Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Modules
Author Message
jetsurgeon
New Member
New Member



Joined: Nov 22, 2004
Posts: 5

PostPosted: Thu Dec 09, 2004 2:16 am Reply with quote

Hi Guys,

Let’s get this out of the way first.

---- Specs ----
Phpnuke v. 7.3
Chatserv v. 2.7
Sentinel v. 2.1.1
Menalto Gallery v. 1.4.4-pl4

Processor: Dual Intel Xeon 3.06GHz w/ Hyperthreading
Memory: 1GB DDR
Hard Drive: 7200RPM IDE
Ethernet Port: 100Mbps
O/S: CentOS 3.3 i686
[ Only registered users can see links on this board! Get registered or login! ]
----------------

Background:

(1) Installed Gallery v 1.4.4-pl4, tested it out as admin, no problems what so ever (I’m guessing because my IP addie is protected within Sentinel).

(2) Created a test user account within nuke named “J1”.

(3) As Admin, created an album for this user name “J1” and set the album owner to “J1”.

(4) Logged in as “J1” I added 19 or so test photos, no problems.

(5) Entered the album, selected one of the photos to change it to new album “HIGHLIGHT PHOTO”…..Bang!!!

(6) Sentinel went off, banning me.

--- Below is the email generated from Sentinel ---

Date & Time: 2004-12-09 02:25:18
Blocked IP: 65.187.211.XXX (Note: I removed the last octet)
User ID: J1 (2)
Reason: Abuse-Filter
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Query String:
copterholic.com/modules.php?cmd=highlight&index=9&set_albumName=J1test&op=modload&name=gallery&file=index&include=do_command.php
Forwarded For: none
Client IP: none
Remote Address: 65.187.211.XXX
Remote Port: 4934
Request Method: GET
--------------------

My questions:

(1) Is there a way to make Sentinel compatible with Gallery? If so how?

Remember….. There’s a lot of functions within Gallery which a user could use on a photo IE: Edit Text, Edit Thumbnail, Rotate / Flip, Highlight, Move, Reorder, Copy, Hide, and Delete.

(2) If Sentinel cannot be tweaked to play nice with Gallery, is there another “Photo Gallery” script which is compatible, and isn’t too bad?

Thanks for your time,

Jeff G.


Last edited by jetsurgeon on Mon Dec 20, 2004 1:18 pm; edited 2 times in total 
View user's profile Send private message Visit poster's website
oprime2001
Worker
Worker



Joined: Jun 04, 2004
Posts: 119
Location: Chicago IL USA

PostPosted: Thu Dec 09, 2004 7:39 am Reply with quote

Try these links (courtesy of the Search).
[ Only registered users can see links on this board! Get registered or login! ] [ Only registered users can see links on this board! Get registered or login! ] [ Only registered users can see links on this board! Get registered or login! ]
 
View user's profile Send private message
jetsurgeon







PostPosted: Fri Dec 10, 2004 5:23 am Reply with quote

Thanks for the tips...... After trying the suggestions in those links, and testing out the gallery, I had to add a few more items to the code list within "includes/sentinel.php".

Below is the code, which will allow any "LOGGED IN" user to run any of the options for an album or photo without getting zapped by sentinel.

Code:
  // Check for XSS attack

if (eregi("http\:\/\/", $name) OR (eregi("cmd",$querystring) AND !eregi("&cmd",$querystring) AND !eregi("cmd=highlight",$querystring) AND !eregi("cmd=hide",$querystring)) OR eregi("exec",$querystring) AND !eregi("execu",$querystring) OR eregi("concat",$querystring)) {


Thanks,

Jeff
 
montego
Site Admin



Joined: Aug 29, 2004
Posts: 9457
Location: Arizona

PostPosted: Fri Dec 10, 2004 10:44 pm Reply with quote

I had to add the following to the above if statement as well:

Code:
AND !eregi("cmd=show",$querystring) AND !eregi("cmd=reset",$querystring) 
 
View user's profile Send private message Visit poster's website
jib_intelli
Hangin' Around



Joined: Aug 17, 2004
Posts: 43

PostPosted: Thu May 25, 2006 11:57 pm Reply with quote

I have a slight problem too, I am using

PHPNuke 7.6
Chatserv's Patches - 2.9
Gallery - 2.1.1
Sentinel - 2.1.3

And on many options I recieve Illegal Content. For example if you visit my gallery - [ Only registered users can see links on this board! Get registered or login! ] and browse through the albums, everything works fine except when you click on the links of the menu at the top where it says as:

Mirror of Erised >> Album Name >> Sub-Album Name >> Item Name

etc. you can click on any of these links and it shows a blank white page with Illegal Content written. When I disable Sentinel, no such problem occurs. Please advise.

_________________
PottersRealm.com ~ Harry Potter Everything! 
View user's profile Send private message
jaded
Theme Guru



Joined: Nov 01, 2003
Posts: 1006

PostPosted: Fri May 26, 2006 5:10 am Reply with quote

have you made the changes listed above?
Have you done this as well [ Only registered users can see links on this board! Get registered or login! ]

_________________
Themes BB Skins [ Only registered users can see links on this board! Get registered or login! ]
Graphic Tees [ Only registered users can see links on this board! Get registered or login! ]
Paranormal Tees [ Only registered users can see links on this board! Get registered or login! ]
Ghost Stories & More [ Only registered users can see links on this board! Get registered or login! ] 
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Modules

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©