Tag Archive | "server"

Force the Use of HTTPS (SSL)


As it turns out, forcing “www” in the URL was just the beginning. When they purchased your site, handturkey.com they got in over their heads. They hired you on as a consultant within weeks of the acquisition, and their first order of business was to lock down security. Handturkey.com has project management software, CRM, and ecommerce, after all. It seemed obvious that all the traffic in and out of the server needed to be encrypted.

“No problem.” You told them. You remembered that this can be accomplished with the mod_rewrite module in Apache. You tell them them that all they need is a few more lines in the .htaccess file in the root of handturkey.com, and that they should look like this:

RewriteEngine On
RewriteCond %{SERVER_PORT} 80
RewriteRule ^(.*)$ https://www.handturkey.com/$1 [R,L]

This instructs the server to take any traffic on port 80 (HTTP) and forward it to 443 (HTTPS), forcing the traffic onto a secure channel. The Duch are grateful, to say the least. A week later you receive an iPad in the mail, a personal thank you from the dutch CEO, Filibert Broos.

Posted in CodeComments (0)

How The MediaTemple Have Fallen


They say that Rome wasn’t built in a day, but that it burned in less than a week.

As a web designer I get asked certain questions more than others. What’s an Internet? Why are you so pale? What web host is best? I used to think I knew the answers to these questions. I’m not so sure about the last one anymore.

It’s so easy to write a disgruntled hatchet job about a product or service, just look at Yelp. So I am making a conscious effort to tell the story of the collapse of my opinion of the once venerable MediaTemple hosting service.

I used to describe them as the “The Gold Standard” of web hosting. It seemed like everyone who was anyone on the web was hosted at MediaTemple. Sony, Adobe, Starbucks, and Toyota adorn their client list, and that little (mt) logo appears on countless respected sites. I remember seeing it and wondering what club I was missing out on.

I wanted SSH and fancy doodads and I was willing to pay for it. I decided to give up my HostGator, and I upgraded to the best. Life was good. I had everything I needed. I had swift, informed responses to my support requests. I had web-based tools to accomplish almost any task. How did I ever live with this level of service?

Service isn’t everything. September of 2009 the outages begin. High server loads and severe latency caused incident reports to begin cropping up. My sites slowed down and became unreachable. MediaTemple repaired the issues and I was very quick to give them the benefit of the doubt. I mean, even Google goes down sometimes. Right?

In December the servers got hacked. We weren’t told how this occurred, but we were told that there was an “exploit affecting Storage Segment 01 on Cluster 05″, which was my home. This wasn’t a matter of a door being left open in my code, this was a server exploit. Files were overwritten. Data was deleted. Then the kicker: They couldn’t find my backup. The good news was that I keep backups, but data generated on the server was gone forever. They were very sorry. They gave me some service credit.

In early March, load balancing errors take my sites offline once more. All my service requests were replied to with links to the support incidents. We were all glad to hear that “The odds of a recurrence are minimal”.

Mid-March their servers get hacked again. Apparently a brute-force attack against the database servers allowed attackers to insert arbitrary code into our sites. We are now all required to change the passwords for our database users. Classy.

It is currently March 19th. All my sites are down. No one has any idea why. I can’t get to my WordPress installation, which is why I’m currently writing this post in TextEdit.

I don’t know how to move forward. The bells and whistles don’t seem to mean anything if the server isn’t up. If you can’t secure your systems against a brute-force attack, what the hell can you defend against? Switching hosts is an enormous hassle, but staying onboard isn’t exactly hassle-free. And frankly, I got no place to go.

Posted in WebComments (1)

Using Flash To Play With Images (AS3 + PHP)


Using Flash to get an image and play with it is a bit more complicated than it looks. The reason is that you can’t take an image from your hard drive and drop it directly into the Flash Player because the Flash Player doesn’t have permission to read data from your machine. The only way to get an image from your local drive into Flash is to first upload it to the server, then re-download it. Here’s a drawring.

I know, it’s the definition of circuitous, but thems the breaks. So we need to write two bits, the Flash (we will use AS3) to run on the client, and the PHP to run on the server. One note before we begin: Due to Flash’s sandbox restrictions, this is most easily tested in a live environment. I’ve had a lot of trouble testing locally.

Firstly, let’s talk Flash upload. The main class we will use for uploading is the FileReference class. This class allows us to upload and download files using Flash.

private var myFileRef:FileReference = new FileReference();

The only mission critical function call is the browse() function. We apply a file filter to prevent Flash from sending us anything but an image. This is only client side validation, so stronger measure are required server side.

var formats:String = "All Formats (*.jpg,*.gif,*.png)", "*.jpg;*.gif;*.png;", "JPEG;jp2_;GIFF";
this.myFileRef.browse([new FileFilter(formats)]);

That alone will bring up our old friend the browse window for your local machine. Now it’s a matter for the event listeners. By attaching them to the FileReference object, we monitor events like Event.SELECT (which occurs when the user picks a file and hits select, or Event.CANCEL which is called if the user hits cancel. Here are all the events you might listen for:

myFileRef.addEventListener(Event.SELECT, this.selectFile);
myFileRef.addEventListener(Event.OPEN, this.openFile);
myFileRef.addEventListener(HTTPStatusEvent.HTTP_STATUS, this.httpStatus);
myFileRef.addEventListener(Event.COMPLETE, this.completeUpload);
myFileRef.addEventListener(SecurityErrorEvent.SECURITY_ERROR, this.securityError);
myFileRef.addEventListener(IOErrorEvent.IO_ERROR, this.ioError);
myFileRef.addEventListener(Event.CANCEL, this.cancel);
myFileRef.addEventListener(ProgressEvent.PROGRESS, this.uploadProgress);
myFileRef.addEventListener(DataEvent.UPLOAD_COMPLETE_DATA, this.uploadComplete);

So when the SELECT event fires, this handler takes care of it:

function selectFile(e:Event):void {
	myFileRef.upload(uploadURL);		
}

Where uploadURL is the address of the PHP script we will setup to receive the upload as a POST variable. So, what we’ve got so far is the equivalent of a file post form element in html. It took us a while to get there, but it gave us finer grain control. Now we need the PHP script to accept the data and turn it into a file.

if (isAllowedExtension($_FILES['Filedata']['name'])) {
	// Path to storage
	$storage = 'flash_uploads';
 
	// Create a random for file
	$newRandName = time().rand();
	$newRandFile = $newRandName.".".findExtension($_FILES['Filedata']['name']); 
	$uploadfile = $storage . "/" . $newRandFile;
 
	// Try to move the uploaded file into permanent storage
	if ( move_uploaded_file( $_FILES['Filedata']['tmp_name'] , $uploadfile ) ) {
		echo($newRandFile); // Return the name of the file
	} else { // If the move failed
		echo( '0'); // Return 0 as an error code
	}
}
// Extract the file extension from the filename
function findExtension ($filename) { 
	$filename = strtolower($filename) ; 
	$exts = split("[/\\.]", $filename) ; 
	$n = count($exts)-1; 
	$exts = $exts[$n]; 
	return $exts; 
} 
// Check to make sure the file extension is valid
function isAllowedExtension($fileName) {
	$allowedExtensions = array("gif", "jpg", "jpeg", "png");
	return in_array(end(explode(".", $fileName)), $allowedExtensions);
}

Since the Flash used regular old POST to upload the file, the result is of course is the return page. We use this to inform the Flash about what happened. In the event of a failure the Flash will receive an error code, but if things go well, the Flash will receive the name of the newly created file on the server. We must now download it with a standard Loader.

var photoloader = new Loader();
var loadRequest = new URLRequest (baseurl+"/flash_uploads/"+serverFileName);
photoloader.load(loadRequest);
photoloader.contentLoaderInfo.addEventListener(Event.COMPLETE, onLoadComplete);
 
function onLoadComplete(event:Event):void {
	stage.addChild(photoloader);
}

where serverFileName is the name of the file returned by the server, and baseurl is the url of the server on which our new file can be found. Our new loader is then added to the stage, where we can play with it. Remember this process can accumulate files on the server, so you might want to do a bit of clean up as well.

Posted in CodeComments (2)

What is a Website?


This entry is part 2 of 5 in the series Web Coding For People Who Are Tired of Being Called Dummies (click to view in order)

You know what a website is, but you’re not sure what a website is.

The best way to think about a website is simply as a group of files. Files just like the ones on your hard drive, organized into folders. Except instead of files that end in .doc and .mp3, these files end in things like .html and .jpg. Website files are kept on a server and delivered to your browser when you ask for them by visiting a particular URL. Your browser analyses them and renders them to the screen.

So next up we are going to make a very small website which will live on your hard drive. People won’t be able to access this website while it is on your hard drive, but it will allow you to build it. When it is ready you can put it on a server on the Internet and then bang. Live website.

Posted in CodeComments (0)


