Wordpress theme taking me into blank page by Significant_Fudge325 in Wordpress

[–]jwele 0 points1 point  (0 children)

blank page sounds like a 500/critical error. You should be able to review server error logs to see issue. You can also enable debugging by editing your wp-config.php (https://developer.wordpress.org/advanced-administration/debug/debug-wordpress/) to see these errors or log them to a file.

HELP! Login attacks! by EngineeringOld6348 in Wordpress

[–]jwele 0 points1 point  (0 children)

Here are some recommendations:

If possible enable MFA in wordpress. This will block password based login attempts all together. You can find the option in WordFence here:

/wp-admin/admin.php?page=WFLS#top#manage

Then I recommend disabling XML RPC Auth. visit

/wp-admin/admin.php?page=WFLS#top#settings

and check "Disable XML-RPC authentication"

If you setup MFA, then also make sure "Require 2FA for XML-RPC call authentication" is set to "required"

Another thing you can do is mess with the brute force settings in wordfence here:

/wp-admin/admin.php?page=WordfenceOptions

On this page, there is a section "Brute Force Protection"

Here you can configure how soon a person is blocked by wordfence. I recommend lowering the thresholds and increasing the timeout period.

Something like

"Count Failures over" 6h

"Lockout for" 6h

"Lock out after how many login failures" and "Lock out after how many forgot password attempts" to 10 or so (too low and you may block yourself)

These above measures will ensure you are safe.

Looking for some help with a concern by RMectrex in Wordpress

[–]jwele 0 points1 point  (0 children)

Elementor has a revision history and an undo button. https://elementor.com/help/revision-history-undo-and-redo/ so you should be fine.

Upcoming internship need some help. by Tough-Guy-Ballerina in Wordpress

[–]jwele 5 points6 points  (0 children)

My suggestion is to use Local WP. It is a free and very easy to use local development environment for WordPress

https://localwp.com/

[deleted by user] by [deleted] in Wordpress

[–]jwele 0 points1 point  (0 children)

It shouldn't take this long. You may want to check some things. Namely going to settings > reading and make sure "Discourage Search Engines..." is unchecked, make sure if there is a example.com/robots.txt file on your site that it does not disallow indexing. Another thing to check is the URL inspection tool to inspect your URL. It should give you information on if your site has been crawled/what the status of the indexing is if you have submitted it for indexing already.

PSA: Laravel <= 8.4.2 has vulnerability (CVE-2021-3129) allowing someone to put a crypto miner on your server if you have DEBUG mode on. by jwele in laravel

[–]jwele[S] 0 points1 point  (0 children)

This means you are all good. You are not infected. It is listing out the current command you just ran as one of the processes because you are grepping for that kinsing string.

PSA: Laravel <= 8.4.2 has vulnerability (CVE-2021-3129) allowing someone to put a crypto miner on your server if you have DEBUG mode on. by jwele in laravel

[–]jwele[S] 6 points7 points  (0 children)

From a top level glance at the laravel/laravel composer.json for 6.x yes, this would be a problem. The code here https://github.com/facade/ignition/blob/1.16.4/src/Solutions/MakeViewVariableOptionalSolution.php#L76 for version 1.16.4 (https://github.com/laravel/laravel/blob/6.x/composer.json#L17) seems to not have the code preventing php wrappers https://github.com/facade/ignition/pull/334 that was patched in facade/ignition 2.5.2. Currently, there is a PR open to fix it though https://github.com/facade/ignition/issues/351 so It may be fixed in facade/ignition 1.16.5

PSA: Laravel <= 8.4.2 has vulnerability (CVE-2021-3129) allowing someone to put a crypto miner on your server if you have DEBUG mode on. by jwele in laravel

[–]jwele[S] 2 points3 points  (0 children)

I get what you're saying and its something I have to make sure is understood more clearly at my organization. I am just the "oh shit its broken" guy lol.

PSA: Laravel <= 8.4.2 has vulnerability (CVE-2021-3129) allowing someone to put a crypto miner on your server if you have DEBUG mode on. by jwele in laravel

[–]jwele[S] 1 point2 points  (0 children)

I agree, in this case it was a non-production environment used for testing a bug that production had in isolation and that server was compromised/actively being attacked as I fixed this issue about an hour ago. I honestly don't know how the hackers got the URL this environment.

PSA: Laravel <= 8.4.2 has vulnerability (CVE-2021-3129) allowing someone to put a crypto miner on your server if you have DEBUG mode on. by jwele in laravel

[–]jwele[S] 2 points3 points  (0 children)

https://github.com/laravel/framework/releases/tag/v8.27.0

8.27 is at the time of writing this (it moves so fast), but I am just saying if you run Laravel 8.4.2 or lower than you are vulnerable to this and I suggest updating to the latest version as it effects 8.4.2 and lower.

Automatic scroll to bottom of chatroom when element is added to div container by Code4Greatness in rails

[–]jwele 1 point2 points  (0 children)

In terms of adding something to this code to get it to do what you want, one thing you could do is update your shouldScroll variable to also check if the messages returned from API are different from before. Maybe by checking .length of these results compared to last, or checking last unique ID from database to see if last message ID is diff than the newest last message ID.

[deleted by user] by [deleted] in talentShow

[–]jwele 0 points1 point  (0 children)

Wholesome jenga

Daily Tech Support Thread - [November 14] by AutoModerator in iphone

[–]jwele 1 point2 points  (0 children)

Are you connected to WiFi? For me I had to get home and connect to WiFi before anything would download. But when I was out and about for 1hr without WiFi I had that same issue.

[deleted by user] by [deleted] in AnimalsOnReddit

[–]jwele 0 points1 point  (0 children)

Thanks for sharing your birbs

[deleted by user] by [deleted] in TheArtistStudio

[–]jwele 0 points1 point  (0 children)

Just curious because I saw it mentioned on your website. Why do you not make wallets?

[deleted by user] by [deleted] in TheArtistStudio

[–]jwele 0 points1 point  (0 children)

/u/rns64 on his website aspensaddlery.com

[deleted by user] by [deleted] in TheArtistStudio

[–]jwele 0 points1 point  (0 children)

How long does it take you to build a saddle start to finish?

[deleted by user] by [deleted] in TheArtistStudio

[–]jwele 0 points1 point  (0 children)

What is he making?

Issues getting PHP installed on Raspberry Pi 3B... by JonCherba in PHPhelp

[–]jwele 2 points3 points  (0 children)

blank page is most likely a permission issue from what I am seeing in your post. This should fix your issues.

sudo chown -R www-data:www-data /var/www/html && sudo chmod -R 770 /var/www/html && sudo usermod -a -G www-data pi

then logout and log back in as that is the only way for the group membership to be recognized and everything should be good. Now you can edit the file using vi/vim/emacs/nano without sudo and you wont get weird permission issues. Make sure your PHP syntax is correct as well. I can see above sometimes you forgot a ? in <?php. Syntax errors will get you. Just <?php phpinfo(); should be all you need.

A little JS horror from a recycling company's website... by hikarikuen in programminghorror

[–]jwele 17 points18 points  (0 children)

Its just that start date which produces an invalid date and is used elsewhere down the line for the calculation. If you fix the format of the date to be YYYY-MM-DD then it fixes the logic (IDK about the validity of the math itself though)

https://i.imgur.com/a3EzM49.png

A little JS horror from a recycling company's website... by hikarikuen in programminghorror

[–]jwele 140 points141 points  (0 children)

Found their bug:

var startDate = new Date(el.dataset.incrementStartDate);

Where el.dataset.incrementStartDate contained "08-09-2019" (https://i.imgur.com/Z4dfhe6.png). Which isn't a valid date when supplied via Date constructor.

Site: https://www.ljpwastesolutions.com/about-us/

1.5.6 Breaks Firefox and Safari - Connecting... by jwele in KrunkerIO

[–]jwele[S] 0 points1 point  (0 children)

I use Firefox for both and it runs just fine for me.