<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>What's New - WORK ActiveSync</title>
<link>http://www.was.com.my/</link>
<description>What's New - Latest 10 Records</description>
<copyright>Copyright(C) WORK ActiveSync</copyright>
<generator>WORK ActiveSync v4.0.5 Retail Pack</generator>
<builder>WORK ActiveSync</builder>
<lastBuildDate>Fri, 03 Sep 2010 01:44:37 +0000</lastBuildDate>
<ttl></ttl>
<image>
<url>http://www.was.com.my/images/Pro-Blue/xml.gif</url>
<title>WORK ActiveSync</title>
<link>http://www.was.com.my/</link>
</image>
<item>
 <title>Notification for Security Update</title>
 <link>http://www.was.com.my/viewpost.php?post=5</link>
 <description><![CDATA[<p><strong>Dear Value Customers</strong></p>
<p>We have come across cases that some of the users uploaded the php scripts for the website, which write in older version of php, not secure, and exploitable to be execute by "nobody" user. To prevent server attack from vulnerabilities, we have strengthen the security layer and upgrade the server to run in <a href="http://www.suphp.org" target="_blank">SuPHP</a> mode on yesterday midnight (8/9/2009).</p>
<p><strong><span style="font-size: medium;">What is </span><a href="http://www.suphp.org" target="_blank"><span style="font-size: medium;">SuPHP</span></a><span style="font-size: medium;">?</span></strong></p>
<p>It runs all PHP scripts as the user in whose account they reside - rather than running all scripts as user "nobody". It also prevents scripts that have insecure permissions from running.</p>
<p><strong><span style="font-size: medium;">What problem with regular PHP, and how </span><a href="http://www.suphp.org" target="_blank"><span style="font-size: medium;">SuPHP</span></a><span style="font-size: medium;"> benefits over?</span></strong></p>
<ol>
<li><a href="http://www.suphp.org" target="_blank">SuPHP</a> does not allow files/folders to run where they have group and world write permissions; only the account owner can write to files/folders. This forces all users to ensure that their files/folders have correct permissions and prevents hackers uploading malicious content into vulnerable folders.</li>
<li><a href="http://www.suphp.org" target="_blank">SuPHP</a> allows all PHP scripts to be run under the user account ownership, instead of running under the "nobody" user. This is particularly helpful in tracking down scripts which send out SPAM as the "nobody" user.</li>
</ol>
<p>Regular PHP installation on a web server runs as the user nobody and it doesn't require the execute flag to be enabled. The problem with regular PHP installation is that if mod_openbasedir is not installed, every user on the server will be able to read your php files because practically everyone shares the same username (nobody).<br />PHP Files are not meant to be read, but parsed, otherwise everyone who is able to read your php file will able to view settings that you would want to keep private, such as your MySQL username and password.</p>
<p><a href="http://www.suphp.org" target="_blank">SuPHP</a> fixes this issue because it requires PHP scripts to be executed with the permissions of their owners. <a href="http://www.suphp.org" target="_blank">SuPHP</a> also fixes common file ownership issues that mostly occur with few Content Management Systems such as Joomla and also on the popular blog software: WordPress.</p>
<p><strong><span style="font-size: medium;">Is </span><a href="http://www.suphp.org" target="_blank"><span style="font-size: medium;">SuPHP</span></a><span style="font-size: medium;"> will have any affect on my website?</span></strong></p>
<p>Most PHP scripts will run well within a <a href="http://www.suphp.org" target="_blank">SuPHP</a> environment. <br />However, some older not well-maintained scripts that rely on insecure permissions (like 777) may experience issues in a <a href="http://www.suphp.org" target="_blank">SuPHP</a> environment.</p>
<p><strong><span style="color: #0000ff;">&nbsp;- .htacccess<br /></span></strong><br /><a href="http://www.suphp.org" target="_blank">SuPHP</a> is not reading .htaccess, it does not support the php_value/php_admin_value directive known by mod_php to parse configuration options to scripts for certain virtual hosts or directories. All the php_flags in your .htaccess will have to be moved to php.ini, which you will have to create in your public_html directory.</p>
<p>For example, you might have a value as "php_flag register_globals on" in your .htacess file, you will need to move it as "register_globals=on" into your php.ini file. <br />You will have to move every command on .htaccess that starts with php_flag. into&nbsp; php.ini file.</p>
<p><strong><span style="color: #0000ff;">- File permission of 777</span></strong><br /><br />Directories that require writable permissions will no longer require 777 as permissions and <a href="http://www.suphp.org" target="_blank">SuPHP</a> will refuse to write or read on directories exposed with such permissions, make sure you chmod them to 755.<br /><br />The highest level of permissions that a user can use on a <a href="http://www.suphp.org" target="_blank">SuPHP</a> enabled server is 755. This permission setting is sufficient enough for any directories/files that need to be written to.</p>
<p><strong><span style="font-size: medium;">My Website shown: Troubleshooting Internal Server Errors (Error 500):</span></strong></p>
<p>You may move the command in .htacess to php.ini file under your public_html folder, you may create it if its not exist. Check your folder permission, the highest level of permissions that a user can use on a <a href="http://www.suphp.org" target="_blank">SuPHP</a> enabled server is 755.</p>]]></description>
 <pubDate>Thu, 10 Sep 2009 00:05:39 +0000</pubDate>
</item>
<item>
 <title>Important Changes on Our Email Hosting Policy</title>
 <link>http://www.was.com.my/viewpost.php?post=4</link>
 <description><![CDATA[<p>Due to free email service provider has applied more strict anti-spam policy in their mail server, We regret to announce that we will no longer allow email forwarding from your hosted email account to any of the free email service providers (e.g. <strong>yahoo.com</strong>, <strong>gmail.com</strong>, <strong>hotmail.com</strong>, <strong>aol.com</strong>, <strong>rocketmail.com</strong>, <strong>tm.net.my</strong>, <strong>streamyx.com</strong> and so on) in our shared hosting mail server.
<p>Many of our customers set their email accounts to forward a copy of the incoming email to the free email service providers. If the email account receives lot of incoming mail and forwards to the free email service providers, they might treat this as an attack or SPAM sending and consequently block us from sending email to their email accounts</p>
<p>In order to secure our mail server, we decided to disallow customers from forwarding their email to the email service providers. If you have any of your user email accounts forward any incoming email to any free email service providers, <span style="color: #ff0000;">please request them to remove the email forwarding</span>.</p>
<p>We thank you for your kind cooperation and tolerance.</p>
</p>]]></description>
 <pubDate>Fri, 17 Jul 2009 15:26:45 +0000</pubDate>
</item>
<item>
 <title>Enabling SMTP Authentication</title>
 <link>http://www.was.com.my/viewpost.php?post=3</link>
 <description><![CDATA[<p><strong>Important changes to your mail software settings</strong></p>
<p>As part of our ongoing commitment to security, we are continually reviewing security measures to protect your website and email. Most of these changes happen behind the scenes and do not require any action on your behalf.</p>
<p>You will need to make the changes to your mail software settings. If you do not make the changes you may be unable to send mail.</p>
<p>Please read below to see if you will be required to make any changes. If you are required to make any changes, step-by-step instructions are provided on how to make the changes.</p>
<ul>
<li><img src="http://www.was.com.my/admin/images/icon/swf.gif" alt="" width="18" height="18" /> <a onclick="window.open('upload/smtp-auth-mo.htm','smtpauthmo','width=820,height=550,left=20,top=20,toolbar=no,menubar=no,status=no,scrollbars=yes,resizable=yes'); return false;" href="upload/smtp-auth-mo.htm">Microsoft Outlook</a></li>
<li><img src="http://www.was.com.my/admin/images/icon/swf.gif" alt="" width="18" height="18" /> <a onclick="window.open('upload/smtp-auth-oe.htm','smtpauthoe','width=820,height=550,left=20,top=20,toolbar=no,menubar=no,status=no,scrollbars=yes,resizable=yes'); return false;" href="upload/smtp-auth-oe.htm">Microsoft Outlook Express</a></li>
<li><a href="http://www.was.com.my/archive.php?file=11" target="_blank">Apple Mail</a></li>
<li><a href="http://www.was.com.my/archive.php?file=12" target="_blank">Netscape 7.1</a></li>
<li><a href="http://www.was.com.my/archive.php?file=13" target="_blank">Eudora (for Windows)</a></li>
</ul>]]></description>
 <pubDate>Fri, 17 Jul 2009 15:25:21 +0000</pubDate>
</item>
<item>
 <title>Mitigating SPAM in TM Network</title>
 <link>http://www.was.com.my/viewpost.php?post=2</link>
 <description><![CDATA[<p>Be informed that effective Monday, December 03, 2007, Telekom Malaysia Berhad had implemented a new policy in their effort to combat spam. TM had basically blocked OUTBOUND Simple Mail Transfer Protocol (SMTP) traffic or port 25 for all outgoing e-mails from DYNAMIC IP ADDRESSES. As such, users who are currently using any mail clients (e.g. Outlook Express, Microsoft Outlook, Thunderbird, etc.) and TMNet connections (Dynamic IP address users) would no longer be able to send email directly. The implementation would be carried out in 3 stages:</p>
<p>3 December 2007 - part of Klang Valley<br />5 December 2007 - Klang Valley<br />7 December 2007 - all states in Malaysia Please click here to read more.</p>
<p>Are you affected? <span style="color: #ff0000;">You will be affected if you are using TM's dynamic IP address.</span></p>
<p>
<p><span style="color: #000000;"><strong><span style="color: #4574bc;"><span style="font-size: medium;">
<hr style="width: 647px;" size="2" />
</span></span></strong></span><span style="color: #000000;"><strong><span style="color: #4574bc;"><span style="font-size: medium;">How to overcome this problem?</span></span></strong></span></p>
</p>
<p><span style="color: #000000;"><strong>Solution 1</strong></span></p>
<p><span style="color: #000000;">For those who hosted their mail server with us, please refer to the below Tutorial Movie for How to change Port 26 for your Outgoing (SMTP) server:</span></p>
<ul>
<li><span style="color: #000000;"><img src="http://www.was.com.my/admin/images/icon/swf.gif" alt="" width="18" height="18" /> <a onclick="window.open('upload/port26-oe.htm','oe26','width=820,height=550,left=20,top=20,toolbar=no,menubar=no,status=no,scrollbars=yes,resizable=yes'); return false;" href="upload/port26-oe.htm">Microsoft Outlook Express</a></span></li>
<li><span style="color: #000000;"><img src="http://www.was.com.my/admin/images/icon/swf.gif" alt="" width="18" height="18" /> <a onclick="window.open('upload/port26-mo.htm','mo26','width=820,height=550,left=20,top=20,toolbar=no,menubar=no,status=no,scrollbars=yes,resizable=yes'); return false;" href="upload/port26-mo.htm">Microsoft Outlook</a></span></li>
</ul>
<p><span style="color: #000000;"><strong>Solution 2</strong></span></p>
<p><span style="color: #000000;">Change to use alternative ISP such as Maxis, Jaring, TimeNet, NTT etc.</span></p>
<p><span style="color: #000000;"><strong>Solution 3</strong></span></p>
<p><span style="color: #000000;">Upgrade your TM-Net ISP from dynamic IP address to dedicated IP address.</span></p>]]></description>
 <pubDate>Fri, 17 Jul 2009 15:24:27 +0000</pubDate>
</item>
  </channel>
  </rss>