rejetto forum


0 Members and 1 Guest are viewing this topic.

Offline username1565

  • Occasional poster
  • *
    • Posts: 35
    • View Profile
Cann't load the page from server, using latest HFS v2.3m .
I see the following error in browser: ERR_RESPONSE_HEADERS_MULTIPLE_CONTENT_LENGTH

In console.log browser, I see the following errors:

« Last Edit: March 15, 2019, 09:10:31 PM by username1565 »

Offline LeoNeeson

  • Tireless poster
  • ****
    • Posts: 868
  • Status: On hiatus       (sporadically here)
    • View Profile
@username1565: You also posted a possible 'exploit' here, and now by seeing this error I would suggest you may need to do a complete scan with an 'offline' antivirus on your system (since that error is not normal). You can choose one option from THIS or THIS list. As far I know, is impossible that HFS had make those *.vbs files, so, I'm almost sure you have something wrong on your PC.

Just to be sure the problem is related to HFS, is recommended that you open HFS alone, starting with a new clean configuration (and without using any modified template). To do this, copy "hfs.exe" in a new folder (which should be clean, without any other files inside), and you also need to create (an put in that same folder), an empty text file named "hfs.ini" (or else HFS will use the settings stored in your Windows registry). And before running your new clean HFS, you must close any other HFS instance you may have running, and it's also recommended to stop any other web server you could be running. That way, if you find an error, it will be more related to HFS than to any other software you could have running.

About v2.3m, the file checksum is fine, so you can safely ignore all those 'false positives'. The antivirus industry is getting more and more useless and rude, along with using a kind of extortion technique, forcing developers 'code signing' their software. Most of those 'false positives' are reporting a PUA (Potentially Unwanted Application), just because HFS is a web server (which on theory could 'leak' files from a computer, but that's of course the nature of any web server: sharing files the user choose).

Although is very important to report bugs or errors (and it's appreciated), any reported error must be reproducible, and you should give detailed steps to reproduce the issue.

;) » You could find this an interesting read: How to write a good bug report? (Example)
HFS in Spanish (HFS en Español) / How to compile HFS (Tutorial)
» Currently taking a break, until HFS v2.4 get his stable version.

Offline username1565

  • Occasional poster
  • *
    • Posts: 35
    • View Profile
Here, I just using this lite-version of hfs.exe. I cann't attach this file, because this have size 700KB (> 500KB).

MultiHasher - says about following hashes for this lite hfs.exe:
CRC-32: 2536BFB5
MD5: 1C14ECE37D3872A0DDD31EA68AC26B14
RIPEMD-160: FC18AE5137C443B2D39A43F8C56D37ED07909C8F
SHA-1: 4828FDB6CF6B86D87CD63BF46B262D312BCE8C66
SHA-256: FF411E98E16D691AA5FEB07432961B957DA65370871DE6322BA586EF59E92A94
SHA-384: C9710DCC39362851328CB9C4DF1E49DE996BB862136D77C77C09AC2459795EFB75782A24BF47672C99BC1B1D635B92F2
SHA-512: 45A337A2D9AEA3374A5AF77BF19ACA0E3AC0DFEA320C9B1AE5A4D2F3A72B0BEF1B2D8D590C99CA36FB29D7870DEE659CBE4834A1C444921329F6F015A63EC15A

And maybe you can find this file by this hashes in your full repositary, and test this.

Google query by sha256 return me back the link on virustotal:
and I see the version of this file: hfs2.3a_289.

Why I use this lite version?
Just Because HFS v2.3m(2MBytes) return me the error in the first post of this thread!
just when I try to load the page from this server...

I didn't have any problem with previous lite-version HFS (700Kbytes),
up to yesterday. Because yesterday I saw this %TEMP% folder.

What logs do you need? Where I can see this on Windows 8.1? I don't understand...

And... How to using HFS.exe v2.3m (2MBytes),

I did check my hard disk, using Comodo Internet Security Premium 11, and not found any viruses.
%TEMP% folder was been renamed.
Virtual File Systems.vfs was been damaged.
Some backups of file-systems files was contains some macroses, and was been renamed.
Now my lite version working good, but... I'm not sure that this will be stable...

Now, I'm using hfs_v2.3k.exe 2.38 МB (2 501 632 Bytes), with hashes:
MD5: 369B251EB6D24F63C95273F357359669
RIPEMD-160: A2038CF37927DABD66FC0808ED6804AB876AC783
SHA-1: 17820F1585A08FD7B5890192F58AB9860961B064
SHA-256: 3B4AD8F1F15F1A73E99CF082AE38A821A7567B63415F57D63595BAEC079A4B07
SHA-384: EE320267F63F2118D9B7C7F4A8667444B1817527A0F8FB921418ECB69A963AD7901B0A815B136CE5E5EEE5ACFA5EAAA7
SHA-512: 305340B4A0047D81452C29EB63BBC263A921B5B6CC46AFE09D38329E966AEA411A77039671CDC2CBE7715A784025EBB3A9309EAF8AC95B868242A970FE66A1F0
Virustotal by sha256-hash:

Also, this russian v2.3m
Hashes you can see there.
« Last Edit: March 16, 2019, 12:23:48 PM by username1565 »

Offline LeoNeeson

  • Tireless poster
  • ****
    • Posts: 868
  • Status: On hiatus       (sporadically here)
    • View Profile
OK, now we are doing some progress (your info will help Rejetto catch the bug)

» Summarizing:

HFS v2.3k and previous versions are working without this error.

So, according to your reports, this error was introduced on version 2.3m.

» Another important questions: you said (here) that you were also running another server (to have PHP functions). Are you running that server along with HFS?. Does this error still happen when you close that another server? (this information is needed to debug this error, and to know if this is some kind of incompatibility). And lastly, what version of Chrome are you using?...

» Note to Rejetto: it seems this happens when multiple distinct 'Content-Length' headers are received. According THIS StackoverFlow answer, 'if you do not specify "Transfer-Encoding" and you include multiple lengths it will throw this very error'. Anyway, to me it seems a error is client side related, not directly related to the server (but you know more than me).
HFS in Spanish (HFS en Español) / How to compile HFS (Tutorial)
» Currently taking a break, until HFS v2.4 get his stable version.

Offline SilentPliz

  • Operator
  • Tireless poster
  • *****
    • Posts: 1298
  • ....... chut ! shh!
    • View Profile

Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13523
    • View Profile
in 2.3m i added the "Content-Length" in error pages because it was missing.
The error says you are getting multiple, but i just checked and HFS is sending one, and it is working for everybody, so the problem must be something specific on your system.
Possibly something is adding another content-length, and this was fine to Chrome with old versions, because before HFS was sending none.
Now that HFS is sending it, adding another is causing the problem.
You must find what is adding the Content-Length. It could be a plugin of the browser, an {.add header.} command somewhere in your template/events, or another server/proxy if you are not connecting directly.
I invite you to try to use HFS directly (no other servers) and with configuration reset (Menu > debug > temporarily reset options), and let us know what happens with this.

Offline username1565

  • Occasional poster
  • *
    • Posts: 35
    • View Profile
in 2.3m i added the "Content-Length" in error pages because it was missing.
I invite you to try to use HFS directly (no other servers) and with configuration reset (Menu > debug > temporarily reset options),
and let us know what happens with this.
Before, and after I do this: ("Menu > debug > temporarily reset options")
I see double Content-Length in Google Chrome 73.0.3683.75
(Load page -> F12 -> network -> main page -> headers),
but the page loading good in this browser.
And in older Google Chrome and Mozilla Firefox (32 bit) - I see that error, and cann't load the page.
This is one header that was been doubled.

Can I disable this header? Can you add option in the settings, to disable this in future?

Also, my Comodo see the virus in HFS 2.3k, and blocking this automatically, after I renaming this file.
So need to unblock this anytime. HFS 2.3m not blocked, but not working anywhere,
because this header, and this error...

I did start HFS v2.3m in Windows XP. Main page is successfully loaded.
I see two headers in the Network-tab, in Google Chrome 34.0.1847.131 m:
Cache-Control:no-cache, no-store, must-revalidate, max-age=-1
Server:HFS 2.3m
But, I successfully loaded the main page!
So now I don't sure that problem in this header only. Maybe something else.
Because error I see, when I start HFS on Windows 8.1, and try to load the page from there.
So just compare more differences between x86 and x64 sub-programs...

Have a nice day.
« Last Edit: March 17, 2019, 08:57:17 PM by username1565 »

Offline username1565

  • Occasional poster
  • *
    • Posts: 35
    • View Profile
OK, now we are doing some progress (your info will help Rejetto catch the bug)
» Summarizing:
HFS v2.3k and previous versions are working without this error.

So, according to your reports, this error was introduced on version 2.3m.
Yeap, all right.

» Another important questions: you said (here) that you were also running another server (to have PHP functions). Are you running that server along with HFS?. Does this error still happen when you close that another server? (this information is needed to debug this error, and to know if this is some kind of incompatibility). And lastly, what version of Chrome are you using?...
That "upload.php" file is hosted on another remote server.
This is just example with WORKING uploading progress.
I didn't host this PHP-page on any local server, and don't run any servers with HFS.
I just copied the code in single HTML, and replaced that link in that example - to the link for uploadable folder on HFS,
to test XHR-uploading there, ajax true/false, and return progress status.
HFS is not PHP-server, and to working with PHP better to using apache, or portable OpenServer.

Hi !

I think it's possible that this bug is related to this thread :
Hi, I see HFS.Events there, but I don't know how do remove Content-Length header, using this file, to test it...
« Last Edit: March 17, 2019, 09:27:38 PM by username1565 »

Offline LeoNeeson

  • Tireless poster
  • ****
    • Posts: 868
  • Status: On hiatus       (sporadically here)
    • View Profile
Hi, I see HFS.Events there, but I don't know how do remove Content-Length header, using this file, to test it...
Make a file named "HFS.Events" with this:

Code: [Select]
{.remove header|Content-Length.}
{.remove header|Content-Length.}

Report back if that solved your problem.
HFS in Spanish (HFS en Español) / How to compile HFS (Tutorial)
» Currently taking a break, until HFS v2.4 get his stable version.

Offline username1565

  • Occasional poster
  • *
    • Posts: 35
    • View Profile
@LeoNeeson, I created this file and put this near hfs.exe (v2.3m).
Then I did run hfs.exe on Windows 8.1 (x64).
After this I try to open the main page on HFS. Ok.
Then F12 -> Network, and reload the page. See request of the main page.
And there I can see doubled headers with Content-length.

When I try to open the main page on HFS from win32 Google Chrome - I still see ERR_RESPONSE_HEADERS_MULTIPLE_CONTENT_LENGTH

So HFS.Events - not working.

Offline LeoNeeson

  • Tireless poster
  • ****
    • Posts: 868
  • Status: On hiatus       (sporadically here)
    • View Profile
Sorry, then I have no idea on how solve that.
HFS in Spanish (HFS en Español) / How to compile HFS (Tutorial)
» Currently taking a break, until HFS v2.4 get his stable version.

Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13523
    • View Profile
i've recently found a bug like this and will be fixed in next release (2.4)