PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Feb 09, 2004 1:34 pm Reply with quote Back to top

Raven, is this script designed to work with 6.5? I have tried both lines added to the mainfile, one on each site, no luck. Thank you, Steve
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Feb 09, 2004 2:52 pm Reply with quote Back to top

Yes. It shouldn't matter. It's not a nuke script - it's php.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Feb 09, 2004 2:58 pm Reply with quote Back to top

I just tried it with this and it worked. It is very slow though
Only registered users can see links on this board!
Get registered or login to the forums!


Last edited by Raven on Mon Feb 09, 2004 10:58 pm; edited 1 time in total
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Feb 09, 2004 3:34 pm Reply with quote Back to top

I just tried it with your link, it worked. Thank you.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Feb 09, 2004 3:42 pm Reply with quote Back to top

What was the link you were trying that wasn't working? Maybe there's a bug?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Feb 09, 2004 3:43 pm Reply with quote Back to top

Raven, you are a lifesaver. Do you remember that blackmail attempt we talked about? I just received 5 hack attempts from the same person. I will forward them so you can see them. I would like to get this guy if we can. I can't thank you enough - Steve
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Feb 09, 2004 3:49 pm Reply with quote Back to top

Well, you got me. That's my IP. Send in the clowns. I'm caught. Chat, the site's yours Laughing
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Feb 09, 2004 3:59 pm Reply with quote Back to top

Laughing Laughing Laughing I better remove you from my banned list. The script worked perfectly. I highly recommend it to anyone and everyone! Very Happy Steve
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Feb 09, 2004 4:20 pm Reply with quote Back to top

Thank you Rolling Eyes Laughing
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Mon Feb 09, 2004 4:24 pm Reply with quote Back to top

Raven, you have the right to remain silent, anything you say can and will be used against you...
Cuff him Sharlein.
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Feb 09, 2004 4:35 pm Reply with quote Back to top

Image
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Feb 09, 2004 6:28 pm Reply with quote Back to top

Embarassed
View user's profile Send private message
Lateron
Worker
Worker


Joined: May 10, 2003
Posts: 119
Location: Katoomba, NSW, Australia.

PostPosted: Mon Feb 09, 2004 10:35 pm Reply with quote Back to top

Raven,

May I suggest you change Sharlein's URL in the third message from the top to yourdomain.com or something?

I have just installed the hack and went to copy the URL to test my site and before I could change domain name to mine, the URL had been actioned and I got the hack page and Sharlein would have got a worrying email.

Thanks, Raven.

Cheers,
Ron...
View user's profile Send private message Visit poster's website
paranor
Worker
Worker


Joined: Aug 28, 2003
Posts: 227

PostPosted: Tue Feb 10, 2004 7:55 pm Reply with quote Back to top

This alert was for reviews and news. What link is this for then?

Only registered users can see links on this board!
Get registered or login to the forums!



Hey Sharlein - GO PACKERS! Smile
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Tue Feb 10, 2004 8:02 pm Reply with quote Back to top

That code traps it all.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
paranor
Worker
Worker


Joined: Aug 28, 2003
Posts: 227

PostPosted: Tue Feb 10, 2004 8:10 pm Reply with quote Back to top

You mean test it? I *just* noticed it's the same as what's in your install document in the hackattemp.php program.

Speaking of that, the install document has a "/php/" in the URL. I had to remove that to test it. Typo?
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Tue Feb 10, 2004 8:14 pm Reply with quote Back to top

If you put that code in mainfile.php it will trap all of the 'union' exploits.

Yes, the php is a leftover. I will fix it.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Ronin
New Member
New Member


Joined: Jul 30, 2003
Posts: 8

PostPosted: Wed Feb 11, 2004 6:28 pm Reply with quote Back to top

Hi guys,

Here's the top of my mainfile.php:
Code:
<?php

if (stristr($_SERVER["QUERY_STRING"],'%20union%20')) header("Location: hackattempt.php/");


If I browse to mydomain.com/hackattempt.php I see the warning and get an email. However I can't seem to trigger it with my URL and the path shown in the INSTALL file:

Quote:
http://www.DOMAIN.COM/modules.php?name=Web_Links&l_op=viewlink&cid=1%20union%20select



Any ideas? This is a nuke6.5 machine.

Cheers,
Ronin


Last edited by Ronin on Wed Feb 11, 2004 6:45 pm; edited 1 time in total
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Wed Feb 11, 2004 6:39 pm Reply with quote Back to top

Try removing the trailing slash.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Ronin
New Member
New Member


Joined: Jul 30, 2003
Posts: 8

PostPosted: Wed Feb 11, 2004 6:45 pm Reply with quote Back to top

Bingo!

Thanks Raven
View user's profile Send private message
qdog
New Member
New Member


Joined: Feb 12, 2004
Posts: 9

PostPosted: Thu Feb 12, 2004 10:25 am Reply with quote Back to top

Raven,

First thanks for another great script!!!

Next a quick question...

I have tried:
header("Location: hackattempt.php/")
header("Location: hackattempt.php")

And get page not found.

It works when I change it to this:
header("Location:
Only registered users can see links on this board!
Get registered or login to the forums!
")

Any problems with doing this?
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Thu Feb 12, 2004 10:35 am Reply with quote Back to top

None at all. It is browser dependent and the fully qualified url is the RFC standard anyway Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
qdog
New Member
New Member


Joined: Feb 12, 2004
Posts: 9

PostPosted: Thu Feb 12, 2004 10:39 am Reply with quote Back to top

Cool, thanks for the quick reply Very Happy
View user's profile Send private message Visit poster's website
Lateron
Worker
Worker


Joined: May 10, 2003
Posts: 119
Location: Katoomba, NSW, Australia.

PostPosted: Fri Feb 13, 2004 4:17 am Reply with quote Back to top

Raven,

I got past the page not error by using:

header("Location:
Only registered users can see links on this board!
Get registered or login to the forums!
")

However now I am getting:

Unable to query WhoIs information for 203.xxx.xxx.xxx.

I have had several union attacks today and they were stopped by Protector but I would like to get your system working.

Cheers,
Ron....
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Fri Feb 13, 2004 5:52 am Reply with quote Back to top

Send me the actual IP and I will check into it.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum