PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
lonk
Regular
Regular


Joined: Aug 04, 2006
Posts: 60

PostPosted: Wed Aug 27, 2008 8:28 pm Reply with quote Back to top

i added those strings but before i get it setup i got this email

User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

Get String:
Only registered users can see links on this board!
Get registered or login to the forums!

Post String:
Only registered users can see links on this board!
Get registered or login to the forums!

Forwarded For: none
Client IP: none
Remote Address: 74.195.190.116
Remote Port: 63527
Request Method: GET
View user's profile Send private message
jakec
Site Admin


Joined: Feb 06, 2006
Posts: 3038
Location: United Kingdom

PostPosted: Thu Aug 28, 2008 12:27 am Reply with quote Back to top

The previous post by Gremmie should protect against this string as well.
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Thu Aug 28, 2008 7:15 am Reply with quote Back to top

lonk, that just looks like a malformed attack. My .htaccess fix won't stop that because there are no spaces between DECLARE and the @, however if that is the actual text you got from Sentinel that probe can't possibly do anything. It doesn't look syntactically correct in any SQL I am aware of.
View user's profile Send private message
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1191

PostPosted: Thu Aug 28, 2008 9:02 am Reply with quote Back to top

Unfortunately I cannot provide the script any longer simply because since the htaccess edit I haven't received ANY scripts (hundreds) that made it through. But I do remember that there were no underscores in the script. Perhaps this is a deliberate attempt to bypass any type of script spoiler, who knows.

Cheers
View user's profile Send private message
jakec
Site Admin


Joined: Feb 06, 2006
Posts: 3038
Location: United Kingdom

PostPosted: Thu Aug 28, 2008 10:42 am Reply with quote Back to top

I stand corrected, sorry. Embarassed
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum