Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> Raven's RavenNuke(tm) v2.00.00 - v2.02.00 Distro
Author Message
xGSTQ
Involved
Involved


Joined: Feb 03, 2006
Posts: 267
Location: UK

PostPosted: Mon Jan 08, 2007 6:03 pm Reply with quote

Quick Question

I have html enabled on the forums all im trying to do is post simple html in the forums its table code thats all and i get the forbidden screen

Code:
<table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse" width="98%" id="table12">

    <tr>
     
      <td class="blockcenter" width="100%">


Thats what im trying to post... ive looked at the allowed Allowed HTML tags
Separate tags with commas in the forums admin ... and added a shed load i found ... lol

to see if that was the issue
Code:
b,I,u,p,pre,html,layer,head,style,title,div,color,font,meta,body,table,width,tr,scope,

center,iframe,align,left,right,table,td,th,title,tt,marquee,input,bgcolor,align,top,middle,
hr,s,br,h1,h2,h3,h4,h5,h6,li,img,embed,textarea,ul,ol,strong,small,dir,form,script,span,


But that didnt resolve it either... any one have any thoughts ?

Thx

Ped
 
View user's profile Send private message Send e-mail Visit poster's website
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Mon Jan 08, 2007 10:29 pm Reply with quote

Forbidden doesn't sound like a problem with phpNuke or the forums. Rather, it sounds like a server-based protection system like mod_security
Ask your host whether they are using such a system

_________________
- Only registered users can see links on this board! Get registered or login! -

Need help? Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website
xGSTQ
PostPosted: Tue Jan 09, 2007 3:13 am Reply with quote

I think your right ! lol

Ive got a fresh install of RN on a separate domain using the same host and i just posted the same table code and guess what ! It stripped the same dam code !

Is there any thing i can do/to get around this problem ?

Thx for the fast response too Evaders, appriciated
 
montego
Site Admin


Joined: Aug 29, 2004
Posts: 9449
Location: Arizona

PostPosted: Tue Jan 09, 2007 7:16 am Reply with quote

I believe "style" was getting caught by NukeSentinel??? Not 100% sure, but I do recall seeing that in the blocker code. The stripping of the code sounds more like the $allowableHTML array in config.php.

However, be careful adding style back in as an allowed tag. This can be used for XSS style attacks. It would be much better to not use in-line CSS anyways...

_________________
Only registered users can see links on this board! Get registered or login!
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website
xGSTQ
PostPosted: Tue Jan 09, 2007 7:25 am Reply with quote

hmm but how come i can post it here at Ravenphpscripts

Im trying to post this
Code:
<table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse" width="98%" id="table12">

    <tr>
     
      <td class="blockcenter" width="100%">


And it ends up like

Code:
<table>

    <tr>
     
      <td>


Im confused now Rolling Eyes (doesnt take much, trust me ! lol)
 
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 6792
Location: Ha Noi, Viet Nam

PostPosted: Tue Jan 09, 2007 10:32 am Reply with quote

Just for grins and gigles have at look at admin-> Forum ->Configuration there is a setting there to allow specific html tags within forum.
This may not override other protection such as Sentinel or the main allowed html array but it is worth noting the setting in forums exists.
 
View user's profile Send private message Send e-mail
xGSTQ
PostPosted: Thu Jan 11, 2007 5:12 pm Reply with quote

Yeah that was my first port of call, i added all of these to see if that was the issue

Code:
b,I,u,p,pre,html,layer,head,style,title,div,color,font,meta,body,table,width,tr,scope,

center,iframe,align,left,right,table,td,th,title,tt,marquee,input,bgcolor,align,top,middle,
hr,s,br,h1,h2,h3,h4,h5,h6,li,img,embed,textarea,ul,ol,strong,small,dir,form,script,span


But still the same !

Is there anything i can do to get round this guys Rolling Eyes
 
montego
PostPosted: Mon Jan 15, 2007 10:09 pm Reply with quote

Unfortunately, I don't have the answer off the top of my head. Sure wish 64bitguy was still active... he'd know in a heartbeat!
 
xGSTQ
PostPosted: Tue Jan 16, 2007 2:18 am Reply with quote

Thanks Montego,

Im really fudged of now... all i want to do is post simple html in the forums ... its stupid it lets me use the embed tags so i can post You Tube video's
 
montego
PostPosted: Sun Jan 21, 2007 7:16 am Reply with quote

Sorry if this has already been asked and answered, but I've been away for quite awhile... have you tried turning OFF HTML in your forums? You really don't need the HTML formatting to show up right? What you are really interested in is being able to show it as code?
 
xGSTQ
PostPosted: Sun Jan 21, 2007 7:31 am Reply with quote

yup you got it in one

I just want to be able to post theme edits ect.

The HTML code was off for a while when we first started up but i was getting messages some times when posting messages

Forbidden if i remember rightly or it could have been you are not allowed to access modules.php or admin.php i cant recall its a while back now... but i thought that might be because of the html being turned off, so i turned it on and ive not had the message since funily enough.

and no ive not fixed her yet !

thx for your concern montego, i dont know what to do ! Bang Head
 
montego
PostPosted: Sun Jan 21, 2007 9:02 am Reply with quote

Quote:

i dont know what to do


Me neither, but when I get some time, I'll try to do some of this. I know that 64bitguy had recoded BBtoNuke some to make this work better, but, unfortunately, he never released any of it... Sad
 
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> Raven's RavenNuke(tm) v2.00.00 - v2.02.00 Distro

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©