Jump to content
xisto Community

BuffaloHelp

Members
  • Content Count

    6,342
  • Joined

  • Last visited

  • Days Won

    9

Posts posted by BuffaloHelp


  1. Email can be fooled to "look alike" it was sent from the source claimed to be by manipulating mail headers. In PHP this is achieved simply by:

     

    <?php
    $to      = 'nobody@example.com';
    $subject = 'the subject';
    $message = 'hello';
    $headers = 'From: webmaster@example.com' . "\r\n" .
       'Reply-To: webmaster@example.com' . "\r\n" .
       'X-Mailer: PHP/' . phpversion();
    
    mail($to, $subject, $message, $headers);
    ?>
    

     

    What it cannot fool is the "Received" portion of the full header. In Yahoo and Gmail you can see the full header by click on "show full header" or "show original," respectively.

     

    In the full header contains many information but it cannot disguise the originated IP address (in bold) such as:

     

    Delivered-To: no-reply@xisto.com

    Received: by 10.229.99.193 with SMTP id v1cs216067qcn;

    Wed, 23 Jun 2010 02:15:16 -0700 (PDT)

    Received: by 10.229.224.81 with SMTP id in17mr4025083qcb.252.1277284515492;

    Wed, 23 Jun 2010 02:15:15 -0700 (PDT)

    Return-Path: <root@******.xisto.com>

    Received: from ******.xisto.com (******.xisto.com [00.00.00.00])

    by mx.google.com with ESMTP id v30si11598770qco.96.2010.06.23.02.15.15;

    Wed, 23 Jun 2010 02:15:15 -0700 (PDT)

    Received-SPF: pass (google.com: best guess record for domain of root@******.xisto.com designates **00.00.00.00** as permitted sender) client-ip=00.00.00.00;

    Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of root@******.xisto.com designates 00.00.00.00 as permitted sender) smtp.mail=root@******.xisto.com

    Received: from root by ******.xisto.com with local (Exim 4.69)

    (envelope-from <root@******.xisto.com>)

    id 1Orrrr39-0003kdddsscc-1n

    for **@xisto.com; Wed, 23 Jun 2010 09:15:15 +0000

    To: user <**********************@xisto.com>

    Subject: ......................................

    Date: Wed, 23 Jun 2010 09:15:15 +0000

    From: "Xisto - Web Hosting (Xisto)" <sales{at}Xisto - Web Hosting[dot]com>

    Message-ID: <13d2454bb7cc3338b50199384jq9483732@localhost.local_domain_name>

    X-Priority: 3

    MIME-Version: 1.0

    Content-Type: multipart/alternative;


    Even when originated IP can be fooled (next paragraph can explain) the SPF cannot be faked (another bold from quote above). This is another reason people register proper SPF so that their emails are not marked as spam. This is another method many popular email servers will base how to filter spam from legitimate email. When you see "this email is not from where it claims" (at least in Gmail) this is how they identify spam emails.

     

    A script can be originated from the hosting of Xisto by creating a free account under Xisto server(s) and send a quick mail script. This is why spamming accounts are quickly suspended form any of our free web hosting accounts. Since the email can be sent from the same server IP as "Xisto" it can pass for the correct IP address of Xisto mail.

     

    In any case, see the full header information and if you can forward the copy to OpaQue. He can investigate further and put a stop to spammer's phishing attempt(s).


  2. Hopefully this page could help you better:https://support.google.com/quickfixes/answer/6252374?visit_id=0-636158069932945099-2952118883&hl=en1&rd=2) You have to make your MX records to point to google apps. This is either performed through cpanel or domain control itself.2) Configure your google apps by verifying domain ownership.Any additional questions you can post them here.


  3. It doesn't sound like the faulty NIC because he said it works fine if the laptop is connected to the cable modem directly.Either your router's port is faulty or you could be using cross-over cable.Try connecting your laptop using a network cable to different port in your router. If you have been using connection #1, try connection #2 or 4. Try connecting your laptop to a different router, such as your friends or at school.If any of those above works fine, you may be looking at a faulty router.Check to see if the network cable you have been using is not cross-over cable. Look at the cable ends side by side, and count the colors in the same sequence. If they are out of order you are using cross-over cable.The proper cable color usually found in 568B:(W stands for "white")1-w.orange, 2-orange, 3-w.green, 4-blue, 5-w.blue, 6-green, 7-w.brown, 8-brownWhen you are looking at the terminated end, the plastic tab is facing down. You count the pins from left to right numbering 1 to 8. Let us know how it goes.


  4. No.But you can achieve that by using PHP code and INCLUDE command.PHP INCLUDE is a very nice function. You can include the same static HTML code to any page by simply,

    include ('file_name.ext');

    But you must use .php extension to the page being included, for example, home.php, reviews.php, etc.You can use .html or .htm and still use this PHP INCLUDE command. You will need to modify htaccess in that directory.

    RemoveHandler .html .htmAddType application/x-httpd-php .php .htm .html  

    Make this your .htaccess file and in your regular .html or .htm file insert the code

    <?php include('nav_menu.php'); ?>

    Your regular .html or .htm file can now parse PHP commands.There is another method to include within regular HTML file. That is to use OBJECT to include another .html or .htm file. But I believe this make your webpage load slower.You can also use iframe to include another page but it may not be good for certain SEO.


  5. In case you didn't already noticed, the forum was acting stranger while OpaQue was upgrading the forum to the next version. This is the price you pay for purchasing a working script that is complete new to both--the IPBoard company and OpaQue.And with this upgrade, OpaQue notified me that myCENT will be delayed. It's an unforeseen delay that we have to ask you all to wait a little longer before your myCENT is updated.If you have received an invoice please submit a ticket to Xisto - Support so that OpaQue can buy you time. Please be aware that your hosting is inconvenienced AND OpaQue is working day and night trying to resolve this. This means he is not being compensated because he is "paying" your invoices with his own funds. I just wanted you to see the both sides. Oh, by the way, I have not seen this month's invoice for my hosting accounts. I'm assuming OpaQue went ahead and took care of those. I am also assuming he did the same for you(hopefully :)).I have not being around past two weeks or so. That's true. My friend's son went through his 35th spinal fusion surgery and I drove his family to Cleveland Clinic. That's about 5 hours from where I live and I did not pack everything with me when I left. And with every surgery like this it comes with great risk and there were moments we thought we lost him. And when I returned I had to host my future in-laws while they were visiting. If you are married you know how that can be. It's nice to be back on the normal routine. Keep me informed with your forum kinks and let's iron them together.


  6. You can burn an ISO image to a disk (unpack) and then make your altercations. Once you have made your modification you can then recreate another ISO image.As far as I know, it's hard to modify few files within ISO because of checksum.


  7. I used to love using MS Outlook. But they bring more trouble than its convenience.If you have the ability, uninstall MS Outlook. Use and check your email using the web browser for now. By uninstalling Outlook you can eliminate the possibility that your Outlook is sending unauthorized email (worm). Remove or change all SMTP/POP password with your ISP (if you have one).And monitor your email activity for about 1 week or so. Oh, this also means change your Yahoo or whatever your main email account's password(s). In the mean time, you can begin to remove suspected trojan or worm in your computer. Run antispyware and antivirus in SAFE mode as well. If you don't know how to enter in SAFE mode search the web for your computer. Usually hold down the F8 button when you start your computer and you'll see startup options.Finally, if you are still unsure about the complete removal go out and purchase antispyware or antivirus. They are about $30-$40 and it may be better than going through annual service or subscription.


  8. On May 19th, OpaQue announced his plans for rewritting the myCENT code for the new forum. Unless he gets distracted with other things hopefully he should have a working script by the end of this month.He also announced that those who are having issues with your suspended hosting due to myCENT shortage, please email him directly so that he can do something about it.Log into your Billing page, submit a ticket with ATTENTION: OpaQue regarding myCENT and suspended account. Include in your support ticket that your account was suspended because myCENT was not updating.Or, use the direct email "support (AT) Xisto - Web Hosting {dot} com"


  9. Dear Xisto members,We are very and truly sorry for this inconvenience. It's been over a week, over 10 days and now we're all into 3 weeks since our forum upgrade and myCENT is not being updated for your active roles in this forum. For that, I would like to apologize on behalf of Xisto.com.I will try to get the exact date (not estimated or projected) when myCENT will be turning back on and give you an immediate update.Please stand by little bit longer and hang onto your patience little bit while. With much appreciation,Buffalo


  10. kira423,You'll need to work on a new bbcode tag to get your google chat badge to work. Because the default security for IPB3 is to disable any HTML codes in your sig. By creating a new bbcode you can bypass that security. However, I am still working on the google chat badge in case any injection can occur. Remember, by creating this bbcode it opens up for hackers to inject malicious codes.


  11. The best way to start your company, separating your money from the company's money (sole purpose of federal and state taxation) is start with D.B.A. (doing business as).It allows you to create a separate entity apart for you and removed any personal liability from getting sued or etc aside from having your company name, paid to your company name, write checks in your company's name etc.DBA is cheap to create and it is the most commonly created business entity. As low as $35 you can simply go to your town or city hall and register your business name (as long as it's not taken). Simply bring a proof of ID, proper tax ID or EIN and the correct form of payment (my city hall only accepts cash).EIN (employee identification number) is free from IRS. You can tie your personal social security number to your DBA but some people are not comfortable with writing and showing their social security number to some public officials. So you can create EIN using your social security number. EIN will be issued to you and only IRS knows the tie between two numbers. Submit your EIN when registering DBA can be reassuring your social security number does not fall into the wrong hands. EIN takes few hours/days to create (registering with IRS on line and possibly waiting to hear back from them, although I seem to remember getting mine almost immediately). So get your EIN before registering DBA.Once you've created your DBA, bring the certified DBA paper(s) to your preferred bank and create a bank account for your company. Voila, congratulations you have now created a company that can accept payments in your company's name. :)

×
×
  • Create New...

Important Information

Terms of Use | Privacy Policy | Guidelines | We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.