{"id":627,"date":"2013-09-19T15:09:29","date_gmt":"2013-09-19T19:09:29","guid":{"rendered":"http:\/\/blog.uvm.edu\/ctl-projects\/?p=627"},"modified":"2013-09-19T15:09:29","modified_gmt":"2013-09-19T19:09:29","slug":"various-and-sundry-landscape-issues","status":"publish","type":"post","link":"https:\/\/blog.uvm.edu\/waw\/2013\/09\/19\/various-and-sundry-landscape-issues\/","title":{"rendered":"Various and sundry Landscape issues"},"content":{"rendered":"<p>Immediately upon return from 6 weeks leave, I was met with this<\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>On Tue, 27 Aug 2013, Scott Dellinger wrote:<\/p>\n<p>After we started getting alerted again about webdb server load, I have spent the last several hours looking into the recurring load issues on<br \/>\nwebdb. \u00a0The issues we\u2019ve been having are due to attacks on several vulnerable PHP scripts on\u00a0<a href=\"http:\/\/www.uvm.edu\/\">www.uvm.edu<\/a>, inserting code into SQL statements\u00a0that causes them to run for very long periods of time while holding open table locks. \u00a0This is being done by calling the BENCHMARK()\u00a0function,\u00a0which makes code run repeatedly, in combination with SLEEP(). \u00a0We have seen this type of attack before, but it\u2019s been a while.<\/p><\/blockquote>\n<p>Specifically, http:\/\/www.uvm.edu\/landscape and http:\/\/www.uvm.edu\/~geomorph<\/p>\n<p>Since they shared code base, I only had to fix the one and copy-paste to the other; nonetheless, some aspects were non-trivial. Ultimately, I prevailed.<\/p>\n<p>Soon after, however, I heard<\/p>\n<blockquote><p>Looks like the back door you gave us for use by our publisher&#8217;s been shut both for them (and I just tried it, for me)<\/p>\n<p><a href=\"http:\/\/www.uvm.edu\/~geomorph\/gallery\/inventory.php\">http:\/\/www.uvm.edu\/~geomorph\/gallery\/xxxxxx.php<\/a><\/p>\n<p>Funny, the landscape back door works fine\u2026<\/p>\n<p>In fact, I can&#8217;t get into the gallery at all from here in Paris unless I use any connect &#8211; otherwise I get a forbidden error.<\/p><\/blockquote>\n<p>The site was temporarily blocked from outside UVM access pending code fixes to address the DoS attacks. I unlocked it, and delivered a much enhanced &#8220;back door,&#8221; URL of which cannot be revealed.<\/p>\n<p>But wait &#8212; there&#8217;s more<\/p>\n<blockquote>\n<blockquote><p>From: Steve Bergeron &lt;<a href=\"mailto:steve.bergeron1@gmail.com\">steve.bergeron1@gmail.com<\/a>&gt;<br \/>\nSubject: Re: Landscape Change Comment<br \/>\nDate: September 5, 2013 7:32:24 PM EDT<br \/>\nTo: Paul Bierman &lt;<a href=\"mailto:paul.bierman@uvm.edu\">paul.bierman@uvm.edu<\/a>&gt;<\/p>\n<p>Paul,<br \/>\nI know that you personally may not be able to address this concern, but I am trying to upload a reshot image for LS69689. \u00a0When I enter the photo number that I want to submit a reshoot for, I get this generic looking screen (the error on the top may have something to do with the problem)<\/p><\/blockquote>\n<\/blockquote>\n<p>Variety of\u00a0Bugs introduced in latest bug fix (denial of service stuff). Squashed.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Immediately upon return from 6 weeks leave, I was met with this &nbsp; On Tue, 27 Aug 2013, Scott Dellinger wrote: After we started getting alerted again about webdb server load, I have spent the last several hours looking into &hellip; <a href=\"https:\/\/blog.uvm.edu\/waw\/2013\/09\/19\/various-and-sundry-landscape-issues\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-627","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/posts\/627","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/comments?post=627"}],"version-history":[{"count":0,"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/posts\/627\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/media?parent=627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/categories?post=627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.uvm.edu\/waw\/wp-json\/wp\/v2\/tags?post=627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}