Author |
Message |
deadl0ck
Hangin' Around
![](modules/Forums/images/avatars/Street_Fighter/Street_Fighter_-_Vega.gif)
Joined: Apr 09, 2006
Posts: 44
|
Posted:
Tue Jan 23, 2007 4:07 am |
|
Hi all,
One of the admins on my site keeps getting blocked.
Here's the details that NukeSentinal is reporting:
Code:
Blocked IP: none...*
User: Anonymous
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Blocked on: 2007-01-23 05:10:46
Notes: Added by NukeSentinel(tm)
Reason: Abuse-Union
Query String:
Get String:
Post String:
Forwarded For: none
Client IP: none
Remote Address: 190.38.180.203
Remote Port: 2612
Request Method: GET
|
Query String:
Get String:
Post String:
Any ideas as to why this keeps happening ? |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
montego
Site Admin
![](modules/Forums/images/avatars/0c0adf824792d6d341ef4.gif)
Joined: Aug 29, 2004
Posts: 9457
Location: Arizona
|
Posted:
Tue Jan 23, 2007 7:28 am |
|
If this IP address is truelly that of your admin, then why is he/she attempting to use a UNION attack on your site to show him/her all your admin usernames and passwords? |
_________________ Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! |
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
deadl0ck
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Tue Jan 23, 2007 8:39 am |
|
I doubt it's my admin - but I think the "none...*" IP address is blockig him from getting to the site
What is "none...*" ? |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
evaders99
Former Moderator in Good Standing
![](modules/Forums/images/avatars/803d73f6452557b947721.jpg)
Joined: Apr 30, 2004
Posts: 3221
|
Posted:
Wed Jan 24, 2007 12:42 am |
|
I'm not sure why it says "none", esp since it is recording an IP under Remote Address
190.38.180.203
What version of Sentinel are you using? |
_________________ - Only registered users can see links on this board! Get registered or login! -
Need help? Only registered users can see links on this board! Get registered or login! |
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
deadl0ck
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Wed Jan 24, 2007 2:15 am |
|
AT the top of the NS Admin PAGE I see:
NukeSentinel(tm) 2.4.2pl3
I assume that's the version ? |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Guardian2003
Site Admin
![](modules/Forums/images/avatars/125904890252d880f79f312.png)
Joined: Aug 28, 2003
Posts: 6799
Location: Ha Noi, Viet Nam
|
Posted:
Wed Jan 24, 2007 3:24 am |
|
You really need to update to the latest version but regardless of that, if that is the IP of your admin (you can cross reference his IP easily enough as its listed in his forum posts - its next to the quote / edit / delete buttons) that string does indicate he was attempting a union attack on your site.
The 'blocked ip= ' might be because the IP is protected - thats purely a guess as I dont have a copy of that specific version of Sentinel to check the code. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
deadl0ck
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Wed Jan 24, 2007 3:32 am |
|
He's posted from a few different IPs over a period of time, but the one listed above isn'tan address he's ever posted from - the vast majority of his posts are from the same IP.
What verision should I upgrade to ? The latest ? |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
Guardian2003
![](modules/Forums/images/avatars/gallery/blank.gif)
|
Posted:
Wed Jan 24, 2007 3:52 am |
|
Yes you should upgrade to the latest version.
If the IP address in the Sentinel email is not one your user has posted from AND given the fact that the user is listed as 'anonymous' (not logged in) I would be even more included to suspect the user was not an admin. |
|
|
|
![](themes/RavenIce/forums/images/spacer.gif) |
|