Author |
Message |
Panthera
Hangin' Around
data:image/s3,"s3://crabby-images/7a19c/7a19c969aab405543947ab9aba07799a696528a4" alt=""
Joined: May 16, 2004
Posts: 28
Location: Northern California, USA
|
Posted:
Sun May 16, 2004 11:28 pm |
|
Hello!
I am just recovering from my first hack and my head is still spinning. I installed the Hack Alert but when I test it I get my own 404 Error page.
Here is what I inserted:
Code:// Raven http://ravenphpscripts.com
$queryString = strtolower($HTTP_SERVER_VARS['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString");
die();
}
|
Admittedly, I'm a phpNuke newbie (running 7.1) but I cannot find the $LOC in the coding. Am I missing something??
Quote: | - NOTE: SOME SETUPS REQUIRE THE TRAILING SLASH AFTER THE $LOC AND SOME WILL NOT WORK IF THE TRAILING SLASH IS PRESENT. IF YOU ARE EXPERIENCING PROBLEMS THEN TRY ADDING/REMOVING THE TRAILING SLASH AS NEEDED. |
Only registered users can see links on this board! Get registered or login!
What am I doing wrong?
Panthera |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
Site Admin/Owner
data:image/s3,"s3://crabby-images/6c868/6c86859170a3596c942592f58366e4a982a03ad0" alt=""
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Mon May 17, 2004 12:05 am |
|
First of all, make sure that you have the hackattempt.php file in the same directory as mainfile.php. Now, the $LOC has been changed to $queryString and I forgot to update the statement in the INSTALL file - sorry (it's fixed now)! So, try thisCode:// Raven http://ravenphpscripts.com
$queryString = strtolower($HTTP_SERVER_VARS['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString/");
die();
}
|
|
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Panthera
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 12:47 am |
|
Raven wrote: | First of all, make sure that you have the hackattempt.php file in the same directory as mainfile.php. |
Hi Raven,
Thanks for the quick reply. They are in the same directory and I updated the code to the above you included. I still get my own 404 Error page.
Should I replace the code that is there currently? Or just place it above it? [I replaced it]
Code:$queryString = strtolower($_SERVER['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: index.php");
die();
}
|
Thanks! |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 12:53 am |
|
Replace it. Make sure you don't have a typo in the script name. Review the error message to see what path it is attempting to goto. That should give an indication as to the pathing error. Try this if nothing else worksCode:header("Location: http://yourdomain.com/hackattempt.php?$queryString");
| Of course adjust the url to point to the script. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Panthera
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 1:17 am |
|
Well, it doesn't look as if there are any typos ... i tried expanding the path location as you suggested and then back again.
Code:// Raven http://ravenphpscripts.com
$queryString = strtolower($HTTP_SERVER_VARS['QUERY_STRING']);
if (strstr($queryString,'%20union%20') OR strstr($queryString,'/*')) {
header("Location: hackattempt.php?$queryString/");
die();
}
|
I still get my own 404 page.
Here is what shows at the bottom of that page:
Code:http://ravenphpscripts.com/modules.php?name=Forums&file=viewtopic&p=10457 69.104.2.35 /modules.php?name=Web_Links&l_op=viewlink&cid=1%20union%20select www.dabat.com Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; AT&T CSM6.0; yie6) 404
|
I'm at a loss. It should be so simple ...
Panthera |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Panthera
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 1:21 am |
|
Oh, and I have tried it with and without the trailing slash / at the end of the location string. data:image/s3,"s3://crabby-images/d2cfc/d2cfc11bf68013f46763733f6fdf89c5bbd7a240" alt="Confused" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
bones
Hangin' Around
data:image/s3,"s3://crabby-images/8c70a/8c70a73a0c686e3ce1cbc910ea05933223e08bb8" alt=""
Joined: Sep 18, 2003
Posts: 36
|
Posted:
Mon May 17, 2004 1:54 am |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Panthera
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 7:32 am |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 8:58 am |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Panthera
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon May 17, 2004 12:58 pm |
|
Bless you Raven!!!
And I am BLIND!!!!!!! and feeling stupid for missing such a simple thing
Yes, it works beautifully now!
Hugs, Panthera |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
|