PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
skeen
Hangin' Around


Joined: Jul 17, 2003
Posts: 29

PostPosted: Tue Dec 28, 2004 10:02 pm Reply with quote Back to top

I have noticed an error in my forums after upgrading to 2.13.
I use 7.11nsn and now when you click on posts since last visit, then try to click on a post you get an illegal content error.
It appears that it is not send the full string to view the posting.

I know it sounds crazy but it was working fine and I have not altered the forums in anyway, I have just reinstated a backup to make sure but still no joy.

/modules.php?name=Forums&file=viewtopic&t=348&highlight=

bit missing of the end, any ideas ????
View user's profile Send private message
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Tue Dec 28, 2004 10:06 pm Reply with quote Back to top

Theat is in hte Santy Worm protection. Open includes/sentinel.php and find:
Code:
$bad_uri_content="rush,highlight,perl,chr(,pillar,visualcoder,sess_";


Now change it to:
Code:
$bad_uri_content="rush,perl,chr(,pillar,visualcoder,sess_";
View user's profile Send private message Send e-mail Visit poster's website
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Tue Dec 28, 2004 10:15 pm Reply with quote Back to top

Strange it doesn't happen when using the search function where highlight is used too.
View user's profile Send private message
skeen
Hangin' Around


Joined: Jul 17, 2003
Posts: 29

PostPosted: Tue Dec 28, 2004 10:22 pm Reply with quote Back to top

Thanks Bob for the quick reply, that did fix the problem.
You are a legend Smile
worship
View user's profile Send private message
skeen
Hangin' Around


Joined: Jul 17, 2003
Posts: 29

PostPosted: Tue Dec 28, 2004 11:46 pm Reply with quote Back to top

Bob I have another module that wont work after the upgrade, this is the end of the string...

/modules.php?name=MyModule&id=20

any idea on this one ??

If that doesnt help you I can send you the file
View user's profile Send private message
raul2010
New Member
New Member


Joined: Aug 06, 2004
Posts: 5

PostPosted: Wed Dec 29, 2004 5:55 am Reply with quote Back to top

BobMarion wrote:
Theat is in hte Santy Worm protection. Open includes/sentinel.php and find:
Code:
$bad_uri_content="rush,highlight,perl,chr(,pillar,visualcoder,sess_";


Now change it to:
Code:
$bad_uri_content="rush,perl,chr(,pillar,visualcoder,sess_";

but if i'm not wrong, this code would also ban something like this:
Code:
/modules.php?name=Forums&file=viewtopic&t=348&highlight=perl

which could be perfectly legitimate

is there no other way?
View user's profile Send private message
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum