WordPress.org

Ready to get started?Download WordPress

Forums

BulletProof Security
[resolved] Forbidden Message (19 posts)

  1. pmuktan
    Member
    Posted 9 months ago #

    You don't have permission to access/wp-content/plugins/mingle-forum/wpf-insert.php on this server.

    As i have denied all files/folder in .htaccess, i couldn't access this plugins.
    How can i give access to only this /mingle-forum/ directory ?

    Thanks.

    http://wordpress.org/plugins/bulletproof-security/

  2. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    How have you denied all files/folder in .htaccess? Post the code you used.

  3. pmuktan
    Member
    Posted 9 months ago #

    Thank you for prompt reply.
    I have two .htaccess file.
    One under the root file which bulletSecurity created.

    And another under /content/wp-content/.htaccess
    <Files *.php>
    Deny from all
    </Files>

    And i do alos have robot.txt file where these text are included.
    # global
    User-agent: *
    Disallow: /cgi-bin/
    Disallow: /wp-admin/
    Disallow: /wp-includes/
    Disallow: /wp-content/cache/
    Disallow: /wp-content/themes/
    Disallow: /wp-content/plugins/
    Disallow: */trackback/
    Disallow: /feed/
    Disallow: /comments/
    Disallow: /category/*/*
    Disallow: */trackback/
    Disallow: */feed/
    Disallow: */comments/
    Disallow: /*/feed/rss/$

    Thank You...

  4. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    You could try something like this.

    SetEnvIf Request_URI "/some-plugin-folder/(.*).php$" whitelist
    
    <FilesMatch "\.(php|phps|php5|php4|php3)$">
    Order Allow,Deny
    Allow from env=whitelist
    </FilesMatch>
  5. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    I checked your other posts and see that your website is being hacked repeatedly. The problem is the Mingle Forum plugin itself. It is pending a security fix. You might want to you use another Forum plugin like BuddyPress instead.

    http://wordpress.org/support/topic/what-happened-to-mingle-forum?replies=3

  6. pmuktan
    Member
    Posted 9 months ago #

    @AIT PRO
    Thank you for your support.
    So you mean mingle forum has vulnerabilities ?
    So when using buddyPress how will i edit the .htaccess file.

    Should i have to give allow access to this plugin ?

    Regards
    Pmuktan

  7. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    The Mingle Forum plugin has been removed from wordpress.org for download, but the plugin support forum is still available. The link I posted above goes to another link that states that this plugin has had a known security vulnerability since April 2013. I really don't know anything else, but I assume that WordPress has removed the plugin because it has a known security vulnerability that has not been fixed yet.

    If you remove the Mingle Forum plugin and install BuddyPress then you would use BPS just like you would normally without doing anything else. If you are asking about how to customize your additional .htaccess file then you would follow the example code I posted above...

    But here is what I think really needs to happen. Read this WordPress Codex link about what to do if your site is already hacked.
    http://codex.wordpress.org/FAQ_My_site_was_hacked

  8. pmuktan
    Member
    Posted 9 months ago #

    I installed buddyPress but it say you need to activate buddypress theme.

    I want my theme as it is but want to use only forum as i am doing with mingle forum.

    When using mingle forum, i just used [migleforum] and the page got automatically activate.

    How can we do for buddy press.??

  9. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    I believe you can use any Theme, but I am not a BuddyPress expert. You would need to ask the BuddyPress folks about that to get 100% confirmation. You can make the BuddyPress Theme notice go away by doing what is in the link below.

    http://premium.wpmudev.org/blog/daily-tip-silence-the-buddypress-is-ready-message-in-the-wordpress-dashboard/

  10. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    Before doing anything else you should restore your website from a good backup that you know is 100% clean/not hacked. If you do not have a good backup then see the link below.
    http://codex.wordpress.org/FAQ_My_site_was_hacked

    If your site is hacked then the chances that there are still hidden backdoor hacker files somewhere on your site is 100%. Not 99% => 100%. Your site will continue to be hacked over and over until you restore it from a good backup or follow the instructions in the link above.

  11. pmuktan
    Member
    Posted 9 months ago #

    I installed buddypress but how can i start my own forum and all??

  12. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    Here is the Getting Started page
    http://codex.buddypress.org/getting-started/

    Here is the main BuddyPress Support page
    https://buddypress.org/support/

  13. pmuktan
    Member
    Posted 9 months ago #

    As you know i had security issues mingle forum, now i am installing buddypress forum in my website.
    But the concern is How can i transfer all data such as topics and replies from mingle forum to buddypress forum.

    Is it possible to do that ?

    Your help is really appreciated.

    Regards
    Pmuktan

  14. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    Yes, it is always possible to import data, but the real question is has someone already created an importer for Mingle to BuddyPress. It looks like bbPress has done this, but it looks like manual DB work is required. Can't really offer much else in suggestions since these are not my areas of expertise or my plugins. ;)

    http://codex.bbpress.org/import-forums/

  15. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    [deleted] horrible suggestion. ;)

  16. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    I deleted my previous post since it was a horrible suggestion. I looked up the history of the Mingle Forum plugin and it is not good (that is being very kind). It is better to move forward and go with a solid/excellent (probably the best Forum plugin) BuddyPress.

  17. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    I am not sure if the Import Forums tool is already included in BuddyPress. Go to your WordPress Tools menu and see if the Forums menu link is already there. If it is then you should be able to import Mingle into BuddyPress. If not then you will need to install bbPress to get the Import Forums tool. This link below shows a screenshot of the Import Forums tool.

    http://css-tricks.com/the-move-to-bbpress/

  18. AITpro
    Member
    Plugin Author

    Posted 9 months ago #

    Resolving.

  19. pmuktan
    Member
    Posted 9 months ago #

    @AIT Pro
    Thank you for your support.
    Yes there is forum menu under tools options
    I used import tab and choosed mingle forum for paltform
    What are Database Server, and rest of the things.

    Regards

Reply

You must log in to post.

About this Plugin

About this Topic

Tags

No tags yet.