PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
magnum
Client


Joined: Jun 23, 2006
Posts: 83

PostPosted: Wed Sep 27, 2006 11:48 pm Reply with quote Back to top

i had a person trying to register on my page and sentinel kept saying it was a santy worm attack now after reading further i found the the word rush in his name was setting it off. now i turned santy worm off in sentinel and he was able to register now . now my question is if i turn the santy worm back on in sentinel will he be blocked from loging on ? or should i leave it off? is the page at risk if its left off? thank you
View user's profile Send private message
montego
Site Admin


Joined: Aug 29, 2004
Posts: 8625
Location: Arizona

PostPosted: Thu Sep 28, 2006 5:55 am Reply with quote Back to top

When those attacks were being made, people were trying to stop it with .htaccess directives. Several folks posted these for stop Santy and possibly other attacks:

Code:

RewriteCond %{HTTP_USER_AGENT} ^LWP                     [NC,OR]
RewriteCond %{REQUEST_URI} ^visualcoders                [NC,OR]
RewriteCond %{QUERY_STRING} rush=([^&]+)                [NC,OR]
RewriteCond %{REQUEST_URI} ^envidiosos                  [NC,OR]
RewriteCond %{REQUEST_URI} ^civa                        [NC,OR]
#variant-6 redirect all inner http:// request
RewriteCond %{QUERY_STRING} ^(.*)http://(.*)$           [NC,OR]
#variant-7 redirect all inner http request regardless if encoded
RewriteCond %{QUERY_STRING} ^(.*)http%3A%2F%2F(.*)$     [NC,OR]
#Variant-X
RewriteCond %{REQUEST_URI} ^(.*)cgi-bin(.*)             [NC,OR]
RewriteCond %{QUERY_STRING} ^(.*)wget(.*)$              [NC,OR]
RewriteRule ^.*$ http://127.0.0.1 [R,L]


This is probably overkill. It is also possible that the whole issue has been resolved already with phpBB, but not sure. You can see the "rush=" line?
View user's profile Send private message Visit poster's website
technocrat
Life Cycles Becoming CPU Cycles


Joined: Jul 07, 2005
Posts: 508

PostPosted: Thu Sep 28, 2006 9:14 am Reply with quote Back to top

The sanity attack is pretty much old news. There really isnt a reason to continue to block against. Even more so if you have been keeping up on your forum patches.
View user's profile Send private message
magnum
Client


Joined: Jun 23, 2006
Posts: 83

PostPosted: Thu Sep 28, 2006 10:32 am Reply with quote Back to top

thanks very much Smile
View user's profile Send private message
montego
Site Admin


Joined: Aug 29, 2004
Posts: 8625
Location: Arizona

PostPosted: Thu Sep 28, 2006 8:05 pm Reply with quote Back to top

technocrat, thanks!
View user's profile Send private message Visit poster's website
Doulos
Involved
Involved


Joined: Jun 06, 2005
Posts: 454

PostPosted: Sat Apr 12, 2008 9:28 pm Reply with quote Back to top

I am getting the same issue with the name Soul_Crusher.

This user keeps getting this message when he tries to log in:
Quote:
Possible Santy Worm Attack!

The weird thing is if after getting the above warning, he just types in our URL, it goes to our home page and he is logged in.

Soul_Crusher is not in my htaccess file, the only instance that is remotely similar is one of "Conecrusher"

Turned off Santy Worm protection.
View user's profile Send private message
jakec
Site Admin


Joined: Feb 06, 2006
Posts: 2878
Location: United Kingdom

PostPosted: Sun Apr 13, 2008 4:42 am Reply with quote Back to top

What settings did you have for the blocker? It may not have been set to permanently block.

Anyway by the sounds of it you should not be at risk anymore if you disable the blocker, if you are running the latest patches etc.
View user's profile Send private message
Doulos
Involved
Involved


Joined: Jun 06, 2005
Posts: 454

PostPosted: Sun Apr 13, 2008 9:24 am Reply with quote Back to top

I don't even know if there are settings I can change. I just had the Santy Worm Protection set to ON, in the NS admin main page.
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2010 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum