Wednesday, June 20, 2012

Make your joomla site secure

1. Change the default database prefix (jos_)
2. Remove version number / name of extensions
3. Use a SEF(Search Engine Friendly) component
4. Keep Joomla! and extensions up to date
5. Use the correct CHMOD for each folder and file. This cofiguration should be used:
  •  PHP files: 644
  •  Config files: 666
  •  Other folders: 755
6. Delete leftover files:
                  When you installed an extension that you didn't like, don't set the extension to unbublished. If you do, the vulnerable files will still be on your website. So simply use the un-install function to totally get rid of the extension.
7. Change your .htaccess file
                 Add the following lines to your .htaccess file to block out some common exploits.
                  
########## Begin - Rewrite rules to block out some common exploits
#
# Block out any script trying to set a mosConfig value through the URL
RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|%3D) [OR]
# Block out any script trying to base64_encode crap to send via URL
RewriteCond %{QUERY_STRING} base64_encode.*(.*) [OR]
# Block out any script that includes a < script> tag in URL
RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL
RewriteCond %{QUERY_STRING} GLOBALS(=|[|%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL
RewriteCond %{QUERY_STRING} _REQUEST(=|[|%[0-9A-Z]{0,2}) [OR]
# Block out any script that tries to set CONFIG_EXT (com_extcal2 issue)
RewriteCond %{QUERY_STRING} CONFIG_EXT([|%20|%5B).*= [NC,OR]
# Block out any script that tries to set sbp or sb_authorname via URL (simpleboard)
RewriteCond %{QUERY_STRING} sbp(=|%20|%3D) [OR]
RewriteCond %{QUERY_STRING} sb_authorname(=|%20|%3D)
# Send all blocked request to homepage with 403 Forbidden error!
RewriteRule ^(.*)$ index.php [F,L]
#
########## End - Rewrite rules to block out some common exploits







Sunday, June 17, 2012

Remove windows Genuine Notification?


Official Method by Microsoft 
  1. Lauch Windows Task Manager.
  2. End wgatray.exe process in Task Manager.
  3. Restart Windows XP in Safe Mode.
  4. Delete WgaTray.exe from c:\Windows\System32.
  5. Delete WgaTray.exe from c:\Windows\System32\dllcache.
  6. Lauch RegEdit.
  7. Browse to the following location:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
    Windows NT\CurrentVersion\Winlogon\Notify
  8. Delete the folder ‘WgaLogon’ and all its contents
  9. Reboot Windows XP.

After you followed the process given above. Do following things
Go to Control Panel > Security Center > Automatic Update Settings.

Select the third option - “Notify me but don’t automatically download or install them”.

Click OK.

The next time the “Windows Updates” icon appears in the system tray, click on the icon and it will display a list of available updates (Windows won’t automatically download and install them anymore).

If “Windows Genuine Advantage Notification Tool” is there, uncheck it and press enter to download everything else (if you want to). You can right-click to “hide updates” that you don’t want.

Select “Don’t notify me about these updates again”, so that they will be ignored every time updates are downloaded.

Just remember, from now on, make sure to check the list of downloads so that you don’t install any new versions of this “tool”.

Next simple method is download Remove WGA. Run the application after restarting ur computer u'll find the notification been removed.

How to enable run in start in XP?

Just a few step & you can see Run in your start. First right click start and go to properties. On properties go to start menu tab then right side you'll see customize button go to advanced tab. There you can see start menu items lists. Scroll down you see Run command. Check it and click ok & then apply. Now you can see run command at your start.