We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28439
    • 222 Posts
    This is an auto-generated topic for PHP-IDS 0.6.4c-Released by Stefanie.

    Brief Description:
    Solved an error in class.module.phpids.php with a wrong column name in a SQL statment

    This new release is based on the current version of PHPIDS 0.6.4 and corrects some bugs.
    In addition the following changes have been done:
    You don't need to download PHPIDS, it is no included in the package.
    A new Module:

    • The configuration is now done with the module and shared with the plugin
    • Here you can see the intrusions in a sortable table
    • Blocked IP addresses can also be ranges, for example 192.168.
    • Blocked IP addresses are listed in a tab, they can be removed from the blocked list

    Plugin changes

    • The plugin gets the configuration from the module
    • IP addresses can be used to block users and send them to a document, for example you create a static HTML document and add this to your MODx installation
    • Intrusions beginning from a given level, default is 50, are blocked and can be send to a document

    The module chooses its language by the language of the current user of MODx, if that language is not supported, English is used instead.
    The project is now hosted on google code: phpids-for-modx
      Gone away and found a better place to stay
      • 26931
      • 2,314 Posts
      Hi Stefanie,

      thanks for this great Module/Plugin!

      apparently assets/lib/phpids/lib/IDS/tmp needs to be writeable, right?
      Does the Module itself has an interface? because when i click on PHPIDS in the Module Tab i got a white screen, but i’m able to configure it via "Manage Modules"

      MODx 1.0.4 / PHP 5.2.12 / Database Version 5.1.47-1~bpo50+1-log

      oh, and i already get reports shocked "HPIDS Plugin detected an intrusion attempt!" Impact: 22 ...so i block this IP via .HTACCESS ?

      in my e-mail: IP: 188.11.11.111
      -> .HTACCESS
      order allow,deny
      deny from 188.11.11.111
      allow from all


      grin grin LOL ... just blocked myself

      *edit: the code for the plugin & the module is the same? -> plugin.phpids.inc.php.tpl
      btw. the installation is in a subfolder
        • 26931
        • 2,314 Posts
        okay, got it smiley

        Open the file assets/plugins/phpids/plugin.phpids.inc.php.tpl and copy the content.
        Go to your MODx backend, click on the tab "Modules" -> "Manage Modules" -> New Module".
        Name the module PHPIDS and paste the copied code into "Module code (php)".
        -> should be assets/modules/phpids/module.phpids.php.tpl
          • 28439
          • 222 Posts
          Hi sharkbait,

          Thanks for the correction about the path to module.phpids.php.tpl, I changed the installation instructions.

          The configuration is done on "Manage Modules" -> PHPIDS -> tab "Configuration".

          There are two ways of block IPs, one is manually with the .htaccess file in the root of the MODx installation, the other is with the module of PHPIDS. The module does not change the .htaccess file,, but it does a redirection to a document ID.
          For example you create a static HTML file and add this file to MODx. In the module configuration just change the fields "ID of the MODx document, where blocked IPs are send to" and "Redircet intrusion to the document ID (0 means no redirection)" and insert the document ID of that static HTML, then PHPIDS redirects blocked IPs or intrusion beginning from the level defined in "Redirect intrusions from a level (50 is hight)" to that static HTML file.

            Gone away and found a better place to stay
            • 26931
            • 2,314 Posts
            Thanks Stefanie!

            For example you create a static HTML file and add this file to MODx. In the module configuration just change the fields "ID of the MODx document, where blocked IPs are send to"
            with "static HTML" file you mean a MODx resource? (because you mentioned their ID)

            and in the configuration: "Exceptions separated with pipes (|)" is this meant for a list of IPs?
            i just entered mine (the one i blocked before), but i still get notified when i log in the manager

            one more question ... can i empty the Logs from within the module?

            :) again ... thanks, very nice tool! j
              • 28439
              • 222 Posts
              From the configuration file of PHPIDS:
              ; define which fields shouldn’t be monitored (a[b]=c should be referenced via a.b)

              exceptions[] = GET.__utmz

              exceptions[] = GET.__utmc


              ; you can use regular expressions for wildcard exceptions - example: /.*foo/i


              This configuration is not done with the that file, it is done by the module itself. Hope, that helps to understand. Regular expression are new in version 0.6.4, see http://php-ids.org/2010/06/06/phpids-0-6-4-is-ready/ for further informations.

              Currently you can’t empty the log from the module, but I put it on the to-do list for the next version, thanks for the request.
                Gone away and found a better place to stay
                • 26931
                • 2,314 Posts
                sorry for all those questions smiley not sure i understand 100% .. e.g. i also get notified when i browse my site. this is in the report:
                Impact: 22 
                Affected tags: xss csrf id rfe lfi 
                Affected parameters: 
                REQUEST.__utmz=80559117.1280754941.933.91.utmcsr%3Dmodxcms.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D%2Fforums%2Findex.php%2Ftopic%2C52389.0%2Ftopicseen.html,
                COOKIE.__utmz=80559117.1280754941.933.91.utmcsr%3Dmodxcms.com%7Cutmccn%3D%28referral%29%7Cutmcmd%3Dreferral%7Cutmcct%3D%2Fforums%2Findex.php%2Ftopic%2C52389.0%2Ftopicseen.html, 


                any ideas?

                thanks, j
                  • 28439
                  • 222 Posts
                  How should PHPIDS know, that it is you?

                  OK, I can add an exception, that the plugin doesn’t track intrusions, if the user is logged in at MODx backend. But by doing it this way, there has also to be implemented a debug mode, because otherwise you can’t test PHPIDS.

                  For additional informations about PHPIDS take a look at http://php-ids.org/faq/ and http://www.h-online.com/security/Getting-started-with-the-PHPIDS-intrusion-detection-system--/features/113163. Questions about PHPIDS should be posted at the PHPIDS forums at Discussions, if one doesn’t find the appropriate in their forums.
                    Gone away and found a better place to stay