PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Thu Jun 03, 2004 6:49 am Reply with quote Back to top

I received my first hit with Sentinel(tm). It was an Inktomi crawler and the reason given was SCRIPT. Can someone tell me exactly one happened? Thank you, Steve
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Thu Jun 03, 2004 6:58 am Reply with quote Back to top

Without revealing your path info, post the email you received.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Thu Jun 03, 2004 7:10 am Reply with quote Back to top

It was sent to Rebecca, I will post it as soon as she forwards it. Thank you.
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Thu Jun 03, 2004 1:20 pm Reply with quote Back to top

Here is the email:
Quote:

----- Original Message -----
Sent: Thursday, June 03, 2004 12:47 AM
Subject: Abuse Blocked on xxxxx


>
> Date & Time: 2004-06-03 02:47:28
> Blocked IP: 66.196.90.7
> User ID: Anonymous (1)
> Reason: Abuse - SCRIPT
> --------------------
> User Agent: Mozilla/5.0 (compatible; Yahoo! Slurp;
Only registered users can see links on this board!
Get registered or login to the forums!

> Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

ndex&l_op=ratelink&lid=6&ttitle=GRC_(Steve_Gibson_Research_Corporation)
> Forwarded For: none
> Client IP: none
> Remote Address: 66.196.90.7
> Remote Port: 54792
> Request Method: GET
> --------------------
> Who-Is for IP
> 66.196.90.7
>
>
>
>
> OrgName: Inktomi Corporation
> OrgID: INKT
> Address: 4100 East Third Avenue
> City: Foster City
> StateProv: CA
> PostalCode: 94404
> Country: US
>
> NetRange: 66.196.64.0 - 66.196.127.255
> CIDR: 66.196.64.0/18
> NetName: INKTOMI-BLK-3
> NetHandle: NET-66-196-64-0-1
> Parent: NET-66-0-0-0-0
> NetType: Direct Allocation
> NameServer: NS1.YAHOO.COM
> NameServer: NS2.YAHOO.COM
> NameServer: NS3.YAHOO.COM
> NameServer: NS4.YAHOO.COM
> NameServer: NS5.YAHOO.COM
> Comment: This netblock contains Web Crawlers. Please
> Comment: contact
Only registered users can see links on this board!
Get registered or login to the forums!
for questions or concerns.
> RegDate: 2001-10-30
> Updated: 2003-09-26
>
> AbuseHandle: ZI107-ARIN
> AbuseName: Inktomi Corporation
> AbusePhone: +1-650-653-2800
> AbuseEmail:
Only registered users can see links on this board!
Get registered or login to the forums!

>
> TechHandle: ZI35-ARIN
> TechName: Inktomi Corporation
> TechPhone: +1-650-653-2800
> TechEmail:
Only registered users can see links on this board!
Get registered or login to the forums!

>
> OrgTechHandle: ZI35-ARIN
> OrgTechName: Inktomi Corporation
> OrgTechPhone: +1-650-653-2800
> OrgTechEmail:
Only registered users can see links on this board!
Get registered or login to the forums!

>
>
>


View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Thu Jun 03, 2004 1:47 pm Reply with quote Back to top

It's the () in the url. Just for curiosity, try that same url but filter out this part
Code:
&ttitle=GRC_(Steve_Gibson_Research_Corporation)
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Thu Jun 03, 2004 4:16 pm Reply with quote Back to top

The link works with or without the (). I removed them. Should I consider this a false positive and remove the ban?
View user's profile Send private message
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Thu Jun 03, 2004 4:24 pm Reply with quote Back to top

This is a false positive Smile In the "Script" blocker there is a regex check that has the ( and ) in it. This is also in the native nuke script checkers. We are looking for a way to prevent it from triggering the blocker but at the same it would then trigger the native script protection.
View user's profile Send private message Send e-mail Visit poster's website
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Thu Jun 03, 2004 4:30 pm Reply with quote Back to top

Thank you, Bob. I will remove the block.
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum