You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 149 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Beta Fortress(TM) 1.20 Released [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Tue May 25, 2004 6:30 am Reply with quoteBack to top

Oh sorry, I was working on my Googletap news article and was in two different worlds. Wink

I don't know how your apache is set to run, but in general terms, so long as apache has READ and WRITE permissions to both the CSV and HTM files all will be well.

If apache even has the permission to create the files, then you have nothing to worry about. If not, then use the info at the end of the PHP file to create the two and adjust settings as stated above.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
American
Corporal
Corporal


Joined: Jan 17, 2003
Posts: 58


PostPosted: Tue May 25, 2004 6:46 am Reply with quoteBack to top

I pulled Raven's admin hackalert and now I receive the email, info is added to the csv but not the htm file. I am of course blocked and see the Banned by C-Like.

Now all I have to do is straighten out the htm permissions.

_________________
Brad
Find all posts by AmericanView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Tue May 25, 2004 6:50 am Reply with quoteBack to top

OK, perfect. Which site is this for?

You can edit the csv manually and remove the line that has you listed.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
nukestud
Private
Private


Joined: Mar 25, 2003
Posts: 38


PostPosted: Tue May 25, 2004 7:35 am Reply with quoteBack to top

After applying latest union + fortress to nuke 7.0 it starting adding my god admin name to all new registered members names. After logging out of admin it was then impossible to log back in causing a sort of admin loop and access denied messages...

After 2 years of constant battling with nuke, from major bugs to constant server attacks, and many many reinstalls, this is the last straw.. Phpnuke has never been and IMHO never will be a commercial applicable solution for a site which has a significant amount of members and traffic no matter how much hacking you do.. I have had enough and I will be removing all traces of nuke as soon as humanly possible.

Good luck to the rest of you guys and gals playing around with nuke, I hope you have better luck than I have had.

Best of luck..

PS. Those of you professional programmers who provide support here or doing the security fixes i would suggest seriously getting together a rewriting somthing from scratch, just do yourselves a favor and don't make it opensource and sell copies for money. After all it is quite an excellent CMS just poorly constructed..

_________________
Virtual Stock Exchange
Stock Market News

Last edited by nukestud on Fri Oct 15, 2004 12:49 am; edited 1 time in total
Find all posts by nukestudView user's profileSend private messageVisit poster's website
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Tue May 25, 2004 7:41 am Reply with quoteBack to top

Not sure what happened but this clearly sounds like an improper installation or modification.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
nukestud
Private
Private


Joined: Mar 25, 2003
Posts: 38


PostPosted: Tue May 25, 2004 7:48 am Reply with quoteBack to top

I had a feeling you might say that lol It's not as if it's a tricky mod but anyway I don't really want to get into it..

_________________
Virtual Stock Exchange
Stock Market News

Last edited by nukestud on Fri Oct 15, 2004 12:49 am; edited 1 time in total
Find all posts by nukestudView user's profileSend private messageVisit poster's website
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Tue May 25, 2004 8:31 am Reply with quoteBack to top

No worries... at least you tried.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
BrainSmashR
Support Mod
Support Mod


Joined: Jan 05, 2004
Posts: 1390

Location: Louisiana, USA

PostPosted: Tue May 25, 2004 3:15 pm Reply with quoteBack to top

Installed fortress, clicked one link on my homepage....I'm instantly banned. Have removed the csv file and I'm STILL banned.


How do I remove the ban and stop this from banning folks for just clicking links?

_________________
ImageImage
USE THE FORUM. If you contact me via messenger for support I will add you to my ignore list.
Find all posts by BrainSmashRView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
BrainSmashR
Support Mod
Support Mod


Joined: Jan 05, 2004
Posts: 1390

Location: Louisiana, USA

PostPosted: Tue May 25, 2004 4:28 pm Reply with quoteBack to top

Well, crisis adverted. Here's the link I clicked. It's in a center block I created for my site. I was banned because of bad tags

http://www.brainsmashr.com/modules.php?name=Top_Users

It also banned a buddy of mine for the same reason, but he says he really doesn't know what he clicked.

Any ideas how to resolve this issue?

_________________
ImageImage
USE THE FORUM. If you contact me via messenger for support I will add you to my ignore list.
Find all posts by BrainSmashRView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
BrainSmashR
Support Mod
Support Mod


Joined: Jan 05, 2004
Posts: 1390

Location: Louisiana, USA

PostPosted: Thu May 27, 2004 3:26 am Reply with quoteBack to top

So what's the word on this?

Will the same errors happend when/if I put fortress into my CPGNuke this afternoon?

_________________
ImageImage
USE THE FORUM. If you contact me via messenger for support I will add you to my ignore list.
Find all posts by BrainSmashRView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
foxyfemfem
Support Staff
Support Staff


Joined: Jan 23, 2003
Posts: 668

Location: USA

PostPosted: Thu May 27, 2004 4:03 am Reply with quoteBack to top

Hello,

Let me see if I get this right, you are banned from your website because of a link you clicked. Now you are posting that same link for someone else to click and get banned.. am I correct? Laughing

What codes do you have in Top Users? Remember the following code was added to mainfile.php via fortress....

Code fortress added to mainfile.php.......

foreach ($HTTP_GET_VARS as $secvalue) { // Current code
if ((eregi("<[^>]*script*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*iframe*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*object*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*applet*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*meta*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*style*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*form*\"?[^>]*>", $secvalue)) || // Current code
(eregi("<[^>]*img*\"?[^>]*>", $secvalue)) || // Current code
(eregi("\"", $secvalue))) { // Current code
# die ("The html tags you attempted to use are not allowed"); // Current code but either delete or comment out
$method = "BAD-TAGS"; // Add this line
$matches[1] = "BAD-TAGS"; // Add this line
AlertMail($method); // Add this line
AlertLog($method); // Add this line
} // Current code
}

Therefore you will get banned. You can either comment this code out or remove the tags you have within your Top User module.

To unban yourself you must remove the information from fortress.csv & fortress.htm file.

_________________
If you shoot for the moon and miss, you'll still be amongst the stars.
Find all posts by foxyfemfemView user's profileSend private message
BrainSmashR
Support Mod
Support Mod


Joined: Jan 05, 2004
Posts: 1390

Location: Louisiana, USA

PostPosted: Thu May 27, 2004 9:01 am Reply with quoteBack to top

Well, this was just one of a few errors I encountered that made me decide to dump pnpNuke and go with CPGNuke.
As of right now, fortress isn't installed, nor is that link or module on my current site.

The question is, why is that link considered bad? Cuz I REALLY don't know another way to do that. I mean that's exactly how the link is in the modules block......and will I have the same problems if i use fortress with CPGNuke?

BTW, checked out your site one day......did you have to buy that dating module or is that offered on the net for free somewhere? Been hunting something like that for ages!!!!!

_________________
ImageImage
USE THE FORUM. If you contact me via messenger for support I will add you to my ignore list.
Find all posts by BrainSmashRView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN MessengerICQ Number
foxyfemfem
Support Staff
Support Staff


Joined: Jan 23, 2003
Posts: 668

Location: USA

PostPosted: Fri May 28, 2004 5:49 pm Reply with quoteBack to top

@BrainSmashR
The dating script is offered for free. I added a link to the script in the chit chat section with instruction on how to utilize it with phpnuke to keep users from registering twice.

The topic in the chit chat section is php match maker.

_________________
If you shoot for the moon and miss, you'll still be amongst the stars.
Find all posts by foxyfemfemView user's profileSend private message
American
Corporal
Corporal


Joined: Jan 17, 2003
Posts: 58


PostPosted: Mon May 31, 2004 6:59 am Reply with quoteBack to top

Our friends from Brazil visited one of my high profile sites last night:

Timestamp: Monday 31st of May 2004 01:35:54 AM
Logtime: 1085985354
Attack: UNION
Query: name=Web_Links&l_op=viewlink&cid=2 UNION select counter, pwd, aid FROM nuke_authors
Raw Query: name=Web_Links&l_op=viewlink&cid=2%20UNION%20select%20counter,%20pwd,%20aid%20FROM%20nuke_authors%20
Method: http://www.mysite.com/modules.php?name=Web_Links&l_op=viewlink&cid=2 UNION select counter, pwd, aid FROM nuke_authors
Raw Method: http://www.mysite.com/modules.php?name=Web_Links&l_op=viewlink&cid=2%20UNION%20select%20counter,%20pwd,%20aid%20FROM%20nuke_authors%20
Suspect Host: SHASTA162220.ig.com.br
Suspect IP: 200.151.162.220
Remote Port: 3587
Suspect Agents: Microsoft URL Control - 6.00.8862

Stopped em dead in their tracks, I then blocked their whole IP range. Thanks to Fortress I'm not wasting my day off fixing my site.

_________________
Brad
Find all posts by AmericanView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Mon May 31, 2004 8:26 am Reply with quoteBack to top

For future reference, it might be best to use "http://example.com" since it is a reserved real domain name.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.758 Seconds - 81 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::