Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
AndyB
Worker
Worker



Joined: Jun 03, 2004
Posts: 231
Location: Torrevieja, Spain

PostPosted: Wed Jul 07, 2004 6:31 am Reply with quote

Hi guys;

one of my site admins did something the other day (not sure what) but he triggered Sentinel. The whole lot with pop ups- and it locked up his PC.

He's got Norton on it as well, and it started complaining about virus, etc (which I am not bothered about)

Now the thing is, we expected to get an email with details of the attempted "hack"- nothing. His IP wasn't blocked either, so I am somewhat slightly confused....

I can't give you more details, because we didn't get the email.... Rolling Eyes

Any ideas?

Most sections of Sentinel are set to email me only, unless it's union type attack....

Any feedback is welcome!
 
View user's profile Send private message
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Wed Jul 07, 2004 6:44 am Reply with quote

Hard to diagnose since you don't know what he did. My guess would be that whatever he did got caught by one of the settings that you don't have flagged as email. He may have triggered the UNION attack.
 
View user's profile Send private message
AndyB







PostPosted: Wed Jul 07, 2004 4:00 pm Reply with quote

This was my first thought;

but then why no email? why wasn't he banned/ blocked? (IP address has not showed up through sentinel OR admin secure....) Question
 
Raven







PostPosted: Wed Jul 07, 2004 4:14 pm Reply with quote

Raven wrote:
Hard to diagnose since you don't know what he did. My guess would be that whatever he did got caught by one of the settings that you don't have flagged as email. He may have triggered the UNION attack.
As I said, it may have been caught by one of your settings that you don't have set to email you.
 
HauntedWebby
Involved
Involved



Joined: May 19, 2004
Posts: 363
Location: Ogden, UT

PostPosted: Mon Jul 12, 2004 2:53 pm Reply with quote

On one of my sites I didn't have the correct path to the .htaccess set ... so a bad visitor would get the screen pop ups, I'd get emailed, and the IP would show up in the database ... but they were not receiving the forbidden access to the site. So check your path in the admin.

Also do you have your "contact" set to a good email addy? The system doesn't put that in automatically. Maybe that's why no email. If you have it, only 1 per line. Smile

Email Only (from what I understand, so don't quote me) doesn't block anything just sends an email letting you know that something happened. I have Author and Script set to email only, all others block, email & background.

Very Happy

_________________
--Webby-- 
View user's profile Send private message Send e-mail
Raven







PostPosted: Mon Jul 12, 2004 3:19 pm Reply with quote

HW, you need to have Author set to KILL! That's one of the worst ones.
 
HauntedWebby







PostPosted: Tue Jul 13, 2004 11:31 am Reply with quote

Really ... I thought that was just for the people I set as authors?!?

So if I set to Kill will a little .45 pop out the screen and shoot the bugger ... lol
 
Raven







PostPosted: Tue Jul 13, 2004 11:43 am Reply with quote

That's for the Authors exploit that is destroying many nuke sites right now.
 
cprompt
Regular
Regular



Joined: Jun 08, 2004
Posts: 64

PostPosted: Tue Jul 13, 2004 7:10 pm Reply with quote

Little HELP!?

well, I have a problem very much related to the original post in this topic.

I was blocked from my own site after trying to administer my Gallery. I am using Gallery from Menalto. 1.4.2. I was adding a New nested Album under an existing album.
Here is the info on why I was blocked by sentinel..By the way, those POP UPS are VICIOUS!!!
But, in WinXP you can simply right click the group of Icons on your task bar and close the whole group Wink

Anyone care to ponder why I was blocked?

Quote:
Blocked IP: 68.249.105.194
User: Anonymous
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Abuse Blocked on: 2004-07-13 17:58:59
Notes: Added by Sentinelâ„¢
Reason: Abuse - OTHER

Query String: www.mysite.org/modules.php?parentName=MYALBUM&return=modules.php%3Fop%3Dmodload%26name%3Dgallery%26file%3Dindex%26include%3Dview_album.php&cmd=new-album&op=modload&name=gallery&file=index&include=do_command.php
Forwarded For: none
Client IP: none
Remote Address: 68.249.105.194
Remote Port: 62815
Request Method: GET


After I hit the drop down the add a new album..BAMMO..POP UPS EVERYWHERE and then I could no longer access the site. I simply reset my DSL modem to change my IP and got back in, but thought I should let you all know about this if it hasn't already come up before.

The other funny thing I just noticed, NONE of my settings are set to hit the "hacker" with POP UPS. They are all set to Block and email...So why did I get the pop up killers on me???

Using Sentinel 1.2.0

WELL, I just got blocked AGAIN!
Quote:
Date & Time: 2004-07-13 18:36:20
Blocked IP: 68.251.105.233
User ID: Anonymous (1)
Reason: Abuse - OTHER
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Query String: www.mysite.org/modules.php?set_fullOnly=off&return=modules.php%3Fid%3D0_012_12%26op%3Dmodload%26name%3Dgallery%26file%3Dindex%26include%3Dview_photo.php&cmd=&op=modload&name=gallery&file=index&include=do_command.php
Forwarded For: none
Client IP: none
Remote Address: 68.251.105.233
Remote Port: 63647
Request Method: GET


this is getting kooky! Bang Head
This time I was trying to modify an Albums properties.


Last edited by cprompt on Tue Jul 13, 2004 10:10 pm; edited 1 time in total 
View user's profile Send private message
Raven







PostPosted: Tue Jul 13, 2004 9:09 pm Reply with quote

This has been well discussed Bang Head but, being the nice person that I am and that you are ROTFL --- http://www.ravenphpscripts.com/postt1861.html Smile
 
cprompt







PostPosted: Tue Jul 13, 2004 10:08 pm Reply with quote

ARGH!. Again, my haste is premature. Rolling Eyes
I apoligize and thank you for your help. Very Happy
At the very least, we created more search results for others with the same or similar problem Razz

and better yet...
http://www.ravenphpscripts.com/postt1796.html
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©