PHP Web Host - Quality Web Hosting For All PHP Applications Clan Themes! We make clans look good!!
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
deadl0ck
Hangin' Around


Joined: Apr 09, 2006
Posts: 44

PostPosted: Tue Jan 23, 2007 4:07 am Reply with quote Back to top

Hi all,
One of the admins on my site keeps getting blocked.

Here's the details that NukeSentinal is reporting:
Code:

Blocked IP:   none...*
User:   Anonymous
Agent:   Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Blocked on:   2007-01-23 05:10:46
Notes:   Added by NukeSentinel(tm)
Reason:   Abuse-Union
 
Query String:   
Get String:   
Post String:   
Forwarded For:   none
Client IP:   none
Remote Address:   190.38.180.203
Remote Port:   2612
Request Method:   GET


Query String:
Code:
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!
query=& query=loquesea&instory=/* */UNION/* */SELECT/* */0,0,pwd,0,aid/* */FROM/* */nuke_authors


Get String:
Code:
Get String:
Only registered users can see links on this board!
Get registered or login to the forums!
*/UNION/* */SELECT/* */0,0,pwd,0,aid/* */FROM/* */nuke_authors


Post String:
Code:
Post String:
Only registered users can see links on this board!
Get registered or login to the forums!


Any ideas as to why this keeps happening ?
View user's profile Send private message
montego
Site Admin


Joined: Aug 29, 2004
Posts: 9133
Location: Arizona

PostPosted: Tue Jan 23, 2007 7:28 am Reply with quote Back to top

If this IP address is truelly that of your admin, then why is he/she attempting to use a UNION attack on your site to show him/her all your admin usernames and passwords?
View user's profile Send private message Visit poster's website
deadl0ck
Hangin' Around


Joined: Apr 09, 2006
Posts: 44

PostPosted: Tue Jan 23, 2007 8:39 am Reply with quote Back to top

I doubt it's my admin - but I think the "none...*" IP address is blockig him from getting to the site

What is "none...*" ?
View user's profile Send private message
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Wed Jan 24, 2007 12:42 am Reply with quote Back to top

I'm not sure why it says "none", esp since it is recording an IP under Remote Address
190.38.180.203

What version of Sentinel are you using?
View user's profile Send private message Visit poster's website
deadl0ck
Hangin' Around


Joined: Apr 09, 2006
Posts: 44

PostPosted: Wed Jan 24, 2007 2:15 am Reply with quote Back to top

AT the top of the NS Admin PAGE I see:

NukeSentinel(tm) 2.4.2pl3

I assume that's the version ?
View user's profile Send private message
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 6373
Location: Vsetin, Czech Republic

PostPosted: Wed Jan 24, 2007 3:24 am Reply with quote Back to top

You really need to update to the latest version but regardless of that, if that is the IP of your admin (you can cross reference his IP easily enough as its listed in his forum posts - its next to the quote / edit / delete buttons) that string does indicate he was attempting a union attack on your site.

The 'blocked ip= ' might be because the IP is protected - thats purely a guess as I dont have a copy of that specific version of Sentinel to check the code.
View user's profile Send private message Send e-mail Visit poster's website
deadl0ck
Hangin' Around


Joined: Apr 09, 2006
Posts: 44

PostPosted: Wed Jan 24, 2007 3:32 am Reply with quote Back to top

He's posted from a few different IPs over a period of time, but the one listed above isn'tan address he's ever posted from - the vast majority of his posts are from the same IP.

What verision should I upgrade to ? The latest ?
View user's profile Send private message
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 6373
Location: Vsetin, Czech Republic

PostPosted: Wed Jan 24, 2007 3:52 am Reply with quote Back to top

Yes you should upgrade to the latest version.
If the IP address in the Sentinel email is not one your user has posted from AND given the fact that the user is listed as 'anonymous' (not logged in) I would be even more included to suspect the user was not an admin.
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum