| Author |
Message |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Fri Jun 11, 2004 4:27 pm |
|
i have installed sentinel and before some minutes i took 4-5 mails :
Blocked IP : xxxxxxxxxx
User ID : Anonymous (1)
Reason : Abuse - SCRIPT
User Agent : ia_archiver
Query String : "STYLE=\"text-decoration:
Remote Port :
Request Method : GET
All has the same query string but different userids(u=40, u=3 etc) and all are in different Remote Ports.
Can someone tell me what is this, if it is dangerous or else?
Tnx |
|
|
|
 |
sixonetonoffun Spouse Contemplates Divorce

Joined: Jan 02, 2003 Posts: 2499
|
Posted:
Fri Jun 11, 2004 4:36 pm |
|
What is causing the style tag to be in your url? Thats why its flagged as a script attack? I have assume something is not normal about your profiles config there is no reason for the style tag to be in the url normally. |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Fri Jun 11, 2004 4:43 pm |
|
well, i don't understand that you say about something not normal in profile config.
It is the first time i see that, in the sentinel's mail. When i go to my site's forum user profiles all are ok, it doesn't show this strange thing with Style tag.
any idea? |
|
|
|
 |
sixonetonoffun Spouse Contemplates Divorce

Joined: Jan 02, 2003 Posts: 2499
|
Posted:
Fri Jun 11, 2004 4:54 pm |
|
"STYLE=\"text-decoration:
should be like this
I would guess somewhere in your site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration:
You'll have to do some poking around to find it though maybe check your server logs if nothing else. |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Fri Jun 11, 2004 5:05 pm |
|
yes, it should be this, and i think it is, because there is nowhere such a link in my site. All forum profile links there are in my site, i checked all now, are ok, without the "STYLE=\"text-decoration: .
it is really strange this, i can't understand why.
anyway, i hope not to be dangerous, and thank you very much for the replys:) |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Fri Jun 11, 2004 5:53 pm |
|
| Quote: | | I would guess somewhere in your site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration: |
i have the default subSilver theme for my forum and my site's theme doesn't have the code text-decoration nowhere, except the style.css file, but even this theme is one of the defaults of phpnuke.
In other modules, blocks etc, there are no forum profile links.
So, what is happening? i am confused, i don't want to ban something without reason  |
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Fri Jun 11, 2004 6:03 pm |
|
Just a quick note, the UserAgent is also banned if you are using the Harvester option. That leads me to believe this is something you want banned. |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Sat Jun 12, 2004 3:22 am |
|
Raven, i have the Harvester option Off. |
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Sat Jun 12, 2004 4:45 am |
|
| Raven wrote: | | Just a quick note, the UserAgent is also banned if you are using the Harvester option. That leads me to believe this is something you want banned. | Note, I said if you are using the Harvester option. I was just alerting you that it would have been caught HAD you been using it. Regardless, I don't know why you want your site raped, but that's your business  |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Sat Jun 12, 2004 9:46 am |
|
raven, sorry my english are not very good, and i don't understand you very well.
i have harvest option off because when i have it on, my site is very slow.
about the "STYLE=\"text-decoration:
sixonetonoffun said that maybe this is something not normal about profiles config. somewhere in site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration:
is there any explanation of what is and why is banned? because as i told in previous post, there is no such a link in my site nowhere.
This was a Script abuse, you say that i have to have the harvest option on, and that was happened was a "rape" attempt of my site from a crawler?
give me your lights  |
|
|
|
 |
sixonetonoffun Spouse Contemplates Divorce

Joined: Jan 02, 2003 Posts: 2499
|
Posted:
Sat Jun 12, 2004 10:18 am |
|
style= is banned because style attributes can be used to enable script based attacks. cookie harvesting and redirections are very common abuses of style=. |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Sat Jun 12, 2004 12:08 pm |
|
sorry if i make you be tired of my questions, but i would like to know if the
"STYLE=\"text-decoration:
is a hack attempt or something else not bad thing.
tnx |
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Sat Jun 12, 2004 12:27 pm |
|
There should never be this type of query, so whether it is a hack attempt or not, it isn't a natural query from nuke. |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Sat Jun 12, 2004 3:02 pm |
|
ok, thanks
but it is strange, isn't it? |
|
|
|
 |
sixonetonoffun Spouse Contemplates Divorce

Joined: Jan 02, 2003 Posts: 2499
|
Posted:
Sat Jun 12, 2004 5:16 pm |
|
I'd check out all your user blocks because that looks like a line from block-Forums.php to me or one of the custom versions of it.
Here is another example of where bad urls like that come from this user posted a nice html formated story at but as you can see there are a lot of nasty urls in there that are probably being parsed by not so smart search engines like the notorious ia_archiver!
If links to one of our sites get hosed like that we may find this happening a lot. Even if the site allowed html I'm sure they don't allow usuage of styles like this submitted from users. |
|
|
|
 |
akis New Member


Joined: Jun 11, 2004 Posts: 9
|
Posted:
Sat Jun 12, 2004 6:01 pm |
|
sixonetonoffun, i found the ("STYLE=\"text-decoration: none) in a scroll forum block i have, but i have it visible only for administrators, and i don't have any other forum block or else, visible to all, with that code inside.
I thought that crawlers can't "see" "only for administrators" things.
Anyway, i put out this code from that block, even noone can see it.
Thank you very much again for the help, i appreciate it  |
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Sat Jun 12, 2004 6:45 pm |
|
Crawlers will see everything they want to. Even robots.txt are on an "if you want to abide by" agreement. They do not have to honor them. That's why we usually ban them  |
|
|
|
 |
|
|
|
|