FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > FutureQuest Site Owners (All may read - Only Site Owners May Respond) > News & Announcements
User Name
Password  Lost PW

 
Thread Tools Search this Thread Display Modes
Old 07-31-2003, 11:21 AM   Postid: 92855
 Terra
CTO FutureQuest, Inc.
 
Terra's Avatar
 
Join Date: Jun 1998
Location: Z'ha'dum
Posts: 7,678
[FQuest Upgrades] Secure_Mode™, Apache 1.3.28 and PHP 4.3.2

When: See below
Window: 1:00am - 6:00am (EDT)
Duration: 5 - 60 minutes (per server)

UPGRADE SCHEDULE:
[DONE] 08/02/2003 - MQS0001, MQS0002, MQS0003, MQS0004(**M40x)
[DONE] 08/03/2003 - RASMUS, ENIGMA, HC01
[DONE] 08/04/2003 - ASTRO, SCOOTER
[DONE] 08/05/2003 - QBERT, ZOOMER, SONIC
[DONE] 08/06/2003 - TAZ, SIX, NINE, SEVEN
[DONE] 08/07/2003 - PHOENIX, DEXTER, DEEDEE, LOLA
[DONE] 08/08/2003 - ESCHER, HUGO, UNITY, HANNA

=== Apache ===

Apache is being upgraded to version 1.3.28:
  • new code to help prevent recursive loops on internal subrequests
  • eliminate leaking of file descriptors from Apache children that spawned CGI scripts
With Apache 1.3.28, we have dropped the old db1 and ndbm hash library bindings, in favor of the newer db2 library... This is a security update to squelch an unfortunate privacy leakage issue where db1 did not properly zero out its working memory area before building its hash structures... No changes will need to be made by site owners using DB style password hashes, as it should be a transparent upgrade with db2 having the ability to read db1 hashes...

Also joining the Apache 1.3.28 lineup is a new custom Apache module entitled FQ-SRC (Spider Rate Control)... FQ-SRC provides much finer grained clamping of abusive spiders and more detailed (internal) stats that should be easier to drill through with realtime alerting capability... FQ-SRC joins our proprietary ZenForce™ Family of server and network management controls, after many months of development and testing... Prior to this new module, FQ-Guardian performed this duty and will now be modified to provide an additional level of defense against server overloads by working side-by-side with FQ-SRC...


=== PHP ===

We are pleased to announce the upgrade of all servers to the new PHP 4.3.2 version

You can view the full changelog here:
http://www.php.net/ChangeLog-4.php

Of particular, carefully check the changes from 4.2.3 to 4.3.2 to see if it will impact your sites operation...

New additions to the PHP 4.3.2 release:
  • Fixed the two Secure_Mode™ issues that postponed the last deployment
  • mbstring (Compiled with: --enable-mbstring=all, --enable-mbregex)
  • GD v2 library with GIF enabled
  • Add exif support
  • DBA with db2 hash library
  • FreeType 2 library (runs parallel with FreeType 1)
=== Secure_Mode ===

Secure_Mode™ is a FutureQuest proprietary subsystem that allows site owners to enjoy the freedom of having safe_mode off, while still retaining all of the positive security benefits that it provided. Please view this thread for the original Secure_Mode™ announcement.
http://www.aota.net/forums/showthrea...threadid=14277

Servers which are already running PHP Secure_Mode™
ASTRO, RASMUS, QBERT, ZOOMER, SONIC, ENIGMA, SCOOTER, HC01

Servers which will be upgraded to the new PHP Secure_Mode™ system
TAZ, SIX, NINE, SEVEN, PHOENIX, DEXTER, DEEDEE, LOLA, ESCHER, HUGO, UNITY, HANNA

Overall, a lot of effort has gone into this non-trivial release, and we are pleased that this new Apache/PHP/Secure_Mode™ combination has been shored up and now ready for full production deployment...

--
Terra
sysAdmin
FutureQuest

<EDIT: added a link to the PHP changelog>
<EDIT: remove the FreeType1 deprecation notice>
<EDIT: add 'exif' support to PHP>

Last edited by Terra : 08-08-2003 at 07:18 AM.
Terra is offline  
Old 07-31-2003, 11:44 AM   Postid: 92858
GSK8
Registered User

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Oct 2001
Posts: 160
Great

Just wondered if I need to back up my databases (and if so, how)? PHP and SQL very new to me. I run VB.
GSK8 is offline  
Old 07-31-2003, 11:58 AM   Postid: 92859
 Kevin
Systems Administrator
 
Kevin's Avatar
 
Join Date: Aug 2001
Location: Orlando, FL
Posts: 2,481
Quote:
Originally posted by GSK8:
Great

Just wondered if I need to back up my databases (and if so, how)? PHP and SQL very new to me. I run VB.
Yes and no

No because Terra is referring to the db that Apache uses for large authentication hash files which is not related to MySQL at all.

Yes because you should be backing up your databases anyway regardless of what we are doing. Go here for more info: http://www.aota.net/PHP_and_MySQL/mysqldump.php4

-Kevin
Kevin is online now  
Old 07-31-2003, 08:45 PM   Postid: 92889
Whisperer
Site Owner

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Apr 2003
Posts: 60
Quote:
No changes will need to be made by site owners using DB style password hashes
I have no idea what that means. I did my site pages in Dreamweaver and used the CNC to password protect a folder or two. I'm assuming the upgrade will be transparent to me, correct?
Whisperer is offline  
Old 08-01-2003, 12:08 AM   Postid: 92894
Jeff
Site Owner
 
Jeff's Avatar

Forum Notability:
872 pts: Dignified Competence!
[Post Feedback]
 
Join Date: Jun 2000
Location: Great Lakes
Posts: 4,221
What are "MQS0001, MQS0002, MQS0003, MQS0004(**M40x)" - I don't remember seeing them before ?
Jeff is offline  
Old 08-01-2003, 12:11 AM   Postid: 92895
Bradley
Site Owner
 
Bradley's Avatar

Forum Notability:
75 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Aug 1999
Location: Kingsport,TN
Posts: 794
I beleive the MQS are Managed Quest Server.
So TeRRa, are you going to upgrade my server while you're at it!?!?
__________________
Bradley
Nothing in this world that's worth having comes easy.
My blog

Last edited by brnoe : 08-01-2003 at 06:32 PM.
Bradley is offline  
Old 08-01-2003, 06:28 AM   Postid: 92907
 Terra
CTO FutureQuest, Inc.
 
Terra's Avatar
 
Join Date: Jun 1998
Location: Z'ha'dum
Posts: 7,678
Jeff:
MQS is an acronym for Managed QuestServer...

MQS systems are a relatively new offering for sites that have outgrown the resources provided by our Community Servers... In the most simplistic terms, it is a Community Server designed and built for one site that has high dynamic resource demands...

MQS systems are based on the Enigma class server core, and are managed just the same as the Community Servers are... This is why I went ahead and added them to the upgrade list...

The nice thing about MQS is that it can be custom tailored to the sites resource demands, as is evident with MQS0004... The (**M40x) notation was a reminder to myself that this server needed to have it's MySQL upgraded to 4.0.x and PHP needed to be linked against the new MySQL libraries... This is because the site's forums on MQS0004 needs Cached Queries, for which more memory has already been added to compensate for the additional resources required...

We were always saddened when a site had outgrown the Community Servers, and not having an option to offer them for dedicated services that their sites now require... The MQS offering has now stepped forward to fill that void in our lineup, and they are now performing even beyond our initial expectations...

--
Terra
--but, but, but, but I don't want to leave - I like it here - No, you can't make me go - I won't go--
FutureQuest

<EDIT: minor edit>

Last edited by Terra : 08-01-2003 at 11:09 AM.
Terra is offline  
Old 08-01-2003, 08:05 AM   Postid: 92908
 Arthur
Developer
 
Arthur's Avatar
 
Join Date: Nov 2000
Location: The Netherlands
Posts: 2,212
Quote:
used the CNC to password protect a folder or two. I'm assuming the upgrade will be transparent to me, correct?
That is correct.

The CNC uses mod_auth style password protection, which stores the password hashes(*) in a plain text format. This will not be affected by the upgrade and neither will site owners using DB style password hashes, where the passwords are stored in a DB format.

(*) A hash function is a computation that takes a variable-size input and returns a fixed-size string, which is called the hash value. When used for authentication purposes a one-way function is used where it's easy to calculate the hash value from a password, but very hard/nearly impossible to get the password back from the hash value.

Arthur
Arthur is offline  
Old 08-01-2003, 01:33 PM   Postid: 92920
 Terra
CTO FutureQuest, Inc.
 
Terra's Avatar
 
Join Date: Jun 1998
Location: Z'ha'dum
Posts: 7,678
Please view edits in original post for a last minute addition to PHP...

--
Terra
sysAdmin
FutureQuest
Terra is offline  
Old 08-01-2003, 03:40 PM   Postid: 92926
GSK8
Registered User

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Oct 2001
Posts: 160
Where exactly? <wincing....>
GSK8 is offline  


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:45 PM.


Running on vBulletin®
Copyright © 2000 - 2013, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2013 FutureQuest, Inc.
FutureQuest, Inc.