PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 9:12 am Reply with quote Back to top

Thanks!
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Wed Feb 18, 2009 10:11 am Reply with quote Back to top

What version of RN is vulnerable to this captcha problem? Thanks.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Feb 18, 2009 10:45 am Reply with quote Back to top

To our knowledge, any version that uses it. Btw, Greetings! You couldn't have come at a worse time!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 11:37 am Reply with quote Back to top

LOL
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Wed Feb 18, 2009 1:08 pm Reply with quote Back to top

Raven wrote:
To our knowledge, any version that uses it.


Okay, I'll do some diffs and see if the new version will drop easily into my site.

Raven wrote:
Btw, Greetings! You couldn't have come at a worse time!


LOL, sorry to hear that my friend.
View user's profile Send private message
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Wed Feb 18, 2009 1:22 pm Reply with quote Back to top

The fix works on 2.3 and 2.20.10 here ...

Cheers
View user's profile Send private message
Donovan
Client


Joined: Oct 07, 2003
Posts: 735
Location: Ohio

PostPosted: Wed Feb 18, 2009 4:44 pm Reply with quote Back to top

So I used to run a site that still has rn76v2.02

Would they be vulnerable?
View user's profile Send private message Visit poster's website ICQ Number
kguske
Site Admin


Joined: Jun 04, 2004
Posts: 5997

PostPosted: Wed Feb 18, 2009 5:00 pm Reply with quote Back to top

No.
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 5:03 pm Reply with quote Back to top

Everythings working fine on the site now apart from 2 users accounts.

One is an existing mod, and is in the mod group, but I can't give moderating rights in ACP, and the other is a member who I need to make a mod who is in the mod group but can't give moderating rights in ACP.

I get this error message when I try to upgrade both those accounts to mods.

Quote:
Could not obtain moderator status

DEBUG MODE

SQL Error : 1064 You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') AND aa.group_id = ug.group_id AND aa.auth_mod = 1 GROUP BY ug.us' at line 3

SELECT ug.user_id, COUNT(auth_mod) AS is_auth_mod FROM nuke_bbauth_access aa, nuke_bbuser_group ug WHERE ug.user_id IN () AND aa.group_id = ug.group_id AND aa.auth_mod = 1 GROUP BY ug.user_id

Line : 561
File : admin_ug_auth.php


Could someone tell me what I need to do please? Thank you.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Feb 18, 2009 5:09 pm Reply with quote Back to top

I think if you will search for the phrase admin_ug_auth (Search all terms) you will find your answer Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 5:13 pm Reply with quote Back to top

Is that in phpmyadmin in the database Raven?
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Feb 18, 2009 5:17 pm Reply with quote Back to top

Search in these forums Smile
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
kguske
Site Admin


Joined: Jun 04, 2004
Posts: 5997

PostPosted: Wed Feb 18, 2009 5:22 pm Reply with quote Back to top

And look at this:
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 5:22 pm Reply with quote Back to top

Found it Raven, thankyou

Groupfix.php

Just uploading it now
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Wed Feb 18, 2009 5:31 pm Reply with quote Back to top

Thanks for the fix. I looked it over, and it was indeed compatible with my site's version. It seemed that a person would only be vulnerable if they were running with register globals on. Is this correct? Is there any more background or detail on the problem?
View user's profile Send private message
kguske
Site Admin


Joined: Jun 04, 2004
Posts: 5997

PostPosted: Wed Feb 18, 2009 6:27 pm Reply with quote Back to top

Don't think register globals mattered. I'll send you a pm with attack details.
View user's profile Send private message
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Wed Feb 18, 2009 6:30 pm Reply with quote Back to top

Upgraded three production domains without a hitch, all ok, etc.

Cheers
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 6:52 pm Reply with quote Back to top

uploaded recommended files in security announcement and no problems at all since.

Will upgrade fully to v2.3.01 tomorrow

Thank you so much team and Raven.
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 7:49 pm Reply with quote Back to top

I have a problem.

As per previous post above, I uploaded recommended files in security announcement.

Everything seemed ok until I left the site and came back again.

Now I'm getting this problem:

from Home (index.php) can access ACP and all working in there and can access all admin areas with no problems.

from Home (index.php) I cannot access Downloads, Your Account, Forums from the top menu on theme.

I'm getting this error

Quote:
Not Found

The requested URL /main/forums.html was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache/2.2.6 (Unix) mod_ssl/2.2.6 OpenSSL/0.9.7a mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.25 PHP/5.2.5 mod_perl/2.0.3 Perl/v5.8.8 Server at
Only registered users can see links on this board!
Get registered or login to the forums!
Port 80


Thats when I click on Forum, obviously if I clicked on Your Account or Downloads it would say /main/forums/downloads.html

It's probably something I've maybe done uploading the files???
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Feb 18, 2009 8:11 pm Reply with quote Back to top

It sounds like you have activated ShortLinks in rnconfig.php $tnsl_bUseShortLinks = true; but you haven't added the ShortLinks.htaccess contents to your regular .htaccess file. That or your host doesn't allow the Apache RewriteEngine on directive in .htaccess.

See the HowToInstall section for AddOns -> TegoNuke(tm) ShortLinks (Version 1.2.1)
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 8:22 pm Reply with quote Back to top

Thats really weird because all I have done, and I swear I've not touched anything else, too tired I just want to go to bed now after 24hrs with 3hrs sleep lol.

But all I did was upload these files as recommended:

** If you are upgrading from ANY version of RavenNuke(tm) that uses the CAPTCHA System: **
images/captcha.php
**

** If you are upgrading from ANY version of RavenNuke(tm) that uses the Resend Email Module: **
modules/Resend_Email/xx.xx - the entire Resend_Email folder/directory
**

** If you are upgrading from RavenNuke(tm) v2.30.00: **
admin.php
modules/Your_Account/xx.xx - the entire Your_Account folder/directory

I went off my site for a second to check email and came back, clicked on Admin everything fine, went to home, home is fine, clicked on forum and wham, 404 error.

Can I just go into rnconfig.php and put false after $tnsl_bUseShortLinks ???

I dont particularly want short links, I've not activated it.

Would there have been anything in those files I uploaded that would have activated short links?
View user's profile Send private message
cornishpixie
Regular
Regular


Joined: Dec 15, 2008
Posts: 79

PostPosted: Wed Feb 18, 2009 8:33 pm Reply with quote Back to top

Have changed $tnsl_bUseShortLinks=true to =false and it all works ok now. Wonder what would have changed that setting, as that files not been touched since the site was installed last year.

Would the groupfix thing have done anything? Very odd.

Am off to me bed now before I collapse.
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Wed Feb 18, 2009 8:50 pm Reply with quote Back to top

kguske wrote:
Don't think register globals mattered. I'll send you a pm with attack details.


Ok, I'd like to hear about it, thanks.

It looked to me like the fix was just to make sure some variables were defined before first use. That's something you always should do, but especially if register globals is on, otherwise a bad guy could provide his own values for those variables.

Register globals "on" is a really, really bad idea.
View user's profile Send private message
montego
Former Admin in Good Standing


Joined: Aug 29, 2004
Posts: 9071
Location: Arizona

PostPosted: Wed Feb 18, 2009 9:27 pm Reply with quote Back to top

Don't forget that for many reasons, we import the request variables within mainfile.php. Too many add-on modules/blocks/etc. would break otherwise.

I am thinking that captcha came into RN at 2.10.00, so that would be the start of this particular one captcha script issue, but there are more files to upload/fix. Only if you are on RN 2.3.0 do you need the modules/Your_Account/* files. Previous versions, I believe, were not at risk... but, don't quote me on that.
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Thu Feb 19, 2009 3:07 am Reply with quote Back to top

cornishpixie wrote:
Have changed $tnsl_bUseShortLinks=true to =false and it all works ok now. Wonder what would have changed that setting, as that files not been touched since the site was installed last year.

Would the groupfix thing have done anything? Very odd.

Am off to me bed now before I collapse.


I verified it's what I had thought. If you add the contents of ShortLinks.htaccess to your .htaccess and then set the 2 settings in rnconfig.php back to true, all should work just fine. If I remember right you had restored your .htaccess file when you were having those cgiauth issues.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum