PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Tue Sep 21, 2004 1:49 pm Reply with quote Back to top

As reported here:
Only registered users can see links on this board!
Get registered or login to the forums!

PUT requests are still being used to deface websites. Why take the risk?
You can easily add PUT to the Nuke Sentinel Request Method blocker and/or in your htaccess.
View user's profile Send private message
chatserv
The Mouse Is Extension Of Arm


Joined: May 02, 2003
Posts: 1396
Location: Puerto Rico

PostPosted: Tue Sep 21, 2004 2:05 pm Reply with quote Back to top

Code:
<Limit PUT>
  Order Allow,Deny
  Deny from all
  Allow from xx.xx.xxx.xxx <-- your ip
</Limit>

<Limit GET POST>
  Order Allow,Deny
  Allow from all
</Limit>
View user's profile Send private message Visit poster's website
oprime2001
Worker
Worker


Joined: Jun 04, 2004
Posts: 119
Location: Chicago IL USA

PostPosted: Tue Sep 21, 2004 3:52 pm Reply with quote Back to top

From the linked sec article, placing a restriction on PUT request would deny file uploads, correct? If so, if I have uploading in a module enabled (e.g. photos in coppermine by registered members), and place a PUT request restriction, the uploading (by members) would fail, correct?
View user's profile Send private message
Muffin
Client


Joined: Apr 10, 2004
Posts: 649
Location: UK

PostPosted: Tue Sep 21, 2004 6:04 pm Reply with quote Back to top

Would it also affect members uploading their own avatars ?
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum