Tuesday, December 13, 2022

Cloudways | DigitalOcean | How To Install MySQL

Dec. 13, 2022

Here is the article. 

MySQL is an open-source database management system, commonly installed as part of the popular LAMP or LEMP stack. It implements the relational model and SQL to manage and query data. This tutorial explains how to install MySQL on your server. Choose your operating system below to get started.

  1. How to install mySQL on Ubuntu 22.04
  2. How to install mySQL on Rocky Linux 9
  3. How to install mySQL on CentOS8

How to Install PHPMyAdmin on Cloudways

Here is the article. 

Following are the steps to launch a separate PHPStack application when installing PHPMyAdmin on the current server.
Cloudways Product avatar
Written by Cloudways Product

It’s recommended to launch a separate PHPStack application for the PHPMyAdmin installation on that server.

Following are the steps required to install PHPMyAdmin:

How to Install PHPMyAdmin on Cloudways

Step #1 — Connecting to Your Application

First, connect to your PHPStack application using SSH and navigate to the public_html folder with this command. Here folder name is the name of your PHPStack application.

cd applications/foldername/public_html

Step #2 — Downloading PHPMyAdmin

Next, download the PHPMyAdmin using the following command.

Tip
Please be sure to check the PHPMyAdmin updated version name and modify the following command accordingly.

wget https://files.phpmyadmin.net/phpMyAdmin/5.2.0/phpMyAdmin-5.2.0-english.zip

Next, unzip the folder using the following command.

unzip phpMyAdmin-5.2.0-english.zip

Next, rename the PHPMyAdmin folder using the following command.

mv phpMyAdmin-5.2.0-english phpmyadmin

Now locate this folder from the browser to use PHPMyAdmin, for example, http://phpstack-123.cloudwaysapps.com/phpmyadmin.

Important

If you need to access databases on a different server using PHPMyAdmin, you must also install PHPMyAdmin on that server.



FTX

 

FTX fires founder's top deputies

FTX's new CEO John Ray is cleaning house at the top, per The Wall Street Journal. Ray, who previously oversaw Enron's bankruptcy proceedings, has fired former CEO Sam Bankman-Fried's top deputies: FTX co-founder and chief technology officer Gary Wang, engineering director Nishad Singh, and Caroline Ellison, CEO of trading arm Alameda Research. Ray criticized the "complete failure of corporate controls" at FTX and Alameda after both acknowledged that FTX lent billions of dollars in customer assets to Alameda to cover a funding hole, setting up the collapse of Sam Bankman-Fried's crypto empire.

Cloudways | Redis | Hosting plan

 Thanks for contacting Cloudways.


We do meet all the requirements and at least a 4GB server would be required to run Redis.

For pricing and plans, we have available, kindly follow the below link.

https://www.cloudways.com/en/pricing.php?ref_id=web_navbar

We provide three days of free trial in order to test our platform and services with no credit card required, so I would suggest you to signup with Cloudways and perform necessary testings.

To sign up with Cloudways, please use the link below:
https://platform.cloudways.com/signup

2022's Best WordPress Hosting Companies Compared (Manually Tested)

 

The 7 S’s of best WordPress hosting

Here are the most important traits to look for in best WordPress hosting:

Speed
Did you know that it only takes 2 seconds of loading time for your visitor to decide that they don’t want to wait any longer? Or, to put it in other terms, if your site takes more than 2 seconds to load, people will leave. Bad WordPress hosting won’t give you good results in this realm. They actually hope you’ll never find out that their platform is slow. Luckily, things like speed are easy to test, and we do just that to point you only in the direction of the best performing hosting platforms.
Security
Every year, literally millions of WordPress sites get hacked (example). If your WordPress host doesn’t care, your site can be the next victim. Good hosts have sufficient precautions and procedures set in place to avoid this kind of risk.
Scalability
What happens if one of your articles or posts goes viral and all of a sudden thousands of people go to your site to see it at the same time? Most likely your site will crash. But if your WordPress hosting setup is scalable, it will be able to handle the influx. This we’ve tested as well.
Support
In case you ever need help with anything regarding your WordPress hosting setup or even your website in general, you should be able to reach out to your hosting firm. Though, that’s not always possible in the real world. We’ve tested the support departments of many hosting companies, and simply not all of them stand up to the task. Let us show you who does.
Space
Can you have more than one website on your single hosting setup? Can you host high-quality image or video files? Well, depends on how lucky you were picking a good hosting firm.
Server location
In a nutshell, you want to be able to choose a server that’s near your target audience’s geographical location. Catering to an audience in Germany? You want a server in Germany, simple! However, not all WordPress hosting companies give you a choice.
SSL
Aka. Secure Sockets Layer or HTTPS, is a web protocol. It’s used to make sure that whatever content you’re reading on the web hasn’t been interfered with. In other words, if your site doesn’t have SSL enabled, your visitors might have second thoughts about interacting with it. What’s more, Google now actively discourages people from even visiting websites without SSL. A good host will let you enable SSL on your WordPress website.
  1. SiteGuard
  2. Bluehost
  3. IONOS
  4. WP Engine
  5. DreamHost
  6. Flywheel
  7. Kinsta
  8. InMotion
  9. A2 Hosting
  10. Hostinger
  11. HostGator

Monday, December 12, 2022

Binance CEO slams ‘liar’ Sam Bankman-Fried over crypto bust: ‘A bad player’

CEO accused of being instigator of FTX collapse: Bankman-Fried ‘definitely’ lied

Here is the link. 

Binance CEO Changpeng 'CZ' Zhao discusses the latest fallout from the FTX collapse and how that is expected to impact his company’s operation on ‘Varney & Co.’  #foxbusiness



小摩多头再次警告:美股近期有下跌风险

 华尔街最坚定的多头之一、摩根大通(134.21,2.05,1.55%)全球市场首席策略师科拉诺维奇(MarkoKolanovic)周一在给客户的一份报告中重申,他认为从现在到明年第一季度末,股市将面临下行风险,该行由于2023年经济前景疲软而减少了建议的股票配置。


科拉诺维奇领导的策略师团队表示,摩根大通目前将其对股票的评级从“增持”下调为“适度减持”,并正在削减大宗商品的风险敞口,同时增加公司债券和现金的配置。

在今年早些时候的市场抛售中,科拉诺维奇是华尔街最乐观的人之一,后来他改变了自己的观点。他周一重申了他的预测,即标普500指数将在2023年初重新测试之前的低点,因为金融状况继续收紧,货币政策变得更加严格,“而经济进入温和衰退”。

科拉诺维奇和他的团队写道:“我们的观点是,由于央行过度紧缩,市场和经济疲软可能在2023年出现,首先是欧洲,明年晚些时候美国也将紧随其后。”

他预计,2023年下半年,市场可能会将注意力转向更好的经济前景和企业基本面,并以高于目前的水平进行交易。

科拉诺维奇说:“这种抛售加上反通货膨胀(disinflation)、失业率上升和企业信心下降,应该足以让美联储开始发出转向信号,随后推动资产复苏,并在2023年底前推动标普500指数升至4200点。”

不过,对于美联储是否会转向,这位策略师正在等待一系列因素的确认,这些因素包括经济恶化、失业率上升、市场波动、风险资产下降和通胀下降。

美国零售业一年被偷千亿美元

零售窃盗已成流行病?美国零售业一年被偷千亿美元

 

美国人继续花钱,看似没有受通膨打击太重,但另一个世界正在兴起。去年美国店内窃盗问题严重,甚至数度演变成街头暴力,今年更猖獗,窃盗犯罪远高于历史,《华尔街日报》称“商店行窃已成为流行病”。大型零售商损失惨重,沃尔玛 (Walmart) 执行长警告,如果行窃问题再不解决,他们只好涨价,或可能看到商店关门。


美国商店窃盗案 2019 年就开始大增,当时行窃造成总损失从前一年 500 亿美元激增至 610 亿美元。 2020 年和 2021 年初 COVID-19 封锁期间损失减少,现在零售业恢复营业,犯罪率又再次飙升。美国零售联合会最近调查发现,2021 年有组织犯罪增加 26.5%,2021 年零售商因有组织犯罪损失近 1 千亿美元。

有组织的犯罪者不只闯入沃尔玛与其他主要零售商,甚至更小的夫妻店都不放过,导致现在美国不只珠宝店以及杂货店柜台有玻璃保护,所有大卖场看似不值钱的物品如肥皂、冰淇淋、洗涤剂都上锁,增加购物者的麻烦,因必须找店员开锁,才能拿到商品。

商家已被偷到怕,沃尔玛一年商店行窃就损失 30 亿美元,沃尔玛执行长表示窃盗损失愈来愈严重,几乎到不可容忍的地步。 Target 今年商店行窃事件增约 50%,导致本财年损失超过 4 亿美元,可能到 6 亿美元。

美国最大药店连锁之一 Rite Aid 10 月表示,纽约市商店行窃导致损失比去年增加 500 万美元,有些商店因此关闭,消息一出股价当天暴跌 28%。

家得宝 (The Home Depot) 资产保护、有组织零售犯罪和中央调查团主管表示,疫情期间窃盗案下降,许多人以为情况好转,但其实变得更糟,肯定影响收益。百思买 (Best Buy) 执行长也坦言零售窃盗对收益造成压力。 11 月美国连锁超市 Wegman 也因窃盗损失,结束使用购物应用程式。

美国分析人士将犯罪归咎于法律,现在美国 38 州不将损失 1 千美元以下行窃视为重罪,2020 年全国零售联合会报告发现,提高重罪商店行窃最低限度的州,有三分之二零售商表示零售窃盗事件增加。

但也有人认为窃盗成为流行病,是时代的反映。雅虎财经主编分析认为,窃盗事件与美国社会契约正在动摇、财富不平等都有关系。类似 1930 年代公敌时代,当时银行劫匪横行,恰逢大萧条时期,穷人钱越来越少、偷窃越来越多。

美国日常生活愈来愈感受到不平等,有些地方可随意在摊位留下 5 美元,拿走一打鸡蛋,但其他地方需要找店员才能解锁一瓶 5 美元的清洁剂,与当今美国许多事一样,都是因分配不均。

未来随着美国鸦片类药物危机、员工短缺及通货膨胀,偷窃只会变本加厉。全国零售联合会认为,零售商利润率通常低于 2%,当货物被偷,损失就会转嫁给顾客。

Week plan

I like to write down my plans this week. 
  1. Monday - get replaced driver license, 7:00 PM bible study - BSC, worked 6+ hours
  2. Tuesday
  3. Wednesday
  4. Thursday
  5. Friday - iRun party 6:00 PM - 9:00 PM
  6. Saturday 

Wild ride

Here is the article.

FAST MONEY

‘Wild ride’: Morgan Stanley’s Mike Wilson predicts double-digit percentage drop will hit stocks in early 2023

 Investors may be on the doorstep of a deep pullback.

Morgan Stanley’s Mike Wilson, who has an S&P 500 year-end target of 3,900 for next year, warns corporate America is getting ready to unleash downward earnings revisions that will pummel stocks.

“It’s the path. I mean nobody cares about what’s going to happen in 12 months. They need to deal with the next three to six months,” he told CNBC’s “Fast Money” on Tuesday. “That’s where we actually think there’s significant downside. So, while 3,900 sounds like a really boring six months. No... it’s going to be a wild ride.”

Wilson, who serves as the firm’s chief U.S. equity strategist and chief investment officer, believes the S&P could drop as much as 24% from Tuesday’s close in early 2023.

“You should expect an S&P between 3,000 and 3,300 some time in probably the first four months of the year,” he said. “That’s when we think the deacceleration on the revisions on the earnings side will kind of reach its crescendo.”

On Tuesday, the S&P 500 closed at 3,957.63, a 17% decline so far this year. Wilson’s year-end price target was 3,900 for this year, too.

“The bear market is not over,” he added. “We’ve got significantly lower lows if our earnings forecast is correct.”

And he believes the pain will be widespread.

“Most of the damage will happen in these bigger companies — not just tech, by the way. It could be consumer. It could be industrial,” Wilson said. “When those stocks had a tough time in October, the money went into these other areas. So, part of that rally has been driven just be repositioning from the money moving.”

Wilson’s forecast comes on the heels of prior pullback warnings on “Fast Money.” In July, he warned the June low was probably not the final move downward. On Oct. 13, the S&P 500 reached its 52-week low of 3,491.58.

‘Not a time to sell everything’

Yet Wilson does not consider himself a full-fledged bear.

“This is not a time to sell everything and run for the hills because that’s probably not until the earnings come down in January [and] February,” he said.

Wilson expects bullish tailwinds to push stocks higher over the next few weeks.

“It’s our job to call these tactical rallies. We’ve got this one right,” Wilson said. “I still think this tactical rally has legs into year end.”

Friday, December 9, 2022

Wordpress plugin: WP Data Access

 WP Data Access is a powerful data administration, publication and development tool. An intuitive interface helps to create responsive tables and charts for back-end and front-end usage in just minutes. Highly customizable CRUD pages are generated on the fly. No programming skills required.

The plugin supports more complex features for advanced users, including remote database and file access, master-detail pages, lookups, inline editing, advanced search options, dynamic hyperlinks, WordPress media library integration, WordPress role management integration and many more. Programmers can also benefit from the WP Data Access API, which can be used to access remote databases and data files directly from their PHP code.

DATA TABLES

Use the Data Publisher to create professional data tables for back-end and front-end usage.

  • Global searching and sorting
  • Many static and interactive filters
  • Many ways of styling [demo]
  • Server-side processing (default)
  • Client-side processing [demo]
  • Export to CSV, Excel, PDF and SQL, Print and Copy buttons (PREMIUM) [demo]
  • Integrated geolocation search (PREMIUM) [demo]
  • Multiple advanced search options (PREMIUM)
  • Interactive Search Builder (PREMIUM) [demo]
  • Interactive Search Panes (PREMIUM) [demo]
  • Custom queries and custom post types (PREMIUM)

DATA APPS

Use Data Projects to create data driven WordPress apps that can be executed on the back-end and front-end. Projects are highly customizable using templates.

  • Auto generated CRUD pages
  • Parent-child relationships
  • Lookups
  • Remote and local databases
  • WordPress role integration
  • WordPress media library integration
  • Accessible from the WordPress dashboard and public pages
  • DataForms – fully responsive apps for back-end and front-end (PREMIUM) [demo]
  • Inline editing (PREMIUM)
  • Full-text search (PREMIUM)
  • Multiple advanced search options (PREMIUM)

The PHP Security Checklist | sqreen | pdf file

Here is the pdf file link. 


Damn, but security is hard. 

It’s not always obvious what needs doing, and the payofs of good security are at best obscure. Who is surprised when it falls of our priority lists? 

We’d like to ofer a little help if you don’t mind. And by « help » we don’t mean « pitch you our product »—we genuinely mean it. 

Sqreen’s mission is to empower engineers to build secure web applications. We’ve put our security knowledge to work in compiling an actionable list of best practices to help you get a grip on your DevSecOps priorities. It’s all on the following pages. 

We hope your find if useful. If you do, share it with your network. And if you don’t, please take to Twitter to complain loudly—it’s the best way to get our attention.

Use Parameterized Queries To avoid SQL injection attacks, never concatenate or interpolate SQL strings with external data. Use parameterized queries instead and prepared statements. These can be used with vendor-specific libraries or by using PDO.

 Read more: 

• Prepared statements and stored procedures in PDO 

• Mysqli Prepared Statements 

• The PostgreSQL pg_query_params function

 Use an ORM 

Take parameterized queries and prepared statements one step further, and avoid, if at all possible, writing SQL queries yourself, by using an ORM; one scrutinized and tested by many security-conscious developers. 

Read more: 

• Doctrine ORM 

• Propel 

• redbeanphp

PHP Security Guide & Checklist for Websites and Web Applications – Bottom Line for Every Good PHP Developer

Here is the article. 

20 Comments / Information Security, PHP Tips & Tutorials / By / 


There are a lot more to consider other than PHP to secure your application. This is just a starting point if you are not also a system administrator who is equally responsible in maintaining a secure server (OS, web server, etc.). Oh and there’s browser security (such as phishing) that you essentially have no control over. So we will just stick to PHP here.

php.ini

Some of the default settings in php.ini in earlier PHP versions are pretty dangerous. Modify the original php.ini if you are a server administrator or create custom php.ini in the webroot (directory of the web documents, accessible to the public via web server) to override the unsafe settings or use in-code functions such as ini_set():

In most cases, you don’t have to worry about more than just the error logging part because the most up-to-date version of PHP has been well optimized in security by default. For example, register_globals and magic_quotes_gpc are turned off as factory settings, and session data is automatically stored outside of webroot. Other than these, feel free to override things by the ini_set() function when you feel obligated to.

Note that magic_quotes_gpc cannot be set by ini_set() any more after PHP version 4.2.3, you have to do it in a local php.ini or .htaccess.

.htaccess

Disable directory listing site wide by adding this line to the .htaccess file (hidden) placed in the document root of your domain:

Valuable files and sensitive data

This includes member only materials, administrator stuff and site wide configuration files containing the vital data of your site, or whatever you feel uncomfortable exposed to the public. In fact, if you are having doubts whether some file is all right to be exposed, don’t expose it at all.

  1. Store them below (outside) webroot so they cannot be retrieved by anyone via web server requests.
  2. Hide the file path and use a PHP script to provide download of it.

Uploaded files

Compulsory security practices when handling uploaded files:

  1. Validate the file name in $_FILES against potential data manipulation. For instance, discard anything that’s not alphanumeric or dot in the file name string.
  2. Validate the mime type against potential spoof and discard anything that seems not what you expect.
  3. After validation, change the file name and move it somewhere confidential below webroot. You can also optionally tar it for storing.
  4. Never execute / serve uploaded files with include() nor require().
  5. Never serve files with mime types of “application/octet-stream”, “application/unknown” nor “plain/text”.

Incoming requests

Cross Site Request Forgery (CSRF) Attacks: Just as the name suggests, the request is forged / fabricated from the authenticated user’s computer yet without his awareness and acknowledgement. For example, the malicious attacker creates a sneaky link (Clickjacking) or a form and manages to trick the legally logged user to use it to submit a hidden request to your application to perform something that he doesn’t authorize at all such as deletion. To prevent it:

  1. Create a confirmation page for the legitimate user to make a final call by clicking ‘Yes’ or ‘No’. The request is then submitted to the server by POST method. Don’t just delete something (or perform other important operations) upon a simple GET request.
  2. Generate a unique token (whatever name = value) in the user’s session and include it in every form as a hidden field so whenever the user submits a POST request, you can check if the form contains the correct token against that in the session variable to make sure if it is submitted by the user by true intentions.

Incoming / User provided data

Always filter or sanitize incoming data in $_GET, $_POST, $_COOKIE or $_REQUEST before using them in your code. Validate that a value is just what you expect and discard any characters suspicious / unneeded. Better yet, white list a few value prototypes by regular expressions and ignore anything that doesn’t match the criteria.

Path Traversal Attacks: By browsing through and trying different combinations of path input to your application, the cracker aims to access files and directories outside of the webroot, probably with a chain of ‘../’ in the path input. To prevent the attack:

  1. Never use user input data directly in your code before it is sanitized or tested against the white list, especially when it is used to determine the subject of file open, include / require, file create and file delete operations.
  2. Let users select indexes rather than the literal path string / file name. For example, open file “/home/test/whatever.txt” when “7” is selected by the user.
  3. In fact, don’t give users the chance to make the call of which file / path to be used / included at all.
  4. Don’t disclose your directory structure to the users in any way, for example, as a hidden field in the form.

SQL Injection Attacks: Exploits of secure vulnerabilities that occur in the database layer of an application wherein user input is not filtered for reserved characters that may cause the database to falsely interpret and execute the SQL query. To prevent this attack:

  1. Escape a string value before using it as part of a SQL query:
    $mysqli -> real_escape_string($str)

    You can also use PDO to prepare the SQL queries, which will automatically sanitize any literal values by escaping it before using them in the query.

Cross-Site Scripting (XSS) Attacks: Or JavaScript injection, security vulnerabilities that allow malicious users to inject HTML code into your web pages that other users can view and execute. It can mess up the page, more fatally, it can load an arbitrary JavaScript script (hosted on another domain) in the user’s browser and steal their cookies thus identity. To prevent this attack:

  1. Cookie should be set with the HttpOnly option enabled (true).
  2. Escape anything and everything that goes live on a web page to be seen by your users:
    htmlentities($str)

Passwords

  1. Optionally enforce strong passwords to your users by only accepting passwords of certain lengths and complexity.
  2. Never store plain text passwords in your database. Instead, salt and hash the passwords. Bottom line is sha1(). Better yet, use hash() with various more advanced algorithms. Never use md5().
  3. Optionally use pass phrases instead of passwords.

Sessions

  1. Regenerate the session ID every time a user’s privileges are upgraded, for example, from visitor to registered member by logging in or from registered member to administrator by further logging in the administrator control panel:
    session_regenerate_id();
  2. Completely destroy session variables (not just empty them) by:
    session_destroy();
  3. Store IP address of initial authentication in session variables and compare request source IP every time you receive a request from the user. However, IP address can unexpectedly change during a legal session and can be a public proxy in the first place.

Cookies

  1. When you need to wipe out some cookie variable, delete it from both the user’s browser AND your server:
    setcookie('SomeCookie', '', time() - 3600); // deletes it from client side
    unset($_COOKIE['SomeCookie']); // deletes it from server side

Other things to consider

  1. All helper / utility scripts in your application that helps develop and debug should be removed from the production deployment. Only necessary files are to remain.
  2. Never talk about your application structure or any other vital information regarding it as real examples in public places such as developer / server administrator discussion boards.
  3. Maintain your own private PHP framework to employ these security practices in a general level. So you will not need to worry about the security particulars of all the projects that derive from this framework. Or use one of the popular PHP frameworks who have gone a long way in security and have been broadly tested by thousands of projects and billions of end users.
  4. It’s not enough to just check and fix your code against these attacks. You have to assimilate these attack prevention tips into your daily coding arsenal and make them as natural as they must be done wherever they are needed. They have to become part of your blood and just feel right to you. Bobince makes a good point on this by asking for a PHP tutorial that preaches the right thing from the very beginning. For example, when you echo something with PHP to the output, even if you are an absolute beginner, it doesn’t absolve you from escaping them first:
    $str = 'Hi, I\'m on a web page.';
    echo htmlentities($str);

Please don’t hesitate to tip in by commenting below to make this security checklist as complete and useful as possible. To start a serious learning session of developing secure web applications, these books will provide a kickass ride for you.