PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Doulos
Involved
Involved


Joined: Jun 06, 2005
Posts: 367

PostPosted: Fri Jan 19, 2007 11:49 pm Reply with quote Back to top

Twice today I got this in my email (second time had different IP address):

Quote:
Date & Time: 2007-01-19 18:26:32 CST GMT -0600
Blocked IP: 64.251.10.133
User ID: Anonymous (1)
Reason: Abuse-CLike

User Agent: libwww-perl/5.803
Query String: clanfga.com/modules.php?

name=Search&type=comments&query=not123exists&instory=/**/UNION/**/SELECT/**/0,0,pwd,0,aid/**/FROM/**/nuke_authors
Get String: clanfga.com/modules.php?name=Search&type=comments&query=not123exists&instory=/**/UNION/**/SELECT/**/0,0,pwd,0,aid/**/FROM/**/nuke_authors


Post String: clanfga.com/modules.php
Forwarded For: none
Client IP: none
Remote Address: 64.251.10.133
Remote Port: 34935
Request Method: GET




Is this something I need to worry about? Never had anyone blocked for Abuse-CLike before.
View user's profile Send private message
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 4821

PostPosted: Sat Jan 20, 2007 1:15 am Reply with quote Back to top

The block occured because someone used a union attack in an atempt to retrieve the admins user/password. Sentinel will protect you from these types of attack.
View user's profile Send private message Send e-mail Visit poster's website
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2846

PostPosted: Sun Jan 21, 2007 12:51 am Reply with quote Back to top

Yep this is a known (old) vulnerablilty. Don't worry about it, if you are up-to-date with patches and Sentinel, you are fine.
View user's profile Send private message Visit poster's website
warren-the-ape
Worker
Worker


Joined: Nov 19, 2007
Posts: 177
Location: Netherlands

PostPosted: Sat Jan 12, 2008 2:40 pm Reply with quote Back to top

Got this one today as well. Our 1st Clike attack Cool

This dude (IP:83.20.148.210, email;
Only registered users can see links on this board!
Get registered or login to the forums!
) even registred on our website/forum..

Code:
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/523.15 (KHTML, like Gecko) Version/3.0 Safari/523.15

Query String: website.com/modules.php?name=Search
&type=comments
&query=not123exists
&instory=/* */UNION/* */SELECT/* */0,0,pwd,0,aid/* */FROM/* */nuke_authors

Get String: website.com/modules.php?name=Search
&type=comments
&query=not123exists
&instory=/* */UNION/* */SELECT/* */0,0,pwd,0,aid/* */FROM/* */nuke_authors

Post String: website.com/modules.php


But are these attacks already blocked by a patched php-nuke version?
Cause when installing NS i remembered seeing some 'Union' code in some of the nuke files.
View user's profile Send private message
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2846

PostPosted: Sat Jan 12, 2008 11:18 pm Reply with quote Back to top

Oh yea this is an old one. It is patched already
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum