Oh no! Where's the JavaScript?
Your Web browser does not have JavaScript enabled or does not support JavaScript. Please enable JavaScript on your Web browser to properly view this Web site, or upgrade to a Web browser that does support JavaScript.
Sign In
Not a member yet? Click here to register.
Chan

PHP-Fusion 9 and 7 Security Announcements regarding ImageMime Exploits.

by Chan, Last updated on 2 years ago in Security Issues & Announcements - 8
I'm strongly advising all sites on Fusion 7 and 9 to immediately update on these values to your .htaccess file soonest possible.

ForceType application/octet-stream
<FilesMatch "(?i).jpe?g$">
    ForceType image/jpeg
</FilesMatch>
<FilesMatch "(?i).gif$">
    ForceType image/gif
</FilesMatch>
<FilesMatch "(?i).png$">
    ForceType image/png
</FilesMatch>
Lead Developer of PHP-Fusion
Developer Tweet: https://twitter.com/phpfusion_tweet
Chan - Thanks for the advice.
Without this code
ForceType application/octet-stream


Only this

<FilesMatch "(?i).jpe?g$">
    ForceType image/jpeg
</FilesMatch>
<FilesMatch "(?i).gif$">
    ForceType image/gif
</FilesMatch>
<FilesMatch "(?i).png$">
    ForceType image/png
</FilesMatch>
PHP-Fusion Development Manager
Web Designer/Developer: GitHub
With ForceType application/octet-stream in .htaccess it seems to block css. Site looks like no css is loaded.
Without ForceType application/octet-stream site is OK.

Does the rest of the htaccess work correctly without ForceType application/octet-stream in htaccess?
www.probemyip.com/probe-my-ip-80x15.png

pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
My htaccess with ForceType application / octet-stream and my site is OK. Css working.
Double check with browser cache emptied! Initially I didn't notice because css was cached, after flushing cache I noticed.
www.probemyip.com/probe-my-ip-80x15.png
pHp-Fusion.Asia & pHp-Fusion.Fr & pHp-Fusion.Cn are available for a localized support community. Send PB for info.
Writing in my .htaccess works. OK.
Linux-Ubuntu, Windows7-WinXP SP3, PHP5, HTML5, Mozilla-Firefox 3.6.3, Opera 10.51, IE 8.0.6
https://www.phpfusion.cz
1. .htaccess do not work on Windows Server, what can i do
2 . i found no .htaccess in PHP Fusion 7.02.07
.htaccess does not work on Windows Server because is only for servers based on Apache. You must convert .htaccess to Web.config.
PHP-Fusion Development Manager
Web Designer/Developer: GitHub
You can view all discussion threads in this forum.
You can start a new discussion thread in this forum.
You cannot reply in this discussion thread.
You cannot start on a poll in this forum.
You cannot upload attachments in this forum.
You can download attachments in this forum.
Users who participated in discussion: Wanabo, Kvido, Chan, Harlekin, zizub, RobiNN