Security Note 06 - help!

Discussion in 'Troubleshooting' started by starlight, May 31, 2009.

  1. starlight

    starlight New Member

    Joined:
    Mar 15, 2009
    Messages:
    5
    Hi

    I followed the steps from http://www.amember.com/p/Main/SecurityNote06 but the last step does not seem to be working?

    The browser wont open fix.php which is in the Amember/Admin folder now. It directs me to the login page - index.php.

    I need to know what I've done wrong here, I followed the other steps just as described in the security note.

    Please help!

    Many thanks
  2. skippybosco

    skippybosco CGI-Central Partner Staff Member

    Joined:
    Aug 22, 2006
    Messages:
    2,526
    Log on to your Admin console first and then run the fix.php. In theory it is not a required step, but since it checks to see if you have any infected user accounts it i certainly a good idea!
  3. currymandavid

    currymandavid New Member

    Joined:
    Dec 12, 2007
    Messages:
    7
    I thought the instructions were NOT to login to your Admin console until everything was fixed?

    I'm having a similar problem but when I run fix.php it asks for my admin login and, once given, after a while it returns a blank page not the expected "no injected records found" or whatever.

    I've raised a ticket but I expect Alex is pretty busy at the moment. Can anyone help in the mean time?
  4. davidm1

    davidm1 aMember User & Partner

    Joined:
    May 16, 2006
    Messages:
    4,437
    You have to login to admin first. Dont run anything once inside, just fix.php.
    Then you are ok to go back to admin.

    David
  5. currymandavid

    currymandavid New Member

    Joined:
    Dec 12, 2007
    Messages:
    7
    Thanks for the advice which I've just tried but I still get a blank page after trying to open fix.php

    The guys have responded to my ticket (very prompt - thanks) so I'll let them sort it out I think

    David
  6. skippybosco

    skippybosco CGI-Central Partner Staff Member

    Joined:
    Aug 22, 2006
    Messages:
    2,526
    @currymandavid, please report back and let us know how they resolved the issue in case anyone else runs into the same thing.
  7. starlight

    starlight New Member

    Joined:
    Mar 15, 2009
    Messages:
    5
    fixed!

    Hi

    Thank you to all for all the info. I logged into Admin and it ran the fix.php automatically, no errors!

    ;)
  8. currymandavid

    currymandavid New Member

    Joined:
    Dec 12, 2007
    Messages:
    7
    OK, in the end Alex had to do a manual check of my database (it was clean thank goodness :) ) as even he couldn't get fix.php to run on my server. Alex thinks it's due to some problem with php or MySQL as the script just hangs.

    Anyway, thanks Alex. back to normal now.

    I would add that I have had aMember running now for 16 months using PayPal and 2Checkout and this is the first issue of any importance that I've had. Pretty impressive I think.

    cheers

    David
  9. davidm1

    davidm1 aMember User & Partner

    Joined:
    May 16, 2006
    Messages:
    4,437
    I've seen fix.php take a long time on large databases- should really be doing the checks in chunks....

    David

Share This Page