Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Impotence
Nov 8, 2010
Lipstick Apathy
I'm working on a new site, what is the latest/hipsteriest frontend framework now? http://www.getmdl.io ?
I'm looking to specifically not use bootstrap/pure/foundation

Adbot
ADBOT LOVES YOU

Impotence
Nov 8, 2010
Lipstick Apathy
Oh nah, I'm not hating on any of them, I just want to use something different for a change pretty much. Probably sounds dumb.

Impotence
Nov 8, 2010
Lipstick Apathy

Loezi posted:

Please stop asking me for a "state or provice" when I'm living in a country that does not use them as part of their postal system. Forcing a user to mangle his/her address to a format that is illogical and foreign just to satisfy some database schema you brewed up is just stupid from the user's perspective.

Impotence
Nov 8, 2010
Lipstick Apathy

fuf posted:

roger that.

I knew it was expensive but yeah looking closer it's pretty crazy how much a basic stack would be.

I've had a server with oneprovider for a long time (used as a seedbox) and it's always been pretty reliable, so I might give one of those a try as a web server. They have pretty good deals:
http://oneprovider.com/dedicated-servers/london-united-kingdom

Their Paris servers are crazy cheap: http://oneprovider.com/dedicated-servers/paris-france

I also want to find someone I can pay to help me with server setup. PMs welcome :) I can bumble through it myself but I'm always super paranoid about stuff like mysql running out of memory and shutting itself down, and also about the server sending out spam because of hacked wordpress sites. I want some expert reassurance that things are set up properly, and also guidance on installing Varnish (worth it?) and some kind of monitoring software.

oneprovider paris resells online.net. i pay about 30something euros for ~32/64gb ram machines at online. and more notably, $2/month for 2GB RAM full dedicated servers. they (online.net) are free.fr, one of the larger isps in france, and occasionally have some hilarious deals - i still have a "limited offer" 2x2tb hwraid dual E5 with 64 GB ram for something like $49/m

Impotence fucked around with this message at 12:26 on Aug 8, 2015

Impotence
Nov 8, 2010
Lipstick Apathy
check error.log, probably has nothing to do with file itself

Impotence
Nov 8, 2010
Lipstick Apathy

v1nce posted:

Place your bets now! My money is on an .htaccess mistake.

Apache 2.4 breaks people that don't know how to use grant/deny, it's really funny too

But yeah probably htaccess typo or something

Impotence
Nov 8, 2010
Lipstick Apathy

Lumpy posted:

I'm going long shot money on parent directory set to 600 permissions.

this should generally just show a 403 I would think

Impotence
Nov 8, 2010
Lipstick Apathy
you aren't loading bootstrap.js properly, or not calling button on all elements

Impotence
Nov 8, 2010
Lipstick Apathy
anyone try this yet? https://github.com/OfficeDev/Office-UI-Fabric

Impotence
Nov 8, 2010
Lipstick Apathy
comedy option i've seen is also setting the entire body to invisible or off-screen, then hooking domcontentloaded and setting it visible all at once, possibly with a horrendous css3 upward-fadein transition so it appears to load faster even though it doesn't

Impotence
Nov 8, 2010
Lipstick Apathy

onemillionzombies posted:

I'm very new to web design and I recently made a modern website for a small business I work for. Everything seems great except the new wholesale form which I put up for them is getting all of its confirmation emails sent directly to customer's spam folders. It's using the exact same from/sender addresses as the old wholesale form, but those confirmation e-mails are getting through just fine.

The new wholesale form is using PHPMailer, would trying SMTP perhaps get the job done?

send via something like amazon ses instead.

Impotence
Nov 8, 2010
Lipstick Apathy
I know someone that will do it for free that wants some portfolio padding for simple tasks, hilariously enough.


How exactly is this managed right now? I don't see any flash loading on a browser with flash enabled.

Impotence
Nov 8, 2010
Lipstick Apathy
this doesn't have a git repo and build server and continuous integration??

Impotence
Nov 8, 2010
Lipstick Apathy
Sent a pm, i'm out for a run right now on mobile so I'll reply when I get back I guess

Impotence
Nov 8, 2010
Lipstick Apathy
try rewrite ^/sitemap.xml$ /index.php?sitemap=1 last;

Impotence
Nov 8, 2010
Lipstick Apathy
https://enterprise.github.com/case-studies could help a bit?

Impotence
Nov 8, 2010
Lipstick Apathy

Karthe posted:

I'm not sure if this is a good place to ask this, but do all SSL certificate services require you to enter your personal information even if the cert is intended for your employer? A friend pointed me to StartSSL for their free tier 1 certificates. I tried registering with our business address but afterwards I received an e-mail from them that said that I had to enter my personal address and phone number. I'm really uncomfortable with that idea and I think it's silly that that's a requirement when I'm not going to be using the certificate for a personal site.

Is this just how it works when getting an SSL certificate, regardless of the provider?

no, most don't ask for anything at all

startssl is not a businessey thing, they are basically meant for personal sites and playing around, do not use it for business

Impotence
Nov 8, 2010
Lipstick Apathy

fuf posted:

Regarding the above: how can I figure out which London datacentre OneProvider (http://oneprovider.com/ , part of https://gobsn.net) is using for their servers?

I want to provide a postal address for a server I have with them but I can't find any info beyond references to "our location in London". Do companies intentionally try and keep that kind of info obscure or something?

oneprovider is basically just a reseller + markup, which might be why they don't like to out all of the dc info

Impotence
Nov 8, 2010
Lipstick Apathy

nexus6 posted:

Yeah, they've decided to move to Umbraco but we've no idea why. I can't even think of any sites that use it.

We're going to get in touch and say obviously we're disappointed in their decision and we'd encourage them to make sure Umbraco meets all their requirements. Since we don't know what led to this decision we'll include a laundry list of reasons we recommend D7 over other solutions.

I think they've been charmed my some Microsoft vendor because I really don't think they know what they are talking about, 'issues we've been having with php' for example. All the issues they 've had with their POS site have been the rear end-backwards way it was implemented by whoever's nephew they hired to build it. A quick example, there is a sidebar search from with multiple filters but all it really does is throw every form value into a keyword search.

https://www.nexon.net and its sub-sites and microsites are built on umbraco if that matters

Impotence
Nov 8, 2010
Lipstick Apathy
try put it above the location / for wordpress's rewrites, or ^~ /logs or something

Impotence
Nov 8, 2010
Lipstick Apathy

Omits-Bagels posted:

I'm assuming the theme is fairly bloated

<link href='//fonts.googleapis.com/css?family=Open+Sans:100,100italic,200
,200italic,300,300italic,400,400italic,500,500italic,600,600italic,700,70
0italic,800,800italic,900,900italic%7CRaleway:100,100italic,200,200italic
,300,300italic,400,400italic,500,500italic,600,600italic,700,700italic,8
00,800italic,900,900italic%7CLora:100,100italic,200,200italic,300,300ita
lic,400,400italic,500,500italic,600,600italic,700,700italic,800,800itali
c,900,900italic%7CMontserrat:100,100italic,200,200italic,300,300italic,4
00,400italic,500,500italic,600,600italic,700,700italic,800,800italic,900
,900italic%7CMontserrat+Alternates:100,100italic,200,200italic,300,300it
alic,400,400italic,500,500italic,600,600italic,700,700italic,800,800ital
ic,900,900italic%7COpen+Sans:100,100italic,200,200italic,300,300italic,4
00,400italic,500,500italic,600,600italic,700,700italic,800,800italic,900
,900italic%26subset%3Dlatin%2Clatin-ext' rel='stylesheet' type='text/css' />
<link rel='stylesheet' id='ls-google-fonts-css' href='//fonts.googleapi
s.com/css?family=Lato:100,300,regular,700,900%7COpen+Sans:300%7CIndie+Fl
ower:regular%7COswald:300,regular,700&subset=latin%2Clatin-ext' type
='text/css' media='all' />




:psyboom:

Impotence
Nov 8, 2010
Lipstick Apathy
foreach (JSON.parse(<file.har>).entries as e) { console.log(e.url); }, dump that out as one per line?

Impotence
Nov 8, 2010
Lipstick Apathy

Munkeymon posted:

Is it actually all that common for attackers to get code+db dumps but not be able to read environment values from live machines or find setup scripts/chef configs/whatever?


If Ashley Madison had encrypted their DB values, a lot of people wouldn't be dealing with blackmail threats right now.

Yes: not code dumps, but SQLi results in DB dumps, but NOT code dumps or reading envvars. But if you use a poo poo db that allows some form of SELECT EXEC(WHATEVER) then all bets are off

AM has a whole other group of issues, and no this would not have helped in any way - AM appears to have been significantly compromised well past db considering even internal emails were leaked, and on top of that they weren't even close to following best practice considering no verification of emails, and hashing passwords with md5()

Impotence fucked around with this message at 16:36 on Nov 4, 2015

Impotence
Nov 8, 2010
Lipstick Apathy

v1nce posted:

What happens if someone gets access to the server?
What if someone gets access to out hosting?

What happens if an attacker convinces your hosting company (assuming not AWS) to hook up IPMI/OOB-KVM, reboot into single user mode? Are disks encrypted at rest too?

Impotence
Nov 8, 2010
Lipstick Apathy

v1nce posted:

Questions like this are why you need to play the game with knowledgeable people.

Half the time I get to play this game with freelance or contract clients it results in "why can't we just use godaddy shared hosting"

Impotence
Nov 8, 2010
Lipstick Apathy

Munkeymon posted:

OK great so what's preventing an attacker from making what looks like a perfectly normal key request from an owned machine? In this scenario, the attacker can see the code that makes the requests, so it should be trivial to replicate one. Or are we assuming they got the code with, say read-only-no-execute access?

If they see the code, they still need to be able to execute the request from within your internal network.

Secret managements basically result in a ton of pros: every single key request being logged and auditable [and possibly rejectable if they look suspicious, happen at a time that don't coincide with reboots or restarts of your machines, be at a higher volume than normal], immediate invalidation and cycling of keys throughout the entire infrastructure or disabling the ability of an owned machine to acquire any secrets at all, passwords not being present in envvars, config files, or otherwise, using a secrets-server allowing automated management of AWS KMS and IAM.

Impotence
Nov 8, 2010
Lipstick Apathy
flip key / value over in $alphabet and look for $alphabet[get_firstletter($str)] so you have $alphabet = ['a' => 1];

array_search somewhat overkill when you can do a single constant time lookup since you already know the array index

Impotence
Nov 8, 2010
Lipstick Apathy

Munkeymon posted:

There's no PHP involved. I just mention it because every result on Google is some PHP noob not knowing how to get the data into $_POST :(


Yeah. You can see them there without inspecting, but they show up in the element inspector, too.

Are you adding disabled to any part of the select chain? Because that will stop it from showing up.

Jsfiddle or something the entire thing + JS if you can.

Impotence
Nov 8, 2010
Lipstick Apathy

Karthe posted:

Alright guys, I need help with something. How am I supposed to leverage environment variables to store things like database passwords if these variables exist only for the life of the session in which they're created? Right now I run gunicorn from within Screen (soon Supervisor) to keep my server running in the background, but I can't think of a way to do this without writing a bash script to set the environment variable before launching gunicorn. That would defeat the purpose of env variables since I'd end up hardcoding the password in the bash file, right?

Acquire your passwords with/from something like https://github.com/square/keywhiz or https://github.com/hashicorp/vault .

Impotence
Nov 8, 2010
Lipstick Apathy
I'm hella curious why you would move to Mongo from MySQL. I don't really have any advice on how to do it, just really really curious as to the why.

Impotence
Nov 8, 2010
Lipstick Apathy

an skeleton posted:

I don't disagree with y'all, unfortunately I don't really have the clout at this point to convince the powers-that-be that we should revert back to SQL. I'm assuming that even though NoSQL dbs are technically schemaless, they still try to enforce some level of normalization? Like... we need to expect some type of structure, right? (I just read that article for the 2nd time and the answer appears to be No)


no, not at all. lol

if you want to store documents where you can't control or know the schema associated with other relations, i think the best way is still postgres' json/jsonb type

Impotence
Nov 8, 2010
Lipstick Apathy

an skeleton posted:

Hahahaha. Well. Will report back when I'm dead.

you are an skeleton already

Impotence
Nov 8, 2010
Lipstick Apathy
have to steal as much code as possible before the licence change, if i have it saved already they can't get me!!

Impotence
Nov 8, 2010
Lipstick Apathy

kedo posted:

If I were SO I would immediately start injecting the following into people's clipboard when they copy something off the site.

1 minute hackjob, use it as a bookmarklet or greasemonkey or something

Impotence fucked around with this message at 01:41 on Jan 16, 2016

Impotence
Nov 8, 2010
Lipstick Apathy

Non Serviam posted:

I'm trying to update my site's podcast, and now the feed isn't loading properly.

You don't HAVE a podcast feed there. You need to get one before you can add it.

The URL you probably want to add is http://www.metalblast.net/category/podcast/feed/

Impotence
Nov 8, 2010
Lipstick Apathy
File extensions are completely meaningless; that IS the xml file you are looking for, and it is xml.
You probably had a redirect or a saved file cached there.

Impotence
Nov 8, 2010
Lipstick Apathy

Kings Of Calabria posted:

Ok, here's four current sites I'm working on... three of them are ongoing which is garbling my brain and making me completely unable to view them as an outsider, as I have been staring at all of them for hours and hours by this point.


You have mismatched tags all over the place like <section><a><div></section></a>, multiple <body> elements stacked in each other, <script> outside of <html>, and a lot of duplicate attributes like <div class="" class="">

Impotence
Nov 8, 2010
Lipstick Apathy

Kings Of Calabria posted:

:/ is that a back to basics html thing? I never even noticed but ya that seems like something I would do and not notice because it works in my specific browser. What body elements am I using wrong and what should I be doing instead?

Yes.

I'm surprised your links even go to the proper place when clicked, because this is really really not valid - you don't close links, so if you click the inner one, do you know deterministically which location will go to?



Code-wise your class names and etc are basically meaningless and the equivalent of <div style="width:50;height:50;">. Additionally, you're horrendously abusing tables. Every single link being a table is :psyduck:

Also never use &nbsp; to position content

quote:

like vertical aligning with a 100% width/height table

It would be easier to literally just apply CSS vertical aligns with position/top/transform or display:table/table-cell;vertical-align

For things like navbars, have to played with line-height?

---
Syntax:


More nested tags that are illegal to nest:


---

I am actually curious as to why you would do this, I want to hear your reasoning on it:


CSS supports letter-spacing.

Impotence fucked around with this message at 01:09 on Feb 7, 2016

Impotence
Nov 8, 2010
Lipstick Apathy

Evil Vin posted:

Thanks for the help. It might not be worth the effort for something I was just really playing around with. Though I may still ask them about next time I email them.

comedy option

code:
<img src="<?= explode('"', show('comic_image'))[3] ?>">

Adbot
ADBOT LOVES YOU

Impotence
Nov 8, 2010
Lipstick Apathy
did you `service nginx restart`? it looks like it should work

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply