Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> v2.30.01 RN Security Issues
Author Message
fkelly
Former Moderator in Good Standing



Joined: Aug 30, 2005
Posts: 3312
Location: near Albany NY

PostPosted: Thu Aug 13, 2009 3:15 pm Reply with quote

Here's a good one. Say you have RNYA set up to block an email domain such as mail.ru (just for instance). Now you have the string blocker in Nuke Sentinel set to block mail.ru also.

Now you go into RNYA to make a configuration change of any kind. You submit it and bammo you are banned from your site ... or if you have a protected IP you still get the Sentinel warning screen and your changes don't go through. Problem is that all the configuration settings are sent as a POST string and Sentinel filters through all that looking for offending strings.

Solution: deactivate the string blocker in NS, at least temporarily.
 
View user's profile Send private message Visit poster's website
Palbin
Site Admin



Joined: Mar 30, 2006
Posts: 2583
Location: Pittsburgh, Pennsylvania

PostPosted: Thu Aug 13, 2009 3:32 pm Reply with quote

My feelings are if the admin/user is smart enough to be doing these things than it is their responsibility to set it up right.

_________________
"Debugging is twice as hard as writing the code in the first place. Therefore, if you write the code as cleverly as possible, you are, by definition, not smart enough to debug it." — Brian W. Kernighan.

Last edited by Palbin on Thu Aug 13, 2009 4:56 pm; edited 1 time in total 
View user's profile Send private message
Susann
Moderator



Joined: Dec 19, 2004
Posts: 3191
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Thu Aug 13, 2009 4:25 pm Reply with quote

Yeah, I know this problem but this shows only how good the string blocker works and I would never deactivate this blocker from one of my site where I don´t have the .ru e-mails in RNYA. Its like Palbin said you are the (web)master of your site. So you need to be smart and flexible. You have all options it up to you to make the best of it. Smile
 
View user's profile Send private message
fkelly







PostPosted: Thu Aug 13, 2009 5:19 pm Reply with quote

I agree with both of you (Susann and Palbin). However, Sentinel has been around for years whereas RNYA is relatively recent. So it's likely that someone who wants to block "mail.ru" would wind up with it in both places. And it's not like NS gives you a message: "string: "mail.ru" has been blocked" ... you have to parse through a pretty long post string to find out what's going on. So I just thought I'd post this in case anyone down the road runs into it.
 
kguske
Site Admin



Joined: Jun 04, 2004
Posts: 6437

PostPosted: Fri Aug 14, 2009 5:57 am Reply with quote

It's unlikely that you'd end up in both place (unless one of them did not work).

_________________
I search, therefore I exist...
Only registered users can see links on this board! Get registered or login!
 
View user's profile Send private message
montego
Site Admin



Joined: Aug 29, 2004
Posts: 9457
Location: Arizona

PostPosted: Fri Aug 14, 2009 9:14 am Reply with quote

It happened to me when I upgraded to 2.3.0 awhile back. I had mail.ru in my string blocker for a few years prior to that and forgot about it. Then, I went to add a new domain in RNYA to block, and got the NS ban message for the string blocker.

I don't know that we should do anything about it other than maybe create a sticky under a NukeSentinel forum? Just wanted you to know kguske that it is a real issue, but born out of "legacy".

_________________
Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website
fkelly







PostPosted: Fri Aug 14, 2009 9:24 am Reply with quote

I think that having this thread here is probably enough ... in terms of doing anything about it. Anyone searching should find it ... 6 months from now or a year or whatever. And yes, it is a real issue and you don't have to be doing anything with a domain to come across it, any kind of configuration change in RNYA is likely to kick it off. Someday it would be nice to make the NS messages more targeted: to tell you exactly what POST string or regular string it objects to but that's a different topic and not needed immediately.
 
kguske







PostPosted: Fri Aug 14, 2009 9:25 am Reply with quote

OK, but it it is born out of legacy. New users won't use the string blocker to prevent registration - logically, the configuration for that is in RNYA. It's only you old fogies who are using string blockers for that unusual purpose... Smile
 
spasticdonkey
RavenNuke(tm) Development Team



Joined: Dec 02, 2006
Posts: 1693
Location: Texas, USA

PostPosted: Fri Aug 14, 2009 11:55 am Reply with quote

I doubt the majority of sentinel users even take the time to use string blockers at all.. I think a sticky thread would suffice.
 
View user's profile Send private message Visit poster's website
montego







PostPosted: Sat Aug 22, 2009 7:45 am Reply with quote

This is now a Sticky.
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> v2.30.01 RN Security Issues

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©