Author |
Message |
KennyW
Hangin' Around
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Jul 15, 2004
Posts: 44
|
Posted:
Tue Jan 11, 2005 10:02 am |
|
NukeC & Download 3000 will not work properly if you have Sentinel 2.13 installed,but it will work with previous version,any idea how to get them to work properly,i tried to disable all the protections in Sentinel but it still stopped them so i try to move it from the mainfile and then it worked,so now I have put Sentinel back online but i want to run these 2 modules |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dameon
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Jan 27, 2005
Posts: 6
|
Posted:
Thu Feb 24, 2005 4:03 pm |
|
I am having the same issues. I see no fix in over a month. hmmmm. Anyone have any idea? |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
Spouse Contemplates Divorce
data:image/s3,"s3://crabby-images/8dfed/8dfededcab41558184ffe2905eff0db84df25448" alt=""
Joined: Jan 02, 2003
Posts: 2496
|
Posted:
Thu Feb 24, 2005 4:12 pm |
|
I haven't looked at either but its most likely something fairly simple. |
_________________ [b][size=5]openSUSE 11.4-x86 | Linux 2.6.37.1-1.2desktop i686 | KDE: 4.6.41>=4.7 | XFCE 4.8 | AMD Athlon(tm) XP 3000+ | MSI K7N2 Delta-L | 3GB Black Diamond DDR
| GeForce 6200@433Mhz 512MB | Xorg 1.9.3 | NVIDIA 270.30[/size:2b8 |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dameon
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 24, 2005 4:22 pm |
|
Yea, I am gonna see what I can figure out but I don't know the sentinel code at all. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 24, 2005 5:03 pm |
|
Start with the santy code in the includes/sentinel.php the $id variable has been causing grief in a lot of modules. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dameon
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 24, 2005 5:38 pm |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dameon
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 24, 2005 6:46 pm |
|
Well, it appears that it is the sanity area. I comment out the entire code and downloads3000 works fine. AS far as I can tell, the bad content variable is assigned words that are not part of the incoming URI. I droped it to 1 word then changed it and it still won't let downloads3000 through. The funny part is it doesn't die with the illegal content error. The text comes back from the server with the following error: "Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in bla \bla\sql_layer.php line 71"
Now it does have other errors also for different things and then repeats. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sixonetonoffun
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 24, 2005 6:55 pm |
|
Just leave it commented out and find the thread that has the Santy worm (revisited) title there are some mod rewrite protections that will do the same job and not bother your script. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dameon
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Feb 24, 2005 6:59 pm |
|
OK here is what I did. I know it is kinda poor code as I am a C++ coder but this worked where the while staement doesn't and it does the same thing only longer. Please tell me if this is any way bad from both functional as well as secure.
Thanks,
D
/********************************************************/
// Stop Santy Worm
$bad_uri_content="perl,rush,chr(,pillar,visualcoder,sess_";
global $REQUEST_URI;
/* $tmp=explode(",",$bad_uri_content);
while(list($id,$uri_content)=each($tmp)) {
if (strpos($REQUEST_URI,$uri_content)) {
die("Illegal Content");
}
}*/
if (strpos($REQUEST_URI, "perl")){
die("Illegal Content");
}
elseif (strpos($REQUEST_URI, "rush")){
die("Illegal Content");
}
elseif (strpos($REQUEST_URI, "chr(")){
die("Illegal Content");
}
elseif (strpos($REQUEST_URI, "pillar")){
die("Illegal Content");
}
elseif (strpos($REQUEST_URI, "pervisualcoder")){
die("Illegal Content");
}
elseif (strpos($REQUEST_URI, "sess_")){
die("Illegal Content");
} |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Doodle
Hangin' Around
data:image/s3,"s3://crabby-images/87dc0/87dc05db8c203b0c1145e30ec1c315e5285ee7c9" alt=""
Joined: Jan 26, 2004
Posts: 46
Location: 127.0.0.1
|
Posted:
Wed Mar 30, 2005 4:20 pm |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Dameon
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Thu Mar 31, 2005 7:13 am |
|
Upgrade to Sentinel 2.2 and you can get rid of the sanity check altogether. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
|