it possible
to disallow access to CodeEditor,
Or just to disable this module?
Or make hardcore solution — override save action of code editor. ex:
die('this is a demo site. it is not allowed here.');

Evgeny


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
4levels  
View profile  
 More options Apr 13 2012, 6:10 am
From: 4levels <4lev...@gmail.com>
Date: Fri, 13 Apr 2012 12:10:48 +0200
Local: Fri, Apr 13 2012 6:10 am
Subject: Re: [diem-users] Re: Unable to authenticate in backend demo

Hi Evgeny,

There are some ways in the code editor configuration to disable read and/or
write actions on specific files/folders.  It looks more difficult to
disable parsing php code in front widgets like eg. Content/Title or
Content/Text widgets.

I'll have a look at it asap as I do agree the demo is quite important for
new developers to get to know Diem.

I'll keep you all posted..

Kind regards,

Erik Van Kelst
IT specialist - OpenSource developer
--
sent from my mobile phone
On Apr 13, 2012 11:31 AM, "Evgeny Sinitsyn" <cuh...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Javier Neyra  
View profile  
 More options Apr 13 2012, 9:03 am
From: Javier Neyra <javier.javi...@gmail.com>
Date: Fri, 13 Apr 2012 10:03:56 -0300
Local: Fri, Apr 13 2012 9:03 am
Subject: Re: [diem-users] Re: Unable to authenticate in backend demo
this is maybe too basic and naive but did u tried to set all file
perms to readonly... let say someting like 440 or 400? and disabling
the console? (id dont know if the console let u change file perms but
u can disable the exec() php func and this will disable the
cosnole....)

2012/4/13 4levels <4lev...@gmail.com>:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Javier Neyra  
View profile  
 More options Apr 13 2012, 9:04 am
From: Javier Neyra <javier.javi...@gmail.com>
Date: Fri, 13 Apr 2012 10:04:44 -0300
Local: Fri, Apr 13 2012 9:04 am
Subject: Re: [diem-users] Re: Unable to authenticate in backend demo
u will of course have problems with cache probably..... i dont know....

2012/4/13 Javier Neyra <javier.javi...@gmail.com>:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Gerard Finnerty  
View profile  
 More options Apr 14 2012, 3:54 pm
From: Gerard Finnerty <swell8me...@gmail.com>
Date: Sat, 14 Apr 2012 12:54:34 -0700 (PDT)
Local: Sat, Apr 14 2012 3:54 pm
Subject: Re: Unable to authenticate in backend demo
I'm not sure what your environment is, but if your demo server were on
AWS or another cloud-based solution, you could set it up to
automatically redeploy a new demo server every hour or something.  I
would say just redeploy the app, but if they're hacking the server,
just redeploying the server may be the easiest option.

For my production environment with a Diem site, I use Rightscale and
manage the server with a bash script.  You could even set it up to
detect activity that compromises the server and it can automatically
redeploy in those instances.  However, demo's can normally be expected
to refresh hourly.  The only difference is you'd be spinning off an
entirely new server.

Then they can hack it all they want, its just going to be a new, clean
server within the hour anyways.

For my production environment, I limited access to admin.php by ip
address, set up private keys for access and so on.  In that way, only
users on approved networks can even access the admin. Also the
production environment has the code editor disabled, since actual
files get deployed via version control.

On Apr 13, 3:10 am, 4levels <4lev...@gmail.com> wrote:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
SideWinder  
View profile  
 More options Jun 10 2012, 3:49 am
From: SideWinder <vyag...@gmail.com>
Date: Sun, 10 Jun 2012 00:49:51 -0700 (PDT)
Local: Sun, Jun 10 2012 3:49 am
Subject: Re: [diem-users] Unable to authenticate in backend demo

Have you thought about an idea to kill the diem demo istallation once an
hour, for example, bu cron and reinstall the clear one. A saw such decision
on some demo sites.

четверг, 12 апреля 2012 г., 20:32:41 UTC+4 пользователь 4levels написал:


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »