Author |
Message |
Dove
New Member
data:image/s3,"s3://crabby-images/ef8c6/ef8c6ffa100d312c50401bab15b4ce4a32abb82a" alt="New Member New Member"
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
Joined: Jun 29, 2004
Posts: 11
Location: USA
|
Posted:
Thu Jun 09, 2005 3:54 am |
|
Hello,
First I'd like to say what a pleasure it always is
browsing your forums.
After installing a fresh Sentinel 2.30 on a Nuke 7.7
web with 3.0 patches, I received a white page (on the main
page- index) with Firefox 1.04, Netscape 7.2, & Opera. All but
IE (for once ). Hitting the "refresh" button loads the page and all is fine.
I checked my server logs and saw this warning:
PHP Warning: ob_start(): output handler 'ob_gzhandler' cannot be used after 'URL-Rewriter' in /home/mysite/public_html/mainfile.php on line 54
The site was fine until installing Sentinel 2.30.
I did see a similar post Only registered users can see links on this board! Get registered or login!
and changing the 3.0 patched code from:
Code:ob_start(array('ob_gzhandler',5));
ob_implicit_flush(0);
header('Content-Encoding: gzip');
|
back to the original as Chatserv suggested:
Code:ob_start();
ob_implicit_flush(0);
//header('Content-Encoding: gzip');
|
Fixed it.
Hope this helps someone that adds Sentinel after the patch.
My server specs
Linux - apache 1.3.33
php 4.3.11 |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sting
Involved
data:image/s3,"s3://crabby-images/3cd78/3cd78967c414f04954d45e6ce61327baab00aa18" alt="Involved Involved"
data:image/s3,"s3://crabby-images/2ac12/2ac12005ceb8c9f1c233d9207b1998e53cbf7c66" alt=""
Joined: Sep 23, 2003
Posts: 456
Location: Somewhere out there...
|
Posted:
Sat Jun 18, 2005 10:03 pm |
|
Thanks much! I am having this same issue on one of my sites, great to know the fix.
-sting |
|
|
data:image/s3,"s3://crabby-images/348fa/348faa7637669e431c5c44a9a0e9797dbaaa7c64" alt="ICQ Number ICQ Number" |
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
Site Admin/Owner
data:image/s3,"s3://crabby-images/f1ebe/f1ebec6bf773a9d94054cd575831abd5c29229a5" alt=""
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Sat Jun 18, 2005 11:49 pm |
|
You might also try moving this codeCode:if (defined('FORUM_ADMIN')) {
@include_once("../../../includes/nukesentinel.php");
} elseif (defined('INSIDE_MOD')) {
@include_once("../../includes/nukesentinel.php");
} else {
@include_once("includes/nukesentinel.php");
}
|
afterCode:$phpver = phpversion();
if ($phpver < '4.1.0') {
$_GET = $HTTP_GET_VARS;
$_POST = $HTTP_POST_VARS;
$_SERVER = $HTTP_SERVER_VARS;
}
if ($phpver >= '4.0.4pl1' && strstr($_SERVER["HTTP_USER_AGENT"],'compatible')) {
if (extension_loaded('zlib')) {
ob_end_clean();
ob_start('ob_gzhandler');
}
} else if ($phpver > '4.0') {
if (strstr($HTTP_SERVER_VARS['HTTP_ACCEPT_ENCODING'], 'gzip')) {
if (extension_loaded('zlib')) {
$do_gzip_compress = TRUE;
ob_start(array('ob_gzhandler',5));
ob_implicit_flush(0);
header('Content-Encoding: gzip');
}
}
}
$phpver = explode(".", $phpver);
$phpver = "$phpver[0]$phpver[1]";
if ($phpver >= 41) {
$PHP_SELF = $_SERVER['PHP_SELF'];
}
|
in mainfile.php. Let me know if that works and I will add this to the NukeSentinel FAQ. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
infidelguy
Hangin' Around
data:image/s3,"s3://crabby-images/5fd11/5fd117e3e1e14c3e0dc5f15d485ed659146b0470" alt=""
Joined: May 25, 2005
Posts: 26
Location: Atlanta, Georgia
|
Posted:
Tue Jun 21, 2005 10:04 am |
|
Raven, this fixed my problem:
Mac users using Solaris also had a problem, their problem is gone too! The error they were getting is: nsurl-error domain 1011.
Thanks! |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
infidelguy
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 11:31 am |
|
Oh wait! Hey Raven or Bob, now that I have made these changes. I no longer get a blocked page notification when I conduct a union attack.
Help please? |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 11:55 am |
|
Please post your first 100 lines or so of mainfile.php. That should not stop Sentinel. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
infidelguy
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 12:12 pm |
|
I made the changes as recommended by Dove and it works now. Possibly less secure I'm sure. Here is my current mainfile.php
Code:
<?php
if (defined('FORUM_ADMIN')) {
@include_once("../../../includes/nukesentinel.php");
} elseif (defined('INSIDE_MOD')) {
@include_once("../../includes/nukesentinel.php");
} else {
@include_once("includes/nukesentinel.php");
}
if (!ini_get("register_globals")) {
import_request_variables('GPC');
}
/************************************************************************/
/* PHP-NUKE: Advanced Content Management System */
/* ============================================ */
/* */
/* Copyright (c) 2002 by Francisco Burzi */
/* http://phpnuke.org */
/* */
/* This program is free software. You can redistribute it and/or modify */
/* it under the terms of the GNU General Public License as published by */
/* the Free Software Foundation; either version 2 of the License. */
/************************************************************************/
/* Additional security checking code 2003 by chatserv */
/* http://www.nukefixes.com -- http://www.nukeresources.com */
/************************************************************************/
define('NUKE_FILE', true);
if (file_exists("includes/custom_files/custom_mainfile.php")) {
include_once("includes/custom_files/custom_mainfile.php");
}
//Union Tap
//Copyright Zhen-Xjell 2004 http://nukecops.com
//Beta 3 Code to prevent UNION SQL Injections
unset($matches);
unset($loc);
if (preg_match("/([OdWo5NIbpuU4V2iJT0n]{5}) /", rawurldecode($loc=$_SERVER["QUERY_STRING"]), $matches)) {
die();
}
$queryString = strtolower($_SERVER['QUERY_STRING']);
if (stripos_clone($queryString,'%20union%20') OR stripos_clone($queryString,'/*') OR stripos_clone($queryString,'*/union/*') OR stripos_clone($queryString,'c2nyaxb0')) {
header("Location: index.php");
die();
}
$phpver = phpversion();
if ($phpver < '4.1.0') {
$_GET = $HTTP_GET_VARS;
$_POST = $HTTP_POST_VARS;
$_SERVER = $HTTP_SERVER_VARS;
}
if ($phpver >= '4.0.4pl1' && strstr($_SERVER["HTTP_USER_AGENT"],'compatible')) {
if (extension_loaded('zlib')) {
ob_end_clean();
ob_start('ob_gzhandler');
}
} else if ($phpver > '4.0') {
if (strstr($HTTP_SERVER_VARS['HTTP_ACCEPT_ENCODING'], 'gzip')) {
if (extension_loaded('zlib')) {
$do_gzip_compress = TRUE;
ob_start();
ob_implicit_flush(0);
//header('Content-Encoding: gzip');
}
}
}
$phpver = explode(".", $phpver);
$phpver = "$phpver[0]$phpver[1]";
if ($phpver >= 41) {
$PHP_SELF = $_SERVER['PHP_SELF'];
}
if(isset($admin))
{
$admin = base64_decode($admin);
$admin = addslashes($admin);
$admin = base64_encode($admin);
}
if(isset($user))
{
$user = base64_decode($user);
$user = addslashes($user);
$user = base64_encode($user);
}
foreach ($_GET as $sec_key => $secvalue) {
if ((eregi("<[^>]*script*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*object*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*iframe*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*applet*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*meta*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*style*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*form*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*img*\"?[^>]*>", $secvalue)) ||
(eregi("<[^>]*onmouseover*\"?[^>]*>", $secvalue)) ||
(eregi("\([^>]*\"?[^)]*\)", $secvalue)) ||
|
|
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 12:16 pm |
|
Change it back as I instructed. Then remove this codeCode://Union Tap
//Copyright Zhen-Xjell 2004 http://nukecops.com
//Beta 3 Code to prevent UNION SQL Injections
unset($matches);
unset($loc);
if (preg_match("/([OdWo5NIbpuU4V2iJT0n]{5}) /", rawurldecode($loc=$_SERVER["QUERY_STRING"]), $matches)) {
die();
}
$queryString = strtolower($_SERVER['QUERY_STRING']);
if (stripos_clone($queryString,'%20union%20') OR stripos_clone($queryString,'/*') OR stripos_clone($queryString,'*/union/*') OR stripos_clone($queryString,'c2nyaxb0')) {
header("Location: index.php");
die();
}
|
That's in the installation instructions, btw. That's what's blocking NukeSentinel. You don't need it. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
infidelguy
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 12:49 pm |
|
Hi Raven and thank you for you patience and kindness,
Everything works fine now.
In your instructions at section 4, you start talking about Upgrading. This lead me to think that everything else was about upgrading, which it obviously was not. So I ignored that part.
I apologize for not understanding.
Thanks, everything is gold. data:image/s3,"s3://crabby-images/92c12/92c1280436c38d9d430ded7042e0373008760263" alt="Smile" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Dove
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 2:19 pm |
|
That worked perfect Raven, thank you. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 4:04 pm |
|
infidelguy wrote: | Hi Raven and thank you for you patience and kindness,
Everything works fine now.
In your instructions at section 4, you start talking about Upgrading. This lead me to think that everything else was about upgrading, which it obviously was not. So I ignored that part.
I apologize for not understanding.
Thanks, everything is gold. | Hey! No aplogy needed. We keep tweaking the ReadMe to make it better. Thanks for the feedback! |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 4:05 pm |
|
Dove wrote: | That worked perfect Raven, thank you. |
data:image/s3,"s3://crabby-images/2dabb/2dabba8c5907cf3f55a360a6d072ddd29e8d360e" alt="RavensScripts" |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
sting
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Tue Jun 21, 2005 9:03 pm |
|
Ahhh Union Tap.
The Spiders! Get them off me.
It was fun though for a while there...
-sting |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
MarkyBear
Hangin' Around
data:image/s3,"s3://crabby-images/1580a/1580af85666ac9236f73d5e66f8ad49c69d1f227" alt=""
Joined: Mar 27, 2005
Posts: 39
|
Posted:
Sat Jun 25, 2005 10:43 am |
|
This did the trick for me too, although the codeing was a little different for some reason in my mainfile, I just added it after the:
Code: $PHP_SELF = $_SERVER['PHP_SELF'];
}
|
and it's worked fine with no more errors!
Thanks Raven!! |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Sfolivier
New Member
data:image/s3,"s3://crabby-images/ef8c6/ef8c6ffa100d312c50401bab15b4ce4a32abb82a" alt="New Member New Member"
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
Joined: Jun 29, 2005
Posts: 15
|
Posted:
Sun Jul 10, 2005 2:01 pm |
|
I moved
Code:if (defined('FORUM_ADMIN')) {
@include_once("../../../includes/nukesentinel.php");
} elseif (defined('INSIDE_MOD')) {
@include_once("../../includes/nukesentinel.php");
} else {
@include_once("includes/nukesentinel.php");
}
|
as instructed and it solved the problem for me as well (just in case you're still wondering if it's FAQ material).
Thanks for the tip (I don't count how many times this forum helped me). |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sun Jul 10, 2005 4:08 pm |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
Client
data:image/s3,"s3://crabby-images/9c5de/9c5de1fb44bb401d0af74a4b7aa27d0145ec3539" alt=""
Joined: Oct 07, 2003
Posts: 735
Location: Ohio
|
Posted:
Fri Jul 22, 2005 10:53 pm |
|
Well I have read this thread and others but cannot get the site back up. Fresh install of 7.6 v3.0b with NukeSentinel_71-78_232. Restored the original edited files but it is still blank.
I run the old analyze.php and I have a good connection.
This is my third time installing Sentinal. You would think I would get it right.
I have yet to run the nsnst.php as I have yet to get the site up again. I uploaded all the files along with the edited filed and the site went blank before I ran the nsnst.php
I tried to clear cookies but no good. I even tried to run the nsnst.php regardless but no joy. |
|
|
data:image/s3,"s3://crabby-images/348fa/348faa7637669e431c5c44a9a0e9797dbaaa7c64" alt="ICQ Number ICQ Number" |
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Fri Jul 22, 2005 11:10 pm |
|
Take NukeSentinel out of the picture. Drop the database and delete all the files. Then, reload the files w/o NS and recreate the database. Does the site come up? What site is it? |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 10:11 am |
|
I can't drop the database as it was an import of around 60 users of a PHPBB site. Everything was working perfectly until I tried to install Sentinal. Before I had a chance to run the nsnst.php I had a blank page.
http://www.1st-infantry-division.net |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Raven
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 10:16 am |
|
What is the error log showing? Are you sure the MySQL parameters are correct? |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 10:20 am |
|
[23-Jul-2005 00:20:47] PHP Fatal error: main(): Failed opening required 'mainfile.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/bcring/public_html/modules.php on line 20 |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 10:21 am |
|
Another one
[23-Jul-2005 00:20:47] PHP Warning: main(mainfile.php): failed to open stream: No such file or directory in /home/bcring/public_html/modules.php on line 20 |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 10:26 am |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 10:37 am |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
Donovan
data:image/s3,"s3://crabby-images/36d40/36d40b188683741fe5e6b5dfea59b2ece7005bfb" alt=""
|
Posted:
Sat Jul 23, 2005 11:04 am |
|
Well the site is back up without Sentinal. A remaining bug is now I have no messages on the front page. I had one programmed with unlimited expiration but I don't see it any more. I deleted and redid it but still nothing. Cleared cookies but again not seeing the front page message. |
|
|
|
data:image/s3,"s3://crabby-images/16ec9/16ec9a13e8037e9930f6eefae5701d6108566c64" alt="" |
|