Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> RN v2.10.01 - All Issues
Author Message
Susann
Moderator



Joined: Dec 19, 2004
Posts: 3191
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Sun Apr 13, 2008 8:42 am Reply with quote

Thats the first time I found such an entry in rnlogs:

Quote:
Unknown column 'id' in 'where clause'
SQL was: SELECT user_email, username FROM nuke_users WHERE id='4' AND nickname='mytestuser' AND password='4803766830cc2b4919b2ef0b5f64b44e'
remote addr: xxx



I quess its from your account.I didn´t changed anything there. How do I correct this ?
 
View user's profile Send private message
evaders99
Former Moderator in Good Standing



Joined: Apr 30, 2004
Posts: 3221

PostPosted: Sun Apr 13, 2008 11:27 am Reply with quote

Weird, looks like the real code should be using 'user_id' rather than 'id'
I haven't looked to see where this is generated yet

_________________
- Star Wars Rebellion Network -

Need help? Nuke Patched Core, Coding Services, Webmaster Services 
View user's profile Send private message Visit poster's website
montego
Site Admin



Joined: Aug 29, 2004
Posts: 9457
Location: Arizona

PostPosted: Sun Apr 13, 2008 8:58 pm Reply with quote

Susann, if you can narrow down which function is doing this within YA it would be greatly appreciate it.

_________________
Where Do YOU Stand?
HTML Newsletter::ShortLinks::Mailer::Downloads and more... 
View user's profile Send private message Visit poster's website
Susann







PostPosted: Mon Apr 14, 2008 5:35 am Reply with quote

I think its not in your account because I would see this just every time in rnlogs whenever my testuser logged in. Maybe its from the journal or nsn gr downloads don´t know but I still try to find out where it comes from.
 
montego







PostPosted: Mon Apr 14, 2008 5:51 am Reply with quote

Ok, Susann, thanks.
 
montego







PostPosted: Fri Apr 25, 2008 1:49 pm Reply with quote

I am still not seeing this anywhere in my own logs. Have you found out anything more on this Susann?
 
Susann







PostPosted: Fri Apr 25, 2008 2:37 pm Reply with quote

No, I´m afraid I´ll not find out where this is from. I´ve checked the code of some nsn gr downloads files but there are just too many files.I´m using also the workboard. Could it be from there ?
I logged in like before with my testuser, downloaded the same download and didn´t get the same messages in rnlogs.
 
Guardian2003
Site Admin



Joined: Aug 28, 2003
Posts: 6799
Location: Ha Noi, Viet Nam

PostPosted: Fri Apr 25, 2008 3:04 pm Reply with quote

I cannot think of anything off hand that would want to do a query against a users password except perhaps (not checked) Resend or the manual creation of of a user or admin by the admin.
 
View user's profile Send private message Send e-mail
Susann







PostPosted: Sat Apr 26, 2008 2:11 pm Reply with quote

This user is since a long time in my database. Its not possible to check every sql select in all files but I found one error within the journal module and his journal. Maybe that was the reason but I´m not sure because with config errors set to true there aren´t any errors but his journal doesn´t exist. I will just empty the table nuke_journal_stats.
 
Guardian2003







PostPosted: Sat Apr 26, 2008 2:31 pm Reply with quote

I think I have found the where but not the why.
mainfile.php around line 1688 is this line
Code:


$row = $db->sql_fetchrow($db->sql_query('SELECT user_email, username FROM '.$user_prefix.'_users WHERE id=\''.$cookie[0].'\' AND nickname=\''.$cookie[1].'\' AND password=\''.$cookie[2].'\''));

It is the only thing I can find that matches that SELECT sql.
 
montego







PostPosted: Sat Apr 26, 2008 3:52 pm Reply with quote

Yeah, that doesn't make sense does it? That should be 'user_id' instead of 'id'. So, it only rears its ugly head when a subscription expires? Does that sound possible Susann?

We should definitely fix that SQL. Great sleuthing 'G'!!
 
Guardian2003







PostPosted: Sat Apr 26, 2008 4:02 pm Reply with quote

Now I have had time to actually look at the code, yes you are right 'M' it is in the function paid() which handles subscriptions and I see a few lines above that one that userid is used correctly in the DELETE FROM statement.
I about to hit the sack but if it has not already been done, I'll create a Mantis issue, apply the fix and SVN.
 
montego







PostPosted: Sat Apr 26, 2008 4:39 pm Reply with quote

You are a scholar and a gentleman... well, ok, maybe gentlemen, well, um, ok, how about a mighty fine bloke? ROTFL

And, Susann, your keen eye for bugs is amazing! You have allowed us to "squash" another nuke bug. :clap:
 
kguske
Site Admin



Joined: Jun 04, 2004
Posts: 6432

PostPosted: Sat Apr 26, 2008 9:41 pm Reply with quote

This team never ceases to amaze or impress me...

_________________
I search, therefore I exist...
nukeSEO - nukeFEED - nukePIE - nukeSPAM - nukeWYSIWYG
 
View user's profile Send private message
Susann







PostPosted: Sun Apr 27, 2008 4:19 am Reply with quote

I only wondered why nobody reported this before. Guardian thanks ! You are the hero of the day! Smile
 
Guardian2003







PostPosted: Sun Apr 27, 2008 10:04 am Reply with quote

No it is you who are the hero Susann, for your diligence, patience and attention to detail.
 
Susann







PostPosted: Sun Apr 27, 2008 5:45 pm Reply with quote

Oh, I would call it just good teamwork Wink
 
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    Ravens PHP Scripts And Web Hosting Forum Index -> RN v2.10.01 - All Issues

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©