PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
jimmo
Worker
Worker


Joined: Dec 08, 2005
Posts: 107

PostPosted: Tue May 22, 2007 12:23 am Reply with quote Back to top

Hi All!

I am using RN 2.02. I have had a couple of cases in the past few days where users have been blocked with messages claiming they have attempted a string attack. The data looks like this:

User Agent: Mozilla/5.0 (compatible; Konqueror/3.3; Linux) (KHTML, like Gecko)
Remote Address: X.X.X.X
Client IP: none
Forwarded For: 127.0.0.1
Date Blocked: 2007-05-14 @ 21:39:09 EDT GMT -0400
Block expires: Permanent

I found references in the forums indicating that the problem is "Client IP: none". While I understand the necessity for things like this, I am curious about a couple of things.

First, why this is being reported as a string attack? I looked in nukesentinel.php and did not see anything that would cause this to be considered a string attack. Also, I see nothing in the "String Blocker Settings" or the general configuration that defaults to the string attacks. In each case the Remote Address is valid.

The other thing is how to prevent this kind of thing. I could protect the IPs in question, but that seems like the long way around. Since the remote address is valid, is there way of configuring Sentinel so that it does not block if the Client IP is none?

Any help is appreciated.
View user's profile Send private message
hitwalker
Sells PC To Pay For Divorce


Joined:
Posts: 5661

PostPosted: Tue May 22, 2007 2:43 am Reply with quote Back to top

have a look at this..
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message
jimmo
Worker
Worker


Joined: Dec 08, 2005
Posts: 107

PostPosted: Sat May 26, 2007 1:28 am Reply with quote Back to top

Thanks for the tip. However, I am confused now. Inside nukesentinel.php I have commented out the entire block "Invalid ip check". I did this because of something in another post, but it seems that setting
$bypassNukeSentinelInvalidIPCheck = TRUE is the cleaner solution. However, as far as I can see, the only place the value is checked in inside that block in nukesentinel.php. So, if the block is commented out, it should have the same effect. Or am I missing something?
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Sat May 26, 2007 12:41 pm Reply with quote Back to top

Sentinel lists a reason for a block, and I don't see it in the info you gave. The Client IP: none may not be the reason, it may just be reporting the fact that the client had masked their IP. Sentinel will also report the GET and POST strings. Do you have these? These would be helpful in trying to decide if it tripped on a string block.
View user's profile Send private message
jimmo
Worker
Worker


Joined: Dec 08, 2005
Posts: 107

PostPosted: Thu May 31, 2007 12:39 pm Reply with quote Back to top

In each case it says

You have been blocked from entering this site.
You have attempted a String attack on this site.

I cannot see anything in the string block configuration that should cause problems. First, it is simply a list of domain names that are know spam havens, etc. (pulled off the forums here). In nukesentinel.php, I see in the block following "Check for Strings", it looks at query_string, get_string, and post_string. A couple of users are saying they are blocked even when inputting the main URL directly with no query string, so I am assuming no get_string or post_string.

For all blocks, I have email notification activated, but the IPs being blocked like this are not being reported via email. I also do not find any matching IP ranges being blocked.
View user's profile Send private message
jimmo
Worker
Worker


Joined: Dec 08, 2005
Posts: 107

PostPosted: Mon Jun 11, 2007 11:07 pm Reply with quote Back to top

I hate to be a pest, but I still have this problem. From all I see so far, this should not be happening. I am more than willing to provide any additional information or change the code to track down this problem. I just need someone to tell me where and what.

best regards,

jimmo
View user's profile Send private message
montego
Former Admin in Good Standing


Joined: Aug 29, 2004
Posts: 9071
Location: Arizona

PostPosted: Tue Jun 12, 2007 6:53 am Reply with quote Back to top

jimmo, check out this thread here. I believe BobMarion posted a code change that might work for you.
View user's profile Send private message Visit poster's website
montego
Former Admin in Good Standing


Joined: Aug 29, 2004
Posts: 9071
Location: Arizona

PostPosted: Tue Jun 12, 2007 6:54 am Reply with quote Back to top

I guess it would have worked out better for me to actually post the !@#$% link! Embarassed

Here it is:
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message Visit poster's website
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum