Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
Chriscon
New Member
New Member



Joined: Oct 30, 2004
Posts: 6

PostPosted: Fri Oct 29, 2004 11:19 pm Reply with quote

Hello Everyone,

I am running Nuke 7.5 Chatserv 2.6 with Sentinel 2.1.0.

In the final stages of testing my new site. I created a test user, logged off as Admin and logged in a as the new user. All seemed fine, until I clicked on FAQ.

Sentinel then was invoked as it thought a scripting attack had occured and blocked the ip. I can't believe this has not been seen before and that the answer may be around but I have searched high and low and cannot find it.

Would someone be able to point me in the right direction? Does the FAQ module need to be upgraded in some way?

Hoping there is a simple answer.

Any help would be wonderful.

Thank you in advance.

Regards

Chris
 
View user's profile Send private message
Chriscon







PostPosted: Fri Oct 29, 2004 11:22 pm Reply with quote

So sorry I forgot this.....

The string that caused this to happen...
[ Only registered users can see links on this board! Get registered or login! ]

Hope this helps more.

Regards

Chris
 
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Fri Oct 29, 2004 11:29 pm Reply with quote

If you run an urldecode on that string, which NukeSentinel does, you will find that the string is actually
Code:
http://www.mysite.com/modules.php?name=FAQ&myfaq=yes&id_cat=1&categories=Arena FAQ (English)


Parentheses are NOT allowed in Nuke, nor in NukeSentinel. This is documented in several places here in the forums. 86 the () Wink
 
View user's profile Send private message
Chriscon







PostPosted: Fri Oct 29, 2004 11:54 pm Reply with quote

Wow!

How quick was that!

Thank you Raven.

You know sometimes you can't see the forest for the trees. I have been fighting with NSN News and my Collapsable Blocks (does n't work...made a new or is that old themeindex function so that I can use it but with no centre collapsing news) and I feel like I have seen so much code that my poor little brain is overheating. Then there was the threaded forum and the Approve Membership. I have a usercp_register that is something to behold. After achieving this all, the FAQ thing just bamboozled me.

I think I'm going to sleep now before I forget who I am (or to forget who I am).

Smile

Thank you once again for saving the day (or is that night).

Regards

Chris
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©