Author |
Message |
akis
New Member


Joined: Jun 11, 2004
Posts: 9
|
Posted:
Fri Jun 11, 2004 4:27 pm |
|
i have installed sentinel and before some minutes i took 4-5 mails :
Blocked IP : xxxxxxxxxx
User ID : Anonymous (1)
Reason : Abuse - SCRIPT
User Agent : ia_archiver
Query String : http://www.mysite.com/modules.php?name=Forums&file=profile&mode=viewprofile&u=40\"STYLE=\"text-decoration:
Remote Port :
Request Method : GET
All has the same query string but different userids(u=40, u=3 etc) and all are in different Remote Ports.
Can someone tell me what is this, if it is dangerous or else?
Tnx |
|
|
|
 |
sixonetonoffun
Spouse Contemplates Divorce

Joined: Jan 02, 2003
Posts: 2496
|
Posted:
Fri Jun 11, 2004 4:36 pm |
|
What is causing the style tag to be in your url? Thats why its flagged as a script attack? I have assume something is not normal about your profiles config there is no reason for the style tag to be in the url normally. |
|
|
|
 |
akis

|
Posted:
Fri Jun 11, 2004 4:43 pm |
|
well, i don't understand that you say about something not normal in profile config.
It is the first time i see that, in the sentinel's mail. When i go to my site's forum user profiles all are ok, it doesn't show this strange thing with Style tag.
any idea? |
|
|
|
 |
sixonetonoffun

|
Posted:
Fri Jun 11, 2004 4:54 pm |
|
|
|
 |
akis

|
Posted:
Fri Jun 11, 2004 5:05 pm |
|
yes, it should be this, and i think it is, because there is nowhere such a link in my site. All forum profile links there are in my site, i checked all now, are ok, without the "STYLE=\"text-decoration: .
it is really strange this, i can't understand why.
anyway, i hope not to be dangerous, and thank you very much for the replys:) |
|
|
|
 |
akis

|
Posted:
Fri Jun 11, 2004 5:53 pm |
|
Quote: | I would guess somewhere in your site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration: |
i have the default subSilver theme for my forum and my site's theme doesn't have the code text-decoration nowhere, except the style.css file, but even this theme is one of the defaults of phpnuke.
In other modules, blocks etc, there are no forum profile links.
So, what is happening? i am confused, i don't want to ban something without reason  |
|
|
|
 |
Raven
Site Admin/Owner

Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Fri Jun 11, 2004 6:03 pm |
|
Just a quick note, the UserAgent is also banned if you are using the Harvester option. That leads me to believe this is something you want banned. |
|
|
|
 |
akis

|
Posted:
Sat Jun 12, 2004 3:22 am |
|
Raven, i have the Harvester option Off. |
|
|
|
 |
Raven

|
Posted:
Sat Jun 12, 2004 4:45 am |
|
Raven wrote: | Just a quick note, the UserAgent is also banned if you are using the Harvester option. That leads me to believe this is something you want banned. | Note, I said if you are using the Harvester option. I was just alerting you that it would have been caught HAD you been using it. Regardless, I don't know why you want your site raped, but that's your business  |
|
|
|
 |
akis

|
Posted:
Sat Jun 12, 2004 9:46 am |
|
raven, sorry my english are not very good, and i don't understand you very well.
i have harvest option off because when i have it on, my site is very slow.
about the http://www.mysite.com/modules.php?name=Forums&file=profile&mode=viewprofile&u=40\"STYLE=\"text-decoration:
sixonetonoffun said that maybe this is something not normal about profiles config. somewhere in site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration:
is there any explanation of what is and why is banned? because as i told in previous post, there is no such a link in my site nowhere.
This was a Script abuse, you say that i have to have the harvest option on, and that was happened was a "rape" attempt of my site from a crawler?
give me your lights  |
|
|
|
 |
sixonetonoffun

|
Posted:
Sat Jun 12, 2004 10:18 am |
|
style= is banned because style attributes can be used to enable script based attacks. cookie harvesting and redirections are very common abuses of style=. |
|
|
|
 |
akis

|
Posted:
Sat Jun 12, 2004 12:08 pm |
|
|
|
 |
Raven

|
Posted:
Sat Jun 12, 2004 12:27 pm |
|
There should never be this type of query, so whether it is a hack attempt or not, it isn't a natural query from nuke. |
|
|
|
 |
akis

|
Posted:
Sat Jun 12, 2004 3:02 pm |
|
ok, thanks
but it is strange, isn't it? |
|
|
|
 |
sixonetonoffun

|
Posted:
Sat Jun 12, 2004 5:16 pm |
|
I'd check out all your user blocks because that looks like a line from block-Forums.php to me or one of the custom versions of it.
Here is another example of where bad urls like that come from this user posted a nice html formated story at http://www.thebix.com/Sections-article2-p1.phtml but as you can see there are a lot of nasty urls in there that are probably being parsed by not so smart search engines like the notorious ia_archiver!
If links to one of our sites get hosed like that we may find this happening a lot. Even if the site allowed html I'm sure they don't allow usuage of styles like this submitted from users. |
|
|
|
 |
akis

|
Posted:
Sat Jun 12, 2004 6:01 pm |
|
sixonetonoffun, i found the ("STYLE=\"text-decoration: none) in a scroll forum block i have, but i have it visible only for administrators, and i don't have any other forum block or else, visible to all, with that code inside.
I thought that crawlers can't "see" "only for administrators" things.
Anyway, i put out this code from that block, even noone can see it.
Thank you very much again for the help, i appreciate it  |
|
|
|
 |
Raven

|
Posted:
Sat Jun 12, 2004 6:45 pm |
|
Crawlers will see everything they want to. Even robots.txt are on an "if you want to abide by" agreement. They do not have to honor them. That's why we usually ban them  |
|
|
|
 |
|