PHP Web Host - Quality Web Hosting For All PHP Applications Clan Themes! We make clans look good!!
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
ladysilver
Hangin' Around


Joined: May 03, 2004
Posts: 49
Location: Cyberspace

PostPosted: Sat Sep 18, 2004 11:42 am Reply with quote Back to top

I have had a few hacking attempts on a site where I have PHP-Nuke 7.4 installed with Sentinel 2.02. Today I received an email from Sentinel as follows:

You Access Changed on [Site Name]

The below information pertains to the HTTPAuth system in NukeSentinel(tm) only!
It does not affect your normal admin login information.


HTTPAuth Login: [not disclosed]
Protected: Is Protected

The header looked legit. I didn't see anything about this anywhere, so if I missed this somewhere in the documentation please excuse me for asking, but why would Sentinel send this? My thoughts are running to an attempt to hack HTTP Auth that (correctly) obtained the login name but not the encrypted password.
View user's profile Send private message Visit poster's website ICQ Number
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Sat Sep 18, 2004 3:24 pm Reply with quote Back to top

This is the email that NukeSentinel will send out when an admin's userid/password is changed in NukeSentinel. Did you modify yours or someone elses?
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
ladysilver
Hangin' Around


Joined: May 03, 2004
Posts: 49
Location: Cyberspace

PostPosted: Sat Sep 18, 2004 4:33 pm Reply with quote Back to top

Hi Raven,

No I didn't change userid or password. I could log in normally using my HTTP Auth name/password combo and the admin username/password combo after HTTP Auth cleared.

After receiving the email I checked both in Sentinel and afterwards in the database in CPanel to make sure there were no new authors or unauthorised changes to exisiting admin accounts. Also checked localhost access to see if anybody might have hacked into the server but did not see anything amiss. I followed this up by checking the logs. Outside of somebody looking for 4NGallery (again) nothing immediately sticks out.

The HTTP Auth username was correct, and I don't use "admin" or "webmaster" or anything that would be unusually easy to guess.

I'm going to go ahead and change all the admin access passwords at that website for general safety, but I am curious what would cause Sentinel to send that emai, if it was in fact generated by Sentinel.
View user's profile Send private message Visit poster's website ICQ Number
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16987
Location: Kansas

PostPosted: Sat Sep 18, 2004 4:43 pm Reply with quote Back to top

Look at the email smtp headers and see where the email originated from.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum