PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15213
Location: Kansas

PostPosted: Tue Jan 10, 2006 8:02 am Reply with quote Back to top

It has come to my attention (thanks Foggy) that the CGI Auth routines were not always honoring the NukeSentinel(tm) admin username. depending on how the .staccess file was created, NukeSentinel(tm) was mistakenly using the nuke_authors table aid column. As a result, you could never get a match for security.

To correct this, you need to modify 1 line in 2 different files.

Edit admin/modules/nukesentinel/ABAuthEditSave.php
FIND
$stwrite .= $adminrow['aid'].":".$adminrow['password_crypt']."\n";

CHANGE TO
$stwrite .= $adminrow['login'].":".$adminrow['password_crypt']."\n";


Edit admin/modules/nukesentinel/ABCGIBuild.php
FIND
$stwrite .= $adminrow['aid'].":".$adminrow['password_crypt']."\n";

CHANGE TO
$stwrite .= $adminrow['login'].":".$adminrow['password_crypt']."\n";

This will be corrected in the next release of NukeSentinel(tm)

This will be referred to as v2.4.2pl3 until we release v2.4.3
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15213
Location: Kansas

PostPosted: Tue Jan 10, 2006 9:51 am Reply with quote Back to top

I have also made a download patch available from
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
djrino
Hangin' Around


Joined: Mar 11, 2005
Posts: 44

PostPosted: Tue Jan 10, 2006 1:52 pm Reply with quote Back to top

Hi raven many tnx fo suppor to sentinel..
i don't find the v2.4.2pl3 i have take a look on nukescript and here but nothing where is the v2.4.2pl3????

Many tnx
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15213
Location: Kansas

PostPosted: Tue Jan 10, 2006 2:30 pm Reply with quote Back to top

In the post right above yours is the link.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
djrino
Hangin' Around


Joined: Mar 11, 2005
Posts: 44

PostPosted: Tue Jan 10, 2006 2:37 pm Reply with quote Back to top

this is a upgrade file s not a full version
i dont' find the full versios v2.4.2pl3 to make this fix
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15213
Location: Kansas

PostPosted: Tue Jan 10, 2006 2:44 pm Reply with quote Back to top

The full version v2.4.2 is available from
Only registered users can see links on this board!
Get registered or login to the forums!
You will still need to apply this patch.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
djrino
Hangin' Around


Joined: Mar 11, 2005
Posts: 44

PostPosted: Tue Jan 10, 2006 2:46 pm Reply with quote Back to top

Ok many tnx Smile
View user's profile Send private message
rino
New Member
New Member


Joined: Dec 06, 2005
Posts: 12

PostPosted: Tue Jan 10, 2006 5:11 pm Reply with quote Back to top

Ciao Raven,

on the download patch i see 3 files and not 2.
-admin/modules/nukesentinel/ABAuthEditSave.php
-admin/modules/nukesentinel/ABCGIBuild.php
-includes/nukesentinel.php

Wich its correct patch? 2 files or 3 files?
Thanks for your big work!
Rino
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15213
Location: Kansas

PostPosted: Tue Jan 10, 2006 5:26 pm Reply with quote Back to top

All 3 - it is a cumulative patch
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum