PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
klaafstra99
Hangin' Around


Joined: Feb 20, 2007
Posts: 32

PostPosted: Fri Feb 23, 2007 4:07 am Reply with quote Back to top

Hi All,

To start: slap (that was me hitting myself for installing 8.0) I didn't know better at the time.... but... now I do...!

Until 2.10 of Ravennuke is released, I would like to know if it's possible to patch 8.0 for disabling the user registration. I followed all the instructions on phpnuke.org and also disabled the link in my forum for registering.

By some SQL injection or PHP issue, some hackers (considering the domain names and emails used) are able to register. The apache logfile only reports a POST action in the your account module:

Quote:
84.19.182.23 - - [23/Feb/2007:06:11:27 +0100] "POST /ovh/modules.php?name=Your_Account HTTP/1.0" 200 19956 "http://ovh.dyndns.org/ovh/modules.php?name=Your_Account" "Mozilla/4.0 (compatible; ICS)"


Any suggestions? My site can be found here:
Only registered users can see links on this board!
Get registered or login to the forums!


Installing Sentinel would maybe help, but since 2.10 is almost released, I prefer to wait for that. Are there other known (easy to apply!) patches?

Greetings,

Martijn
View user's profile Send private message
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2749

PostPosted: Fri Feb 23, 2007 9:55 pm Reply with quote Back to top

Well here's a very simple fix

in modules/Your_Account/index.php
Add anywhere after the mainfile.php line
Code:

if ($op == "finish") {
die("Registration is disabled.");
}


Not the most user-friendly, but it should work
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum