Thursday, April 16, 2015

solr and pint

solr 5 no longer support p prefixed fieldtype,
therefore:
pint, pstring, pdate, etc... no longer supported.

solr query rows did not return all results

solr by default allows query
*:* and x=1

but it is not suppose to make sense if you are adding condition,
*:* should not be added.
but solr allows to return all results to match x=1.

but when use with edismax,
the results seems to return strange behaviour as it does not return all rows.
therefore, removing *:* does the tricks in use_dis_max = true is used.

Monday, March 16, 2015

modx minified error

It seems to happen on certain site that modx manager stop functioning properly.
when open in firebug, it shows modx minified returned error 400,
missing file.

when i appended &debug to the url, error starts showing out in firebug, and it indicates double appended path to the script.
the solution to this problem is to goto root/manager/mini/index.php

line #66 and add the bold code below:

if ($hasVirtualAssetsURL && !$hasVirtualManagerURL) {
    $min_serveOptions['minApp']['allowDirs'][] = MODX_ASSETS_PATH;
    $min_serveOptions['minApp']['virtualDirs'][MODX_ASSETS_URL] = MODX_ASSETS_PATH;
}

yes, ive already submitted a bug, and hopefully they have fixed it

Thursday, February 5, 2015

prestashop upload image: undefined error

my latest update on cpanel, were installing modsecurity with extra vendor from owasp.
it seems that 1 rule have caused prestashop to unable to upload image to product through the admin control panel. The rule effecting the upload is:


rules/REQUEST-20-PROTOCOL-ENFORCEMENT.conf 
For example, these rules block GET requests with a body.
Basically it means it stop all post data if the url contains GET querystring...

hope it help you guys. You may disable this rule in the vendor - edit and off this line.

Friday, December 12, 2014

calling .net dll from asp classic

Prerequisites:
tested on visual studio pro 2013 and windows 8 / 2012

First, create a new vb / c# project com class component.
Then go to project properties,
Application tab > assembly information > Check Make Assembly com visible
Compile tab
Check Register for com interop
(makesure to sign your app, otherwise you cant register with gac)
Signing tab > Sign the assembly > Create a password

Okay, now to solution explorer on the right side,
Right click on solution and add item
Common items > Code > Com Class

Declare your class with method required,
Remember this class will be visible from outside.


When done building your project,
Go to Build > Build [your projectname]

goto start, find for visual studio tools
run VS2013 x64 Native Tools Command Prompt
(please take note that this is x64 environment).
So we need to run regasm and gacutil from x64 tools, not the default 32bits

Then cd \yourprojectpath\yourclass\bin\Debug\
regasm yourfile.dll
(need to sign assembly)

gacutil -i yourfile.dll


Then you may check if your registry is registered by calling
regedit
HKLocal Machine > Software > Classes > YourProjectname.YourObject

okay, then restart iis. and test your dll in asp:
<%
dim foo
set foo = Server.CreateObject("YourProjectname.YourObject")

dim pass
pass = "abA2356!"

if foo.ValidatePassword(pass) then
Response.Write "all ok!"
else
    response.Write "not ok!"
end if
%>

other references:
http://forums.iis.net/t/1183338.aspx?Calling+NET+DLL+from+classic+ASP

Thursday, October 23, 2014

fixing poodle vulnerabilities on cpanel services

This guide will help to disable ssl2 and ssl3 support.

/var/cpanel/conf/cpsrvd/ssl_socket_args
SSL_cipher_list=ALL:!ADH:+HIGH:+MEDIUM:-LOW:-SSLv2:-EXP
SSL_version=TLSv1

#SSLProtocol ALL -SSLv2 -SSLv3

restart service
/etc/init.d/cpanel restart

test
openssl s_client -connect example.com:2087 -ssl3

should get error
CONNECTED(00000003)
44604:error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure:/SourceCache/OpenSSL098/OpenSSL098-52/src/ssl/s3_pkt.c:1125:SSL alert number 40
44604:error:1409E0E5:SSL routines:SSL3_WRITE_BYTES:ssl handshake failure:/SourceCache/OpenSSL098/OpenSSL098-52/src/ssl/s3_pkt.c:546:

openssl s_client -connect example.com:2087 -tls1

note:
do not add -SSLv3 to SSL_cipher_list as it will disable tls as well.

Tuesday, October 21, 2014

laravel saving child model

Took me hours to finally figure this out.

When calling child has_many, calling method seems to return the association / querybuilder,
but calling attribute seems to return the collection.

so save the child record,

$object->childs()->save($child)

to get list of collection of childs, calling:

foreach($object->childs as $child)