Author |
Message |
sneezyyzeens
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Nov 12, 2005
Posts: 6
|
Posted:
Sat Nov 12, 2005 10:21 pm |
|
This is what i did for my installation:
I uploaded a single line blank .htaccess and .staccess files along with the new sentinel files and the changed files (per the readme)
ran the nsnst.php successfully.
opened up the sentinel admin panel
added my username and a password to the admin auth list.
clicked the little create the .staccess file dohicky over my admin name
(checked, and yes, my .staccess now has my login name and the cryptized password)
so now I update the .htaccess file with
Code:<Files RELATIVE_PATH_TO_ID_PASS_FILE>
deny from all
</Files>
<Files admin.php>
<Limit GET POST PUT>
require valid-user
</Limit>
AuthName "Restricted"
AuthType Basic
AuthUserFile REAL_PATH_TO_ID_PASS_FILE
</Files>
|
I reload the page, and get the popup login, but it won't accept my password (rechecked 50billion times to make sure i wasn't typing it wrong or in caps lock)
So for now I reloaded the blank .htaccess, but that kinda defeats the purpose of having sentinel installed...
so what's my next step? Or have I done something wrong? I'm sure I've missed something, but I've been trying to get phpnuke working all day and my eyes are getting bleary |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
Site Admin/Owner
data:image/s3,"s3://crabby-images/6c868/6c86859170a3596c942592f58366e4a982a03ad0" alt=""
Joined: Aug 27, 2002
Posts: 17088
|
Posted:
Sat Nov 12, 2005 11:55 pm |
|
First of all, in NukeSentinel Admin menu, do you have HTTPAuth as an option in the drop down box? If so, use it instead. |
Last edited by Raven on Sun Nov 13, 2005 12:26 am; edited 1 time in total |
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sneezyyzeens
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 12:19 am |
|
Is that a Admin Auth: option?
For that I don't get a dropdown box, I get
HTTPAuth Requires "register_globals" to be ON
I turned register_globals on in my php.ini file, but it could be my host is overwriting that setting globally (the php.ini file says turning that parameter on can cause security holes) |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 12:22 am |
|
It will only cause security holes if your scripts are poorly written. Try this instead. Add this line to your .htaccess file.
php_flag register_globals On |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sneezyyzeens
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 12:31 am |
|
doing that gives me a 500 Internal Server Error for all pages |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 12:37 am |
|
So your host does not allow you to override php directives via .htaccess. Too bad. When you're ready for a more complete web hosting solution, be sure to check out Raven Web Hosting Now, back to your issue.
To see if you are overriding the setting in your php.ini file, run phpinfo() and look at what the LOCAL value is for register_globals. Do not post a link to your phpinfo for security reasons. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sneezyyzeens
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 12:51 am |
|
looks like my local copy is being overridden
Directive . . . . . . Local Value . . Master Value
register_globals . . . Off . . . . . . . . . . Off |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 1:05 am |
|
okay, so we are back to square one, using CGI. 99.9% of the time when it doesn't work it's because the relative path to .staccess is not correct. Verify that you have the correct relative path paying particular attention to the upper/lower case. |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sneezyyzeens
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 1:26 am |
|
the paths are correct
if I change them, or delete the .htaccess/.staccess file, I get a
File does not exist or is not correctly CHMODed.
error message in the sentinel config settings |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
sneezyyzeens
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 10:24 am |
|
hi..looking at in the morning instead of at 2am...
I forgot to change AuthUserFile REAL_PATH_TO_ID_PASS_FILE
in the .htaccess file itself to the real path (I had only changed it in the sentinel settings)
thanks so much for your help last night!
(now on to upgrading the default phpbb that came with 7.9 to 2.018 ugggh) |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Sun Nov 13, 2005 10:25 am |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Rollercoaster
New Member
data:image/s3,"s3://crabby-images/0b3dd/0b3dd56bc606132b506b4d2f9c985116ba684530" alt="New Member New Member"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Mar 01, 2006
Posts: 6
|
Posted:
Mon Mar 06, 2006 4:11 pm |
|
This thread helped me as well... !
I guess I made the same mistake:
In the ht & st access pathes i typed in the complete path, displayed as normal examples just below, instead of only the file names, which seems to be accepted though.
But doing that did it.
Thank you so much for this! data:image/s3,"s3://crabby-images/fabed/fabed724a04168d23d67c0f0722ee8a640f1adb3" alt="Smile" |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
Raven
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
|
Posted:
Mon Mar 06, 2006 4:18 pm |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
leo51
Worker
data:image/s3,"s3://crabby-images/8b787/8b787549c86734a98c61309018e332528520bc6f" alt="Worker Worker"
data:image/s3,"s3://crabby-images/6ea31/6ea3138e9a23822aea960115951a6c1ae34639ea" alt=""
Joined: Sep 09, 2004
Posts: 106
Location: Canada
|
Posted:
Fri Mar 24, 2006 6:36 pm |
|
sneezyyzeens wrote: | This is what i did for my installation:
I uploaded a single line blank .htaccess and .staccess files along with the new sentinel files and the changed files (per the readme)
ran the nsnst.php successfully.
opened up the sentinel admin panel
added my username and a password to the admin auth list.
clicked the little create the .staccess file dohicky over my admin name
(checked, and yes, my .staccess now has my login name and the cryptized password)
so now I update the .htaccess file with
Code:<Files RELATIVE_PATH_TO_ID_PASS_FILE>
deny from all
</Files>
<Files admin.php>
<Limit GET POST PUT>
require valid-user
</Limit>
AuthName "Restricted"
AuthType Basic
AuthUserFile REAL_PATH_TO_ID_PASS_FILE
</Files>
|
I reload the page, and get the popup login, but it won't accept my password (rechecked 50billion times to make sure i wasn't typing it wrong or in caps lock)
So for now I reloaded the blank .htaccess, but that kinda defeats the purpose of having sentinel installed...
so what's my next step? Or have I done something wrong? I'm sure I've missed something, but I've been trying to get phpnuke working all day and my eyes are getting bleary |
Could you tell me what version of nuke did you install Sentinel?
Many Thanks |
|
|
|
data:image/s3,"s3://crabby-images/74676/7467655c43f84619d5d7cf725b1d668453dba0fe" alt="" |
|