Forum Replies Created

Viewing 14 replies - 1 through 14 (of 14 total)
  • Thread Starter Green Being

    (@green-being)

    The scan under Firefox terminated successfully and serve up a new scan report depicting all of the clean-up changes I did the previous scan. I think that this scan report with its various audit tools is pretty nice.

    Be prepared to do the audit work if you want to expect a clean scan report. I didn’t find any malware as such but did find other stuff that needed to be cleaned up for consistency. I do think that you need to get your site as consistent as possible to establish a clean baseline for going forward with Ninja Scanner.

    So, I think that this has all sorted itself out. More to learn, I am sure 🙂

    Color me impressed …

    Thread Starter Green Being

    (@green-being)

    My host did kill the process but I suppose I could have done this by deactivating the plugin, which is what my host did. But, since my website was locked up, I could not get to the plugin page.

    After the process was killed, I was still locked up, which made me think that the issue was with my browser (Chrome). I opened the website successfully with Firefox but had to restart Chrome to do the same.

    In this process, I did discover the NinjaScanner tool that let’s examine the scan log file by file. Very, very nice! I am going through that now and intend to rerun the scan under Firefox. I will report back …

    Thread Starter Green Being

    (@green-being)

    I ran another scan because the one to which I was referring was over five days old and so, pre-migration. And now this scan has sent me a very detailed scan report BUT it has also seized control of my website by not terminating. I cannot cancel the scan either, it seems. This is not good. 🙁 I will have to contact the host to see if they can kill the process. Yikes!

    Thread Starter Green Being

    (@green-being)

    Hi Author,

    Good news: For unrelated reasons, I recently migrated to another hosting provider–InMotion–and now the scanner does not timeout. And I no longer get a 504 Error when trying to access the Options page.

    I still can only install the NinjaFirwall as a WordPress WAF. I am sure I configured it correctly according to my PHPAdmin page information.

    Now, my only remaining issue is how to interpret the scan log. Lots of entries with warnings and failed checksums but what am I to do about them? Rhetorical question.

    Anyway, the firewall seems to be configured and running. Let’s see how it goes for protecting my production website …

    Cheers.

    Thread Starter Green Being

    (@green-being)

    It does not seem that .user.ini files are allowed. I think that .htaccess may be used otherwise but not sure. .htaccess for Apache set up and .user.ini for CGI/FastCGI setup?

    It may be that my other security firewall at the IP level is conflicting … but if it is, I am not going to disable it. I could IP-whitelist it possibly, but I don’t see anywhere to do that with your plugin.

    Thread Starter Green Being

    (@green-being)

    Thanks for the quick reply.

    Okay, I tried all of those recommended solutions. They didn’t work either. The scan just does not terminate successfully.

    FYI, I am running on a shared server under HostGator. HostGator says 30 seconds is an industry standard for a shared or reseller server. I think GoDaddy is also 30 seconds but not fixed … but GoDaddy has a kill script for scripts running over 60 seconds.

    Moreover, HostGator says that it is not difficult to write software to obey these limits and still get the job done … scans in this case. The job can be broken up into several PHP scripts, for example. This is allowed on HostGator.

    I had HostGator monitor a scan with NinjaScanner. They also experienced 504 errors for some of the web pages and said that the scan job they finally executed was not even close to the 30 second CPU time limit when it hung up. They suggest that the plugin is just not working correctly … and it could be compatibility issues with other plugins or with my WAF security service by Sucuri Firewall.

    Anyway, it seems that I cannot really use your scanner under these circumstances.

    Thanks for your patience.

    I am having the same problem and following all of the recommended fixe in this thread. The only one that allows my scanner to “successfully” terminate is the disabling of the Anti-malware signatures step. But, isn’t this the point of the scan in the first place! Are we not scanning for malware? I am a bit confused that this is the last post in this thread. Is the issue resolved?

    Thread Starter Green Being

    (@green-being)

    Hi, thanks for the quick response!

    I think the answer to your question is yes. As I understand it, I am using WAF running on top of a CDN. The vendor is Sucuri. I do not know if they are filtering any output considered offensive. I checked my error logs for the site and I do not see anything that jumps out. I can look some more if you can tell me where else to look.

    There is another thing that seems to be an issue: I also installed the NinjaScanner to complete the NinjaFirewall set. With it, I started a scan yesterday and it has yet to complete. It seems stuck. Could this be related?

    One other perhaps relevant note is that, in order to complete the installation on my website, I had to go the WordPress WAF way.

    Thread Starter Green Being

    (@green-being)

    UPDATE: In spite of what I said earlier, I found that the plugin WP jQuery CDN was the culprit with respect to the NextGEN Gallery by Photocrati. The update brought that particular plugin into conflict.

    @windwoman: I have absolutely confirmed that this issue is related to the last update and NOT due to a plugin conflict. I had not updated the plugin on my LOCAL server, but had on my LIVE website, where and when this problem described arose. But, when I updated the plugin on my local server – and that alone – the problem got transferred to that server implementation as well. QED.

    Since we are not hearing from the developer on this, I am going to have to punt and find another solution … of which there are countless.

    GB

    I am having a similar problem, I suspect since the plugin update. The plugin has been working fine since install several months ago, but now the slideshow stacks the images into a single column instead of rotating them in a single slideshow box with auto transitions. Fiddling with the settings does not help. Deleting and re-installing the slideshow does not work. I am also using fancybox for the image lightboxes, but that hasn’t been a problem. I have tried to selectively deactivate newest plugins to no avail, but not exhaustively. I think something went wrong in the updated version, but not sure. Is there a way to roll back?

    See My Site

    Appreciate any assistance with this issue. Thanks.

    Just a follow up to the original observation for this thread.

    I found that the pink-encased message disappeared when I finally went out and selected a medium (e.g. phone) for the “setting an appointment” choices presented in the contact form. I believe that you only get ONE choice (still trying to clarify with vCita) under a FREE account. What I noticed when I made that choice through my vCita account was that one of the two vCita meeting-setting icons disappeared AND the pink-encased message disappeared.

    I would agree that vCita could make the process a little less ambiguous through that message. Right now, it kind of has you going in circles at the moment. 🙂

    Thanks Mike!

    I have another question but maybe need to open a different thread.

    Anyway, I am wondering if vCita is capturing/logging the emails sent out from FSCF with the vCita integration enabled. Right now I am using your Contact Form DB integration, which works great. I will ask vCita as well.

    I have exactly the same concern, only I DID want vCita for my client, whom I assured that FSCF is the “mother of all contact forms”. I still think this (and will send a donation), but how in the heck to I dismiss the pink-encased message that shows up at the top of everywhere in my admin area? I went through the same experimentation as PrettySickPuppy and was UNplesantly surprised that the Dismiss link is NOT to dismiss the message, but to DISABLE cVita … which I had to enable again. Seems like this pink message: “FAST SECURE CONTACT FORM – You still haven’t completed your Meeting Scheduler settings. Click here to learn more or Dismiss” is more a marketing thing for cVita than anything else.

    No link, since this is in my Admin area.

Viewing 14 replies - 1 through 14 (of 14 total)