PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
pureliving
Worker
Worker


Joined: Dec 01, 2008
Posts: 175

PostPosted: Sun Mar 08, 2009 4:12 pm Reply with quote Back to top

I have not been able to access my admin for over a week now, starting a few days after the update.
I originally thought it was nuke sentinal issue, but now i'm confused.

I have had several people look into this, with no-one able to provide any conclusive reason, until i just received an email stating:

[Regarding this email, it would appear that someone is trying to send email from your admin script using a potential exploit. Are you using the most recent version of phpnuke?

The IP address in question is a twtelecom.net email address. I'm assuming this isn't your ISP, would it be OK with you if we block this IP from the server?

That email was stopped by our server due to the From: header used.]

It would really be appreciated if someone could advice me please.
View user's profile Send private message
pureliving
Worker
Worker


Joined: Dec 01, 2008
Posts: 175

PostPosted: Sun Mar 08, 2009 5:22 pm Reply with quote Back to top

I believe there to be a step missing in the nuke sentinal configuration steps in the confns document, which is discussed upon a karakas-online forum topic:

Quote:

Log into your site's admin.php and click on the Nuke Sentinel icon. From the Nuke Sentinel Administration menu, select "Protected Range Menu". In that new menu, Click on "Add Protected Range." Add your IP, select your country and click on the "Add Protected Range" button. Be sure to complete both the "IP From:" and "IP To:" rows.


I forgot to do anything along this line, with so many things to think about with the upgrade, etc, now i'm not protected, and from looking into the IP address, i found the above to be my host themselves, which caused big confusion with them and myself.

It seems that within the upgrade somehow this has triggered something in admin, creating a potential exploit with email, although exactly what is the issue i and others looking into this for me can not quite work out.

Taking note of above and the fact i did not do this upon upgrade, and the fact now i can not get access to my admin properly, do you have any suggestions at all as to what i may do to solve this?

Please, please help me someone, i feel like i am going around in circles, of which having to rely on a few people aswel is becoming quite an headache of time, and the fact of having to ask in the first place.
eeergh. Bang Head

xx Bless xx
View user's profile Send private message
alien73
Involved
Involved


Joined: Sep 15, 2008
Posts: 352

PostPosted: Sun Mar 08, 2009 6:57 pm Reply with quote Back to top

Did you check your database directly and make sure the admin name hasn't changed?
View user's profile Send private message Visit poster's website
pureliving
Worker
Worker


Joined: Dec 01, 2008
Posts: 175

PostPosted: Sun Mar 08, 2009 7:13 pm Reply with quote Back to top

Admin names seem correct, although would it be correct for nsnst_admins, to show my password, without encryption, as isn't this a security problem:

password <- password_md5 password_crypt
View user's profile Send private message
alien73
Involved
Involved


Joined: Sep 15, 2008
Posts: 352

PostPosted: Sun Mar 08, 2009 7:33 pm Reply with quote Back to top

no it should be encrypted.. Did you look into your email (Qmail etc... via SSH? It will show who really sent the email.

Example with qmail using plesk

var/qmail/bin/qmail-qread
View user's profile Send private message Visit poster's website
pureliving
Worker
Worker


Joined: Dec 01, 2008
Posts: 175

PostPosted: Sun Mar 08, 2009 9:31 pm Reply with quote Back to top

Ok thank you for the tip, i have used function to encrypt the password; thought it were strange when supposed to be secure.
Anyway as i still can not get access and looking further into this, this is what part of one email states:

Quote:

Created By: NukeSentinel(tm) 2.6.02
Date &amp; Time: 2009-03-08 21:06:44 CDT GMT -0500
Blocked IP: ***.***.**.***
User ID: Anonymous (1)
Reason: Abuse-Admin
--------------------
Referer: on site
User Agent: **************************************************
HTTP Host: mywebsite.com
Script Name: /admin.php
Query String: op=AdvertisingAdmin
Get String: op=AdvertisingAdmin
Post String: Not Available
Forwarded For: none
Client IP: none
Remote Address: ***.***.**.***
Remote Port: 26596
Request Method: GET


Apparently there's a problem with admin related links all being blocked to ips when they are clicked, and we can not figure out exactly what's blocking it, to look at a solution; even others looking into this all keep getting blocked after the CGIAuth login box access successful.
All ips get removed from nsnst_blocked_ips, then try all over again.
My .htaccess file has been removed for time being, and i have even tried just commenting out the code to staccess, but still no access and still everyone looking into this keeps getting blocked.
View user's profile Send private message
montego
Site Admin


Joined: Aug 29, 2004
Posts: 9136
Location: Arizona

PostPosted: Tue Mar 10, 2009 6:55 am Reply with quote Back to top

alien73 wrote:
no it should be encrypted.. Did you look into your email (Qmail etc... via SSH? It will show who really sent the email.

Example with qmail using plesk

var/qmail/bin/qmail-qread


No, it should NOT be encrypted. NukeSentinel has always stored the admin password this way. Yeah, its not the best, but if you change it, there is a chance it will not work - have not tried - just a warning.
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum