By Todd on Wednesday, 30 July 2014
Posted in General
Replies 11
Likes 0
Views 1.9K
Votes 0
How does the suggestion outline here - http://stackideas.com/faq/easyblog/i-have-issues-uploading-images-in-media-manager impact the security of my website? Does it open it up for vulnerabilities because I allow help forums and blogs?

To disable DFI shield, please follow the steps below:

Access admin tools.
Click on Web Application Firewall.
Then, click on Configure WAF.
Finally, scroll down to Direct File Inclusion Shield (DFIShield) and disable this option.
why couldn't you simply define a component exception in Admin Tools administrator instead of completely disabling it?
·
Wednesday, 30 July 2014 08:19
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Todd,

Disabling the DFI shield will disable detection of parameters like "../" or "../../" or "../something/" . We have spoken this with Nicholas from Akeeba and this is the only work around that he suggested because EasyBlog needs to post data back to the server by providing the necessary paths.
·
Wednesday, 30 July 2014 03:37
·
0 Likes
·
0 Votes
·
0 Comments
·
Paul, THANK YOU for your input!

Can you please provide me with a little more detail about this option and/or point me in the direction of a tutorial?

Thanks again!
Todd
·
Wednesday, 30 July 2014 10:10
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Todd,

Sorry but I don't quite get you here. You can actually see the steps to disable DFI Shield as outlined at http://stackideas.com/faq/easyblog/i-have-issues-uploading-images-in-media-manager
·
Wednesday, 30 July 2014 10:18
·
0 Likes
·
0 Votes
·
0 Comments
·
Paul wrote:

why couldn't you simply define a component exception in Admin Tools administrator instead of completely disabling it?


If there's a way to add exception, then it's possible but it's not possible to add exception for this.
·
Wednesday, 30 July 2014 10:20
·
0 Likes
·
0 Votes
·
0 Comments
·
·
Wednesday, 30 July 2014 10:25
·
0 Likes
·
0 Votes
·
0 Comments
·
Mark wrote:

Paul wrote:

why couldn't you simply define a component exception in Admin Tools administrator instead of completely disabling it?


If there's a way to add exception, then it's possible but it's not possible to add exception for this.


In Admin Tools go to: Web Application Firewall>WAF Exceptions and define it there.
·
Wednesday, 30 July 2014 10:31
·
0 Likes
·
0 Votes
·
0 Comments
·
Todd wrote:

https://www.akeebabackup.com/support/admin-tools/12986-how-to-disable-admintools-for-image-uploads-in-easyblog.html

The above solved the problem perfectly!


yes, specifically:
Admin Tools>Web Application Firewall>WAF Exceptions
·
Wednesday, 30 July 2014 10:32
·
0 Likes
·
0 Votes
·
0 Comments
·
Thanks for the heads up on this Paul! Didn't know that you could add these exceptions.
·
Wednesday, 30 July 2014 10:35
·
0 Likes
·
0 Votes
·
0 Comments
·
Glad to help. Every Joomla! site should be running Admin Tools Pro in my opinion.
·
Wednesday, 30 July 2014 10:42
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Paul,

Thanks for sharing
·
Wednesday, 30 July 2014 16:49
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post