Author |
Message |
mrix
Client

Joined: Dec 04, 2004
Posts: 757
|
Posted:
Wed Oct 29, 2008 6:50 pm |
|
Hi there, something I find very usefull is the HTTP Referers in admin panel.
Unfortunately its stopped working with the upgrade
anyone else noticed this or is it just a problem my end
cheers
mrix |
|
|
|
 |
ecchi_goshujinsama
New Member


Joined: Jul 11, 2008
Posts: 9
|
Posted:
Wed Oct 29, 2008 6:56 pm |
|
I have also experience the same problem. I'm wondering if it's a bug on RN2.3 or mayhap something went wrong with the upgrade process. |
|
|
|
 |
jestrella
Moderator

Joined: Dec 01, 2005
Posts: 593
Location: Santiago, Dominican Republic
|
Posted:
Wed Oct 29, 2008 7:38 pm |
|
Nothing wrong with it.
This feature was removed from RN230, because of some security flaws present...
If you still want it on your server, and you understand the risk of having it active, you can get the files from previous version and upload it to your server.
If I remember correctly, the given files were:
/admin/case/case.referers.php
/admin/links/links.httpreferers.php
/admin/modules/referers.php
NOTE: We highly discourage using this feature on Nuke systems |
_________________ "For those whom have not reach the sky... Every mountain seems high"
Best Regards
Jonathan Estrella
http://about.me/jestrella04 |
|
|
 |
ecchi_goshujinsama

|
Posted:
Wed Oct 29, 2008 7:41 pm |
|
Jestrella, is it possible to point me in the correct direction on this security flaw that was found in the http referers?
Thank you |
|
|
|
 |
mrix

|
Posted:
Wed Oct 29, 2008 7:43 pm |
|
Quote: | This feature was removed from RN230, because of some security flaws present... |
Thats a shame as it was such a useful tool
I`ll say goodbye to it though for the sake of better security
cheers anyway
mrix |
|
|
|
 |
jestrella

|
Posted:
Wed Oct 29, 2008 7:49 pm |
|
ecchi_goshujinsama, With this active there's a risk of a potential sql injection attack. Hope this clear your doubt. |
|
|
|
 |
jestrella

|
Posted:
Wed Oct 29, 2008 7:53 pm |
|
hey mrix sorry on this one.
I can see you joined the site same day as my bday.  |
|
|
|
 |
evaders99
Former Moderator in Good Standing

Joined: Apr 30, 2004
Posts: 3221
|
Posted:
Wed Oct 29, 2008 9:09 pm |
|
As far as I know, that injection was fixed a while ago. There shouldn't be any harm in it, but I believe it was removed because NukeSentinel had its own referrers feature |
_________________ - Only registered users can see links on this board! Get registered or login! -
Need help? Only registered users can see links on this board! Get registered or login! |
|
|
 |
jestrella

|
Posted:
Wed Oct 29, 2008 10:17 pm |
|
Thats so true.
You can enter
NukeSentinel -> Tracked IP Menu -> Display Tracked Referers
and have a look at the sites referring people to your site.
 |
|
|
|
 |
Guardian2003
Site Admin

Joined: Aug 28, 2003
Posts: 6799
Location: Ha Noi, Viet Nam
|
Posted:
Wed Oct 29, 2008 10:45 pm |
|
NS definitely does it better  |
|
|
|
 |
mrix

|
Posted:
Thu Oct 30, 2008 5:29 am |
|
Quote: | You can enter
NukeSentinel -> Tracked IP Menu -> Display Tracked Referers |
I did take a look and nothing in there also? has that side been effected as well? or do I have to enable something in sentinal to get that recieving them etc?
cheers
mrix |
|
|
|
 |
jakec
Site Admin

Joined: Feb 06, 2006
Posts: 3048
Location: United Kingdom
|
Posted:
Thu Oct 30, 2008 6:56 am |
|
You have to make sure it is turned on in the Nukesentinel admin, I think it might be under the IP Tracking option. |
|
|
|
 |
hube
Hangin' Around

Joined: May 02, 2008
Posts: 28
|
Posted:
Sat Jan 10, 2009 2:56 am |
|
Sorry for bumping.
I also miss the refers feature, however I understand that its not worth the risk.
Regarding the referers in Sentinel (via tracked ip) is there a way to exclude my own domain from being tracked? |
|
|
|
 |
jakec

|
Posted:
Sat Jan 10, 2009 3:14 am |
|
You need to add you IP to the Excluded ranges. |
|
|
|
 |
hube

|
Posted:
Sat Jan 10, 2009 4:27 am |
|
|
|
 |
|