Welcome to my simple place online.


The Home page has been viewed 15,444 times.
We received a total of
page views since
December 27, 2015

Re: the large internet outage
Posted by: MGCJerry on Oct 22, 2016 @ 21:32 EDT
Last Edited: Never
Keep creating useless devices with internet access with little to no security and do not need to be on the internet and this will continue.

The internet is NOT a public utility that everyone can "just enjoy". Its a somewhat decentralized, highly technical system with severe flaws that cant cause major damage when a technical individual decides to do something malicious. It is a system that a non technical person should be using willy nilly without some technical experience or education.

Do you have an internet connected device AND an enforced device security policy AND an enforced network use policy? No? You are part of the problem.

• Restrict what can run on your device.
• Restrict what can communicate on the internet.
• Restrict devices that don't *need* to be on the internet. A refrigerator runs fine without an internet connection.
• Employ a self-enforced policy of thinking before doing.
• Educate yourself about the internet. The landscape changes daily, adapt as needed.
• Do not depend on the system to operate your life. the internet is not "always on". There are always pockets of it that are down.

And people thought I was "extreme" on how I handle my computers and what applications and sites I use.
Comments are disabled for this story

My main site
Posted by: MGCJerry on Aug 28, 2016 @ 11:43 EDT
Last Edited: Sep 18, 2016 @ 11:52 EDT

For those coming over to "follow me" from Facebook... I will be hanging out here so I don't have to deal with Facebook. why? Oh let me count the ways.

1. Less of a mangled mess.
2. Facebook's scripting makes it very heavy and cumbersome to use, especially on a mobile device.
3. Got more control over my own information.
4. No nagging. I hate few things worse than a program or place that feels its need to nag me.
5. I can pretty much say what I want here, if you don't like it, then go pound sand. Complaining to an admin will not solve anything. I AM the admin.
6. Spam is not tolerated here. I gave up reporting blatant violations to Facebook only to get told "nothing is wrong".
7. Porn is not tolerated here. See #6.
8. No sudden random changes here that breaks things.
9. I can actually upload stuff here. 100% of the time, compared to some of the time on Facebook.

Do I plan on replacing Facebook? For my use, yes. For you, its not planned. This current site does not have any registration system at this time. However, I am still working on a huge update to the system that will allow you all to register so you can like/dislike & comment on my posts as well as other people's posts. That update will come soon enough I hope. Other than that, Welcome to my place. Its been here awhile.

Comments are disabled for this story

Current Events - Behind the scenes of index.php
Posted by: MGCJerry on Apr 23, 2016 @ 19:58 EDT
Last Edited: Never
downvote story upvote story Score: 1.00
2 people like this story! 1 people hate this story.

I had originally posted this on my other site, but now this one is getting it bad now too.

Lately I've been seeing a lot of people trying to load /etc/passwd using this CMS. Sorry my friends, the $_GET[page] request URI doesn't work like this. index.php?page=../../../../../../../../../../../../../../../../../etc/passwd

This CMS code does NOT work like this:

Here is how this CMS loads pages in a step by step...
First off, $_GET & $_POST are NOT used directly.
1. Bans are checked against the list. If your IP is found in the block list, all you get is a banned page and the script exits.
2. Rogue Admin rules (which are set by admins) are checked. I have "../" as a rule that triggers a ban. As well as "http://" or even "ftp://". If Rogue Admin finds these - anywhere, it carries out the action that is configured for that rule and ALL site variables are set to false. Since remote requests are not utilized, I have bans setup for them. This CMS cannot load remote resources anyhow- By design.
3. "api.sanitation" Removes all non-text characters for $_GET['page'] (quotes, slashes, dots, punctuation, etc) Note: "api.sanitation" is the only place where $_GET and $_POST are used. All variables get a first sanitation pass and creates a new global. This global is used exclusively in the CMS. If nothing is left after sanitation, the variables are unset entirely. The result is this will show you the home page.
4. After sanitation, "header.php" fetches the current list of all pages (The menus stem from this output). If you are requesting a specific page and the page exists in the list AND is enabled, AND you have permission to see it, the "header.php" will tell "index.php" what page to load from the database. If the page doesnt exist in the page list, you will get a 404 error page. If you are not allowed to see the page you get a 403 error.

Your URI actually NEVER sees the database, or is ever used in a database query. It is compared to a current list of pages, and the script will build its query from its own results, never yours. Even if I deleted the http & ftp rules, there is an include restriction built into modules system where it will once again only load a local file if it is present in its own list AND in a specific location. Else all you get is a 404, and I get am includes error report.

Hope you enjoyed this look behind the scenes. Remember, reading is your friend. You don't want to look like a dingus because you didn't read the documents its bad for your image.

Oh, this is also NOT Joomla, PHPNuke (or any clone), or Wordpress so those administration or rpc pages do NOT exist. Period

Comments are disabled for this story

Public Ban List
Posted by: MGCJerry on Mar 30, 2016 @ 16:14 EDT
Last Edited: Never

After some thought, all my sites will now share a ban list. I will periodically merge the bans from all my sites and apply them to each site.

Comments are disabled for this story

Mini Rant - Spamming
Posted by: MGCJerry on Feb 20, 2016 @ 17:02 EST
Last Edited: Never
downvote story upvote story Score: -1.00
4 people like this story! 5 people hate this story.

Just a minor rant based on the status of my 3 main sites.

It seems a few sites are on a hell of a spamming spree over the last few months now that I have more complete logging abilities. These sites are of questionable purposes. They don't work at all with Noscript and there is NO WAY IN HELL I will see what they do without any kind of protection.

I won't call them a SCAM because I haven't used their product or services but buyer beware when dealing with these domains!. My trust meter on these sites registers a big, fat ZERO.

Anyone who possesses these referers in their browser or attempts to contact form spam will be automatically banned. Typically the system is slightly more lenient but for these 3 sites, the system is much more aggressive. These bans will not be overturned. Excessive bans from a particular IP address allocation will result in that entire block being banned server-side. A few blocks are already close to being server banned.

Comments are disabled for this story

21 Total (5 Pages, 5 per page)

1 2 3 4 5 ... Next Last

[ Home | MX12 Lumamod | Kerbal Names | Contact Me | Poser 6 | Carrara 6 | Video Conversion | Site Map ]
[ ISO8859-1 Table | Public Ban List ]

This page was generated in 0.00683 seconds using 16 queries.
This page consumed 1.34 MB of memory during its creation.

MGCMS Programming by MGCJerry
Copyright © 2007-2012, 2014, 2015, 2016