PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
wrecit
Regular
Regular


Joined: Jan 27, 2008
Posts: 57

PostPosted: Tue Feb 05, 2008 9:17 pm Reply with quote Back to top

I have...... Well Sentinel has caught and blocked a few hack attempts on my site and I love it.

I do have one problem though. I am running HTTP Video stream modual and one of the features of this modual is members can submit videos to the site then the admin gets the request info in the admin panel and approves or denies the video.

When my members submit a video Sentinel does not allow the submition and I recieve this



Quote:
Date & Time: 2008-02-05 17:52:31 EST GMT -0500
Blocked IP: 205.188.116.130
User ID: miguel (6)
Reason: Abuse-Script
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; iebar; acc=vonner)
Query String: therectorboys.com/modules.php?name=Video_Stream&page=vidadd
Get String: therectorboys.com/modules.php?name=Video_Stream&page=vidadd
Post String: therectorboys.com/modules.php?title=king george speedway&category=8&description=the final Virginia pavement Divisional in jr stock&url=<object width=\"425\" height=\"355\"><param name=\"movie\" value=\"http://www.youtube.com/v/wlsDA2-Hy_k&rel=1\"></param><param name=\"wmode\" value=\"transparent\"></param><embed src=\"http://www.youtube.com/v/wlsDA2-Hy_k&rel=1\" type=\"application/x-shockwave-flash\" wmode=\"transparent\" width=\"425\" height=\"355\"></embed></object>&picurl=&thumbimg=&width=425&height=355&plugin=5&ADDIT=Add Video
Forwarded For: none
Client IP: none
Remote Address: 205.188.116.130
Remote Port: 37197
Request Method: POST
--------------------
Who-Is for IP


How can I fix this?
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15221
Location: Kansas

PostPosted: Wed Feb 06, 2008 1:34 am Reply with quote Back to top

Try this. Edit includes/nukesentinel.php.

FIND:
if (stristr($qs,'name=Forums')!==false && stristr($qs,'file=posting')!==false && (strtolower($qsName[0])=="private_messages" || strtolower($qsName[0])=="forums")) {

CHANGE TO:
if (stristr($qs,'name=Video_Stream')!==false || stristr($qs,'name=Forums')!==false && stristr($qs,'file=posting')!==false && (strtolower($qsName[0])=="private_messages" || strtolower($qsName[0])=="forums")) {

Should this work, there are security implications which I will discuss after you reply back.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
wrecit
Regular
Regular


Joined: Jan 27, 2008
Posts: 57

PostPosted: Sun Apr 27, 2008 12:27 pm Reply with quote Back to top

ok Raven it took me a while to get back to my site (real world job gave no time)

I just made the code modifycation and going to have some friends submit a video today

Now how bad have I just opened my site to hacking lol
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum