Commit Graph

  • 756e16b533 Fixed potential race condition pointed out in issue #31 Daniel Winzen 2018-12-06 16:54:35 +01:00
  • 5cd13e9269 Introduced selection between v2, v3 and custom hidden service Daniel Winzen 2018-12-06 16:24:35 +01:00
  • 305c8bc0c3 Fix mariadb 10.3 compatibility by adding default values Daniel Winzen 2018-12-05 22:19:46 +01:00
  • be005c3137 Renamed config file Daniel Winzen 2018-12-05 17:18:46 +01:00
  • aedd8a1e6a Update to latest mariadb version Daniel Winzen 2018-12-05 17:18:11 +01:00
  • 64163823a8 dnsmasq should only listen on lo interface Daniel Winzen 2018-12-05 07:59:46 +01:00
  • fd95a4e2e3 v3 hidden service export to disk + hostname file is auto generated by tor Daniel Winzen 2018-12-04 21:48:45 +01:00
  • c9cddc9f86 Username should be a prepared variable Daniel Winzen 2018-12-04 21:23:56 +01:00
  • d0710d3d20 Merge pull request #37 from DanWin/revert-35-patch-1 Daniel Winzen 2018-12-04 21:13:51 +01:00
  • 0fc4412404 Revert " Disabling emulated parameters" Daniel Winzen 2018-12-04 21:10:36 +01:00
  • ba71455ca5 Introduce DEFAULT_PHP_VERSION Daniel Winzen 2018-12-04 20:48:08 +01:00
  • 4e163a7e2d Fixed syntax error Daniel Winzen 2018-12-04 15:26:24 +01:00
  • c174251826 exim4 might interfere with postfix Daniel Winzen 2018-12-04 13:36:16 +01:00
  • 4f059e66f7 Droped php7.2 systemd.service files Daniel Winzen 2018-12-04 13:29:17 +01:00
  • c651bb65c7 Add jounald.conf Daniel Winzen 2018-12-03 17:22:23 +01:00
  • 6ee51f3d7e removed stray mention of php7.2 Daniel Winzen 2018-12-02 21:44:07 +01:00
  • 22066309d5 Add login.defs file Daniel Winzen 2018-12-02 21:41:31 +01:00
  • 363d1b31ad Debian sid dropped php7.2 support - move to 7.3 only Daniel Winzen 2018-12-02 21:17:11 +01:00
  • 2e0e69d605 We don't need apt repository translations Daniel Winzen 2018-12-02 19:31:26 +01:00
  • 2149bc9fd8 update paragonie/sodium_compat dependency Daniel Winzen 2018-12-02 10:45:51 +01:00
  • 7111fa3a65 Prevent httpoxy vulnerability in PHP applications Daniel Winzen 2018-11-29 20:56:28 +01:00
  • 921c43122c Merge pull request #35 from teikakki/patch-1 Daniel Winzen 2018-11-28 21:05:56 +01:00
  • cf8a6cde80 emulated params teikakki 2018-11-28 14:30:36 +00:00
  • 1fc180752f emulated params teikakki 2018-11-28 14:30:22 +00:00
  • 4475e3b277 emulated params teikakki 2018-11-28 14:30:05 +00:00
  • 6ffd291f12 emulated params teikakki 2018-11-28 14:29:46 +00:00
  • 79774b5a1d emualted params teikakki 2018-11-28 14:29:27 +00:00
  • b46d0c7ab0 emulated params teikakki 2018-11-28 14:29:13 +00:00
  • 01af3c367d emulated params teikakki 2018-11-28 14:28:49 +00:00
  • 7ab640ea4b emulated params teikakki 2018-11-28 14:28:36 +00:00
  • 5753ca2cee Disabling emulated parameters teikakki 2018-11-28 14:26:55 +00:00
  • 36fc7103cb Add hidden service v3 keygen and parser for base64 encoded secret keys Daniel Winzen 2018-11-25 14:36:28 +01:00
  • f0afbe14c9 Add sodium_compat composer dependency for v3 hidden_services Daniel Winzen 2018-11-24 14:56:24 +01:00
  • 9de11a9722 Dropped PHP7.1 support and install composer Daniel Winzen 2018-11-24 10:38:59 +01:00
  • 910381fee2 Removed php7.0 setup instructions Daniel Winzen 2018-11-19 21:23:34 +01:00
  • 7d032f4955 Merge pull request #28 from jtesta/sshd_hardening Daniel Winzen 2018-11-19 21:20:43 +01:00
  • e4e59782ca Disabled RSA host key type (because small keys are generated by default), as well as ECDSA (due to suspicions of NSA-compromised P-curves). Enabled only strong key exchange, cipher, and MAC algorithms. See https://www.sshaudit.com/ and https://github.com/arthepsy/ssh-audit. Joe Testa 2018-11-19 15:01:11 -05:00
  • 41b33f2c51 Drop PHP7.0 support Daniel Winzen 2018-11-18 20:50:35 +01:00
  • db626a54a4 disable imap_open because of https://github.com/Bo0oM/PHP_imap_open_exploit Daniel Winzen 2018-11-17 10:15:15 +01:00
  • f4ca23336b Add clamav virus scan to mails Daniel Winzen 2018-11-11 11:17:20 +01:00
  • bb21f9f10b Reload disabled php versions since accounts can still be deleted Daniel Winzen 2018-10-28 09:31:00 +01:00
  • 5f3dfefa02 Drop now redundant config Daniel Winzen 2018-10-28 09:07:20 +01:00
  • b69293ab6d Dynamic supported versions on frontpage Daniel Winzen 2018-10-28 09:01:31 +01:00
  • 58b5efb96c Added suspend hidden service feature + disabled php7.0 for new accounts Daniel Winzen 2018-10-28 08:48:30 +01:00
  • 1884f4b08b php is .ini not .conf Daniel Winzen 2018-10-26 19:14:29 +02:00
  • 9985ba4864 Add PHP7.3 support and let setup.php write initial config files Daniel Winzen 2018-10-24 19:59:02 +02:00
  • d5d7078776 Allow editing hidden service options Daniel Winzen 2018-10-22 21:45:08 +02:00
  • b80f30ac03 Ignore insecure 777 permissions set by users on logrotate Daniel Winzen 2018-10-21 10:44:23 +02:00
  • cfb19915b5 Optimized find query to only search within each users tmp directory Daniel Winzen 2018-10-20 21:08:44 +02:00
  • d9e496930d Add HiddenServiceMaxStreams option and service_instances table Daniel Winzen 2018-10-20 20:43:26 +02:00
  • 2cee59dc6f Structure changes for future features Daniel Winzen 2018-10-20 18:20:27 +02:00
  • 96efd92ab1 bump dbversion Daniel Winzen 2018-10-17 21:51:20 +02:00
  • 1f2ff2176b Save DB information in separate table Daniel Winzen 2018-10-17 21:50:20 +02:00
  • 6eb068222c Refactor DB foreign keys to auto_incrementing id instead of onion Daniel Winzen 2018-10-16 21:09:16 +02:00
  • 81c2364b7b Better load distribution on multiple relays Daniel Winzen 2018-09-23 20:09:04 +02:00
  • acc8782043 Add privacy policy checkbox (required by GDPR) Daniel Winzen 2018-09-10 19:30:12 +02:00
  • 382ea73efb Update firewall rules Daniel Winzen 2018-09-10 19:20:11 +02:00
  • 2c634b889c Add dnsmasq DNS caching and performance tune tor instances Daniel Winzen 2018-09-10 19:11:02 +02:00
  • 156a66a3ff Added missing php7.0-intl package Daniel Winzen 2018-09-10 19:06:51 +02:00
  • 1d157473e6 Move account folder creation into cron.php Daniel Winzen 2018-07-14 10:41:44 +02:00
  • f43e699b91 chroot postfix Daniel Winzen 2018-06-18 20:24:00 +02:00
  • e6d798370f secmail.pro dropped rewriting of .onion to .pro domain Daniel Winzen 2018-06-02 12:05:30 +02:00
  • 943ca4b151 Enable fastcgi_cache Daniel Winzen 2018-05-15 20:45:49 +02:00
  • dda49153b3 Buffer access log writes to reduce IO Daniel Winzen 2018-05-13 09:04:12 +02:00
  • 1a9ee646c6 Adapt firewall rule to new ftp ports Daniel Winzen 2018-05-06 09:57:24 +02:00
  • c6498ea1dc Increase available ports for passive ftp Daniel Winzen 2018-05-05 14:10:01 +02:00
  • 49a5b187b0 Increase buffer to get rid of errors on large response headers (e.g. cookies) Daniel Winzen 2018-04-22 15:07:00 +02:00
  • 300cd647df Increase limits and add putenv to disabled functions (vulerability) Daniel Winzen 2018-04-22 09:11:43 +02:00
  • c9487adb1a MariaDB hit open_files_limit -> increase it Daniel Winzen 2018-03-12 06:46:41 +01:00
  • e6ac79457f We have proper firewalling, fsockopen no longer needs to be disabled Daniel Winzen 2018-03-11 20:26:19 +01:00
  • b2fab1ec53 Fix /var/run/nginx not being created on nginx start Daniel Winzen 2018-03-11 20:17:14 +01:00
  • 7bd2e79f06 Separate nginx sockets for each site to make hoster identification harder Daniel Winzen 2018-03-08 20:57:42 +01:00
  • 9eb5c2ae3c Show error message on login when account has not yet been created Daniel Winzen 2018-03-03 19:22:57 +01:00
  • 47b9b6e3a6 Fixed db query Daniel Winzen 2018-02-26 16:37:35 +01:00
  • e8f8f42a24 Fix db query Daniel Winzen 2018-02-25 21:53:00 +01:00
  • 463be89b09 bumped database layout version Daniel Winzen 2018-02-25 21:47:29 +01:00
  • 6b0759be73 Added admin panel + optional manual approval for new sites Daniel Winzen 2018-02-25 21:25:05 +01:00
  • eca0c675cd Added missing dovecot config to use home maildir Daniel Winzen 2018-02-11 19:53:10 +01:00
  • ea112b3389 Added missing authorized destinations for services also reachable via .onion Daniel Winzen 2018-02-11 17:36:50 +01:00
  • 5163c7aa2b Connect to unix socket for default site Daniel Winzen 2018-02-11 17:22:31 +01:00
  • ee191ccbb8 PHP7.2 no longer has the mcrypt module as a package Daniel Winzen 2018-02-11 15:46:52 +01:00
  • fa24bb61ec Added PHP 7.2 support + minor bugfixes and performance tweaks Daniel Winzen 2018-02-10 22:10:07 +01:00
  • c65055a9bb Set mysql host to % instead of localhost to allow connections to 127.0.0.1 Daniel Winzen 2017-12-21 20:26:24 +01:00
  • 779c7bdaea Mentioned https://deb.sury.org/ debian php packaging Daniel Winzen 2017-12-07 18:05:24 +01:00
  • a9fd1b658c Use X-Accel-Redirect in log.php output Daniel Winzen 2017-12-03 12:48:37 +01:00
  • 99ccbdccfe Updated tutorial for Ubuntu 16.04 LTS compatibility Daniel Winzen 2017-11-05 10:33:29 +01:00
  • e8dd2b864e Sort disable_functions and added a few system info revealing posix_* functions Daniel Winzen 2017-09-03 18:25:13 +02:00
  • 20754f052f Update frontpage and FAQ texts Daniel Winzen 2017-09-03 14:15:55 +02:00
  • 6384f4929a Added text editor to FileManager Daniel Winzen 2017-09-03 11:09:07 +02:00
  • 8801d3ae0c Increase PHP memory limit to 256M Daniel Winzen 2017-09-02 08:49:16 +02:00
  • e34ad9efd7 Allow browser caching of common ressources (js, css img, vid and audio) Daniel Winzen 2017-08-26 14:49:03 +02:00
  • 6c6b6a689d Protect from zip-bombs Daniel Winzen 2017-08-07 21:15:13 +02:00
  • 06dce903dc cleanup tmp file Daniel Winzen 2017-08-07 21:05:58 +02:00
  • 5244f89340 Make file upload multiupload Daniel Winzen 2017-08-06 17:10:19 +02:00
  • f549f6ddfb Added web based FileManager Daniel Winzen 2017-08-06 15:35:47 +02:00
  • 2a95dfc748 Show hidden files in FTP Daniel Winzen 2017-08-06 13:19:51 +02:00
  • 2cda288913 Increase upload limits Daniel Winzen 2017-08-06 10:57:56 +02:00
  • df22041c09 Added anonymail.tech rewrite rule Daniel Winzen 2017-08-03 17:47:27 +02:00
  • c85e5a9100 Added vfemail.net rewrite rule Daniel Winzen 2017-08-01 20:34:37 +02:00
  • d33b216a4f Added secmail.pro rewrite rule Daniel Winzen 2017-08-01 20:20:07 +02:00