Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> phpnuke 7.6
Author Message
mrix
Client



Joined: Dec 04, 2004
Posts: 757

PostPosted: Mon Sep 26, 2005 9:20 am Reply with quote

Hi all, I have finally managed to install the latest patch 3.1 nad the latest sentinal but I keep receiving emails like this

Date & Time: 2005-09-26 10:24:58 EDT GMT -0400
Blocked IP: 86.128.85.123
User ID: Visitor (1)
Reason: Abuse-Script
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Query String:
www.sea-fishing.org/modules.php?name=Downloads&d_op=viewdownload&cid=1(\"derby=hitsD
Get String:
www.sea-fishing.org/modules.php?name=Downloads&d_op=viewdownload&cid=1(\"derby=hitsD
Post String: www.sea-fishing.org/modules.php
Forwarded For: none
Client IP: none
Remote Address: 86.128.85.123
Remote Port: 2709
Request Method: GET

and this

Date & Time: 2005-09-26 10:40:41 EDT GMT -0400
Blocked IP: 68.142.250.158
User ID: Anonymous (1)
Reason: Abuse-Script
--------------------
User Agent: Mozilla/5.0 (compatible; Yahoo! Slurp;
http://help.yahoo.com/help/us/ysearch/slurp)
Query String:
www.battlefield-2.biz/modules.php?name=Web_Links&file=index&l_op=viewlink&cid=3(\"derby=dateA
Get String:
www.battlefield-2.biz/modules.php?name=Web_Links&file=index&l_op=viewlink&cid=3(\"derby=dateA
Post String: www.battlefield-2.biz/modules.php
Forwarded For: none
Client IP: none
Remote Address: 68.142.250.158
Remote Port: 43562
Request Method: GET
I also get the same thing from msn for my sea fishing site and my gaming site

any idea`s
thanks for any help
Cheers
mrix
 
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Mon Sep 26, 2005 9:53 am Reply with quote

The quote marks and/or parentheses are not allowed in a search string for security against XSS attacks.
 
View user's profile Send private message
mrix







PostPosted: Mon Sep 26, 2005 11:52 am Reply with quote

Sorry I am not sure what you are talking about regards the quotes? are you saying its something I have added?
Cheers
mrix
 
Raven







PostPosted: Mon Sep 26, 2005 12:59 pm Reply with quote

Look at the Query String at the end. Do you know where the quote and parentheses are coming from?
 
mrix







PostPosted: Mon Sep 26, 2005 1:06 pm Reply with quote

To be honest I have no idea?
Cheers
mrix
 
Raven







PostPosted: Mon Sep 26, 2005 1:12 pm Reply with quote

Well, that's the source of the Bans.
 
mrix







PostPosted: Tue Sep 27, 2005 12:16 am Reply with quote

Strange thing though I have these emails coming from my News Downloads Links and survey pages? this all happened after installing the latest sentinal it must be some code somwhere as I havnt changed anything for months on these pages now they are blocking? these quote marks etc must be part of nuke or sentinal?
Cheers
mrix
 
Raven







PostPosted: Tue Sep 27, 2005 12:26 am Reply with quote

Both. If you have parentheses or quote marks in your download titles get rid of them. This is not new.
 
mrix







PostPosted: Tue Sep 27, 2005 12:45 am Reply with quote

I havnt touched my downloads page in over a year but I`ll check this out etc.
I do appriciate the help
Thanks
mrix
 
mrix







PostPosted: Tue Sep 27, 2005 12:49 am Reply with quote

Having checked my downloads page where I only have 7 downloads

www.sea-fishing.org/modules.php?name=Downloads&d_op=viewdownload&cid=1(\"derby=hitsD


I dont see anything that stands out? if you can find a minute could you please look and tell me if you see something that stands out??.
many thanks if this is possible
mrix
 
mrix







PostPosted: Thu Sep 29, 2005 12:17 am Reply with quote

Actually the when I go to the download page above as admin it shows the download page but no downloads links in it at all?
should I just allow the blocked ip`s of yahoo slurp ?
Cheers
mrix
 
VinDSL
Life Cycles Becoming CPU Cycles



Joined: Jul 11, 2004
Posts: 614
Location: Arizona (USA) Admin: NukeCops.com Admin: Disipal Designs Admin: Lenon.com

PostPosted: Thu Sep 29, 2005 2:10 am Reply with quote

Heh! I see it...

Code:
derby=hitsD

Look at the code for sorting your downloads, for instance 'Popularity (A\D)'...

Code:
http://www.sea-fishing.org/download1-orderbyhitsD.html

LoL! 'orderbyhitsD.html' -> 'derby=hitsD' Get it? ROTFL

_________________
.:: "The further in you go, the bigger it gets!" ::.
.:: Only registered users can see links on this board! Get registered or login! | Only registered users can see links on this board! Get registered or login! ::. 
View user's profile Send private message Visit poster's website ICQ Number
mrix







PostPosted: Thu Sep 29, 2005 2:40 am Reply with quote

Hi I am sure you know what you are talking about but I dont really know the ins and outs of phpnuke code and that means nothing to me unfortunately Sad is there an easy way to fix this ? the only thing I can see from it it may be a google tap problem and when I have updated the with the 3.1 files its messed it up I use GT Nextgen and thats a little out of date now.
Cheers
mrix
 
VinDSL







PostPosted: Thu Sep 29, 2005 4:39 am Reply with quote

mrix wrote:
Hi I am sure you know what you are talking about but I dont really know the ins and outs of phpnuke...

What I'm saying is when a user tries to sort your downloads, it bans you. That's how it's happening... Wink

I looked at your source code first, then tested the theory and attempted to sort your downloads, on both sites -- and promptly got banned as soon as I clicked the button[s].

I'm the guy running SeaMonkey 1.1 Alpha for a browser, so don't report me to the federal authorities... Smile
 
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> phpnuke 7.6

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©