Sessions Created With No Permissions Set
Apr 16, 2007
I'm in the process of configuring my company's new server and I've hit a slight stumbling block. What's happening is that PHP is creating its sessions like normal with the exception of no permissions being set for them. This then means that errors are thrown up when PHP attempts to open the session files. Can anybody tell me why this is happening? I have set the sessions directory to octal 0777 for the time being.
The server is running Linux redhat.
View 0 Replies
ADVERTISEMENT
Sep 1, 2008
I recently got a dedicated server (CentOS with WHM and cPanel) and I am a newbie when it comes to server admin.
I had a hard time with the proper configuration so that Fantastico would work (it took their admin a week to figure out their own installation).
In any case now I can use Fantastico to install scripts and the one I use the most is Joomla. There is a major problem though. So I create a new account in WHM (with root access or not), go to domain.com/cpanel, go to Fantastico and install Joomla. Then if I access files or folders through FTP using CoreFTP I can't change permissions (most of files or folders) and I can't edit files. (that's the case even for the accounts with root access).
I can perform those actions if I log into WHM with my main root account and change what I need using a module called Configserver Explorer that shows all the files on the server (without that module I would be lost - I don't know all those shell commands)
So can anyone help me with some proper configuration tips so that if I create user accounts (other then myself) they would have those permissions to edit or change stuff in their account?
I come from shared hosting and never had these problems. They were allowing add-on domains and I could copy entire sites to other domain names with one click. Now WHM says it's not a good idea to allow add-on domains. No idea why. Any advise one that?
View 9 Replies
View Related
Aug 16, 2007
I operate vbulletin across my site including a couple of subdomains. I've just moved to a new server only to find that sessions are no longer recorded unless the user actually visits the forum (ie. forum.mysite.com).
The rest of my site uses the following code to track sessions / maintain connection to database:
PHP Code:
// vB Global File$cwdir = getcwd();chdir('/home/mysite/public_html/forum/');require_once 'global.php';chdir($cwdir);
Would anyone know what could be the problem? I'm running vBulletin 3.6.8, PHP 5.2.3, Apache 1.3 and MySQL 4.1.22. Safe mode is off, mod_security is off, open_basedir is off.
View 2 Replies
View Related
Aug 23, 2007
I recently upgraded to PHP 5.2.3 and now some of my customers sites are throwing errors.
Apache 1 with PHP 5.2.3 on RH.
Code:
Warning: session_start() [function.session-start]: Unknown session.serialize_handler. Failed to decode session object. in /home/kaaoscom/public_html/wow/raids/auth/auth_phpraid.php on line 70
Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/kaaoscom/public_html/wow/raids/auth/auth_phpraid.php:70) in /home/kaaoscom/public_html/wow/raids/auth/auth_phpraid.php on line 70
Warning: Unknown: Unknown session.serialize_handler. Failed to encode session object. in Unknown on line 0
View 3 Replies
View Related
Dec 2, 2007
I'm having some problems configuring my server sessions in php.
Server espec:
WHM 11.2.0 cPanel 11.11.0-S18033
CENTOS Enterprise 4.5 i686 on standard - WHM X v3.1.0
PHP version 5.2.4
MySQL version 4.1.22-standard
Apache version 1.3.39 (Unix)
Sessions def. in php.ini:
Quote:
Code:
[Session]
session.save_handler = "files"
session.save_path = "/tmp/sessions"
; in the case of files, this is the
; path where data files are stored
session.use_cookies = 1
session.name = "PHPSESSID"
; name of the session
; is used as cookie name
session.auto_start = 0
session.cookie_lifetime = 0
; or if 0, until browser is restarted
session.cookie_path = "/ "
session.cookie_domain =
session.serialize_handler = "php "
; php is the standard serializer of PHP
session.gc_probability = 1
; 'garbage collection' process is started
; on every session initialization
session.gc_maxlifetime = 1440
; data will be seen as 'garbage' and
; cleaned up by the gc process
session.referer_check =
; externally stored URLs containing ids
session.entropy_length = 0
session.entropy_file =
; session.entropy_length = 16
; session.entropy_file = /dev/urandom
session.cache_limiter = "nocache "
; determine HTTP caching aspects
session.cache_expire = 180
session.use_trans_sid = 1
; by compiling with --enable-trans-sid
Register globals are ON
First I recieved about 7 e-mails from clients saying that in joomla pre instllation teste sessions.save_path was unwritable.
I went to /temp created a sessions folder and chmoded it to 777
After that they still can't login on the admin area
Error: Warning: session_start() [function.session-start]: Cannot find save handler files in /home/asasdosa/public_html/site00/administrator/index.php on line 111
From what I could read on-line in joomla this means that clients can't save sessions file in the session.save_path although it is writable. But never saw a solution for it, because it was all client oriented. All the solutions were contact your isp.
Well they did contact, but the isp doesn't know how to fix it
View 3 Replies
View Related
May 28, 2008
Is there a way in the php.ini file to force all sessions to be stored in a database? For example, in ColdFusion you can configure sessions to be stored in a db. Can you do this in PHP? Thereby forcing all sessions no matter what the customer specifies to be stored in a db.
View 3 Replies
View Related
Sep 3, 2008
I've come across an issue where our users are not logging out of their terminal services session properly. Whether via TSWeb or MSTSC (remote desktop), if they close the browser or RDP window using the x it keeps the session alive for upto 1 minute.
The problem with this is that we use terminal services to host an application for users who can't install it, so other users that login (using a generic username and password) are adopting/hijacking the original session and seeing someone elses data.
Does anyone know of a way to force a new session each time a user connects to RDP? Whether via TSWeb or MSTSC (remote desktop)?
View 7 Replies
View Related
Jun 28, 2007
I have a fairly good understanding of IIS 6.0 and so this is beginning to confuse me some what.
Our clients are running on Windows 2003 server with IIS 6.0 which in turn runs the site that we had created. The thing is our site does rely on sessions so when one ends it runs the Session_OnEnd within the global.asa and runs some other functions.
But just recently a number of our clients are experiencing the problem that the sessions are not ending so the Session_OnEnd is not running therefore causing some major problems with their sites.
Two of our clients has said recently that they had installed SP2 but I am not sure if this would change any of the settings or **cough** BUGS **cough**. Can anyone please shed some light on what the SP2 actually did and if any of the settings for IIS 6.0 would of been reset.
View 3 Replies
View Related
Jul 27, 2007
While I was using my VPS, I was disconnected 2 times and when I re-connected again, it told me to choose 1 from 2 sessions to continue? Can anyone please tell me how can I create sessions like this and how to delete one of them ?
View 4 Replies
View Related
Jan 10, 2009
I was looking at some load balancers hosting companies offer and some of the load balancer specs say they can handle up to 15million concurrent sessions(users online at the same time), so does this mean if i had a site like wikipedia that had 15 million users online at the same time, would i be able to do this with only 2 dedicated servers, or will the Cpu's not be enough?
View 3 Replies
View Related
Apr 10, 2007
I have a server Windows 2003 Server
I have a problem for ask WHT. I have 3 session in my Windows 2003 Server but we can only 2 person connect but i want 4 or more connection to my server. Hown can i do it?
View 4 Replies
View Related
Dec 5, 2008
suddendly some of my sites in my server is taking sessions errors...then after a while all its going ok and then again the same problem...the problem still continues.from what might be the problem?a php update?mysql update?any exprerience?
i havent made any change.my server is linux has centos 4.7
View 5 Replies
View Related
Nov 18, 2014
I implemented a Reverse Proxy using apache2 v. 2.4... What i need to do is limit number of sessions against a Virtual Host. Is that possible?
View 13 Replies
View Related
Nov 5, 2014
I am trying to capture 3-4 digits when sent as part of a URL, for them to be proxied to another URL. I have no control over how the source sends this data, I am supposed to redirect it. Which works.
#RewriteCond %{HTTP:whoisd-ussd-message} ([d]{2,4})
#RewriteRule ^/original/individual.do(.*)$ https://other.server.com/somewhere/011$1 [P]
The problem is this works for all URLs that have digits to this server. I am expecting to trap URLs that send digits as part of the first call to the server, but this also affects URL calls that are part of other server call transactions, once digits appear, it gets redirected. What can I do to stop this interference?
View 1 Replies
View Related
Mar 23, 2009
I am planning to get a Juniper firewall, but due to SSG140 has a maximum of 48,000 concurrent sessions per second, so it triggers me how do I measure the concurrent session of a linux server of the total throughput instead of just port 80?
OS: CentOS
View 3 Replies
View Related
Sep 28, 2009
i hosted one server socket application in my dedicated server which is recving the data from different units(vehicle tracking system) through port no 4444.in dedicated machine i am keeping one active session always...that means my socket application exe is opened always in an active session ie sectionA.This session is not logged off insted i used to close the rdp for keeping this session active.Based on settings if userA accessing SessionA then userB cannot able to reach the active sessionA at the same time instead new sessionB will open for userB.
now my question is
if userB also opened socket application in SessionB with same portno ,then which soket application will recive data from the units...whther the applictaion from sessionA or from SessionB?
View 2 Replies
View Related
Mar 31, 2008
We have setup and are currently testing a load balanced cluster using heartbeat and ldirectord. One of the problems we have come across is that we are unable to reliably use the same web server for connections from the same user. As a result the php sessions are getting in a bit of a muddle.
Obviously its not something that we can easily sync between servers like the customers other web content. We are looking at either storing the sessions in a database or NFS.
The site is pretty busy and we are a bit worried that when the site goes live both these options will slow everything down.
Apart from using different load balancing software is there any other solutions we could use for this? Has anyone stored php sessions in a database on a busy site or on a NFS?
View 3 Replies
View Related
Nov 13, 2008
I'm running a Windows 2003 based Vps, I'm looking to have more than 2 sessions of RDP at one time, I think every people know that is setted to 2.
I want only one more, at the moment I have admin acc always running, #1 friend account (where there are running 2 process always) and now I want #2 friend account for run another process.
View 3 Replies
View Related
Aug 28, 2014
i saw very often in the active sessions site following line:
Username Empty IP empty Date Nov 30, -0001 12:00 AM Idle time 00:45:39
What is that and how can is stop this or get it fixed ?
View 1 Replies
View Related
Dec 18, 2008
After some yum updates last night one user and group called xfs were created on my dedicated server. Does anyone know what this group/user is used for?
View 0 Replies
View Related
Apr 19, 2007
I am designing a site for a client and in all the years I've done design etc, I've come up against a phenomenon with their VPS server they have. It's linux and uploading files I am using WS_FTP Home.
I am uploading files and folders to their public_html/domain.com/ (*I use domain here for their privacy) and in some folders (directories) after doing so, a mystery folder suddenly appears that is named 5" and as you enter that folder, you see the path directory show up "public_html" and if you go into that one, you come up to the domain.com folder again, and if you deeper into that one you start to see this phenomenon of mirroring folders of the one you go into. Example:
public_html/domain.com/images/5"/public_html/domain.com/images/file
***the file whether it's an image jpg, png, etc is created as the last directory as a folder, not a file. I should also mention that as you go deeper in the 5" mystery directory folder, you no longer see the path in the FTP anything past the 5" one even as you go further in.
Oh, and it doesn't allow you to delete these 5" folders regardless of what permissions. And this folder seems to show up in many areas of this website's directory structure...mostly where images are (don't know if that is just a coincidence).
So hope all this makes sense....anyone seen this before and what the cause could be? Their host doesn't seem to know the reason and says they cannot see it even though others can. They said it's the FTP program as the cause and not their server.
My comeback to that is that I've used this FTP for years and never before seen this happen. It's only with this one client's server.
View 4 Replies
View Related
Oct 15, 2009
(2) Intel Xeon 5310 Quad Core 1.6GHz Processors
Supermicro X7DVL-E Dual Processor Motherboard with 1333/1066/667MHz FSB
(4x) 2GB DDR2 PC5400 ECC Fully Buffered (667MHz) System Memory (1GBx2)
(6x) 250GB SATA II Hard Drives (1.25TB Available Storage)
How many VPS Servers can be created on that dedicated server?
And what is the suitable dedicated server for about 20 VPS Servers to be hosted on?
View 14 Replies
View Related
Dec 11, 2008
How to find out who created account?
How can I find out who created an account in CPanel? Where in the logs?
I have a new account on my server but I don't know who created it, it's possible one of my resellers lost his password, but how can I find more about it?
View 5 Replies
View Related
Mar 9, 2007
This is twice I have found email addresses on the web that I have never created. Both domain names are the new extensions and I purchased them the first day they become public. .biz the other is .US
One of the domains I never even created a web page until yesterday. And today I find a German site using my domain as an email address. One note on this, this domain name is extremely unique and related to certain German ideas or thoughts.
I am thinking someone at the server created them and used them for their personal use. Is this possible?
Not only that, but I have sent email to these addresses and there was no bounce back. No bounce back meaning these are valid email addresses?
View 4 Replies
View Related
Apr 1, 2007
We've had someone starting nobody PERL procs on a box and we can't quite track it down or read the file to see what it is. What he does is to create a folder in /tmp, execute the script from there and delete the folder as soon as it's running (yes, /tmp is mounted noexec, makes no difference). We've managed to discover and block the IP that was doing this, but that's no fix. He hasn't been back since banning the IP...so far.
What we would like to do is see if anyone knows of (or can help create) a script that can watch the /tmp folder and copy newly created directories and thier contents to another dir (also notifying via email would be helpful) in order to see what the heck it's doing, and hopefully be able to figure out how it's getting in. Nothing in any logs this time, and the PERL process seems to be able to hide itself from PS. That bit worries me quite a lot, but none of the binaries appear to have been changed, and it doesn't appear we've been rooted in any way.
Thoughts on this, ideas and suggestions welcome.
Failing that, is it possible without breaking the box to prevent the creation of new directories in /tmp? This I seriously doubt, but if all they need to do is create a folder and work from there, noexec is a joke.
View 14 Replies
View Related
Aug 7, 2014
We are getting the below message in Apache's error.log when accessing from mobile application & updated apache from 2.4.9 to 2.4.10 also.Trailing dot is created after the URL.
I can able to hit [URL] ..... and I can't able to hit [URL] ....
View 11 Replies
View Related
May 27, 2015
Since a week ago or so, in one of our Plesk 12.0.18 / Centos 6.6 servers, when we create subdomains the process seems to stop half-way without being finished.
To reproduce the error:
Select a subscription (e.g. example.com) and go to "Domains and subdomains"
Select "add new subdomain" and enter a value (e.g. new.example.com). The directory will live in parallel to httpdocs
Click Accept
Expected result:
The subdomain should be created: Filesystem diirectory with default contents, DNS entry, Apache VirtualHost, etc.
Actual result:
After several minutes Plesk responds with Internal Errror (in a red area in the panel).
Things done right:
The file space in parallels with httpdocs is created fine with the default site.
DNS entries are created under /var/named/chroot infrastructure.
The subdomain menu appears fine in the Plesk panel.
Things wrong/missing:
The filesystem directory is not mapped by Apache. Even after changing its contents the default server templeate appears in the browser, (all precautions taken, apache restart, browser in private session and different browsers).
Log info:
- /var/log/sw-cp-server/error_log says:
2015/05/27 18:17:45 [error] 28890#0: *1828 readv() failed (104: Connection reset by peer) while reading upstream, client: nnn.nnn.nnn.nnn, server: , request: "POST /smb/web/add-subdomain HTTP/1.1", upstream: "fastcgi://unix:/var/run/sw-engine.sock:", host: "<hostname>:8443", referrer: "https://<host>:8443/smb/web/add-subdomain"
- /var/log/httpd/access_log records the access with 200 OK codes although I don't find them in neither subscription logs under /var/www/vhost/system/*/logs/access_log
nnn.nnn.nnn.nnn - - [27/May/2015:18:38:35 +0200] "GET <deleted_content_in_the_subdomain_directory> HTTP/1.1" 200 14036 "http://<new_subdomain>" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:34.0) Gecko/20100101 Firefox/34.0
I don't find the Apache VirtualHost .conf files for subdomains, where can I look for them up...
View 4 Replies
View Related
May 24, 2014
$request = <<<EOF
<packet version="1.6.5.0">
<mail>
<create>
<filter>
<site-id>34</site-id>
<mailname>
<name>$username</name>
<mailbox>
<enabled>true</enabled>
<quota>1024000</quota>
</mailbox>
[code]....
I write this code for creating mail box, but I get "No mailbox" message in plesk panel. I need to create mailbox.
View 2 Replies
View Related
Nov 3, 2008
How to make backup of VE's(created with openvz) to .tar.gz and restore later?
View 4 Replies
View Related