Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
akis
New Member
New Member



Joined: Jun 11, 2004
Posts: 9

PostPosted: Fri Jun 11, 2004 4:27 pm Reply with quote

i have installed sentinel and before some minutes i took 4-5 mails :

Blocked IP : xxxxxxxxxx

User ID : Anonymous (1)

Reason : Abuse - SCRIPT

User Agent : ia_archiver

Query String : [ Only registered users can see links on this board! Get registered or login! ]"STYLE=\"text-decoration:

Remote Port :

Request Method : GET



All has the same query string but different userids(u=40, u=3 etc) and all are in different Remote Ports.

Can someone tell me what is this, if it is dangerous or else?

Tnx
 
View user's profile Send private message
sixonetonoffun
Spouse Contemplates Divorce



Joined: Jan 02, 2003
Posts: 2496

PostPosted: Fri Jun 11, 2004 4:36 pm Reply with quote

What is causing the style tag to be in your url? Thats why its flagged as a script attack? I have assume something is not normal about your profiles config there is no reason for the style tag to be in the url normally.
 
View user's profile Send private message
akis







PostPosted: Fri Jun 11, 2004 4:43 pm Reply with quote

well, i don't understand that you say about something not normal in profile config.

It is the first time i see that, in the sentinel's mail. When i go to my site's forum user profiles all are ok, it doesn't show this strange thing with Style tag.

any idea?
 
sixonetonoffun







PostPosted: Fri Jun 11, 2004 4:54 pm Reply with quote

[ Only registered users can see links on this board! Get registered or login! ]"STYLE=\"text-decoration:
should be like this [ Only registered users can see links on this board! Get registered or login! ]

I would guess somewhere in your site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration:

You'll have to do some poking around to find it though maybe check your server logs if nothing else.
 
akis







PostPosted: Fri Jun 11, 2004 5:05 pm Reply with quote

yes, it should be this, and i think it is, because there is nowhere such a link in my site. All forum profile links there are in my site, i checked all now, are ok, without the "STYLE=\"text-decoration: .

it is really strange this, i can't understand why.

anyway, i hope not to be dangerous, and thank you very much for the replys:)
 
akis







PostPosted: Fri Jun 11, 2004 5:53 pm Reply with quote

Quote:
I would guess somewhere in your site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration:


i have the default subSilver theme for my forum and my site's theme doesn't have the code text-decoration nowhere, except the style.css file, but even this theme is one of the defaults of phpnuke.

In other modules, blocks etc, there are no forum profile links.

So, what is happening? i am confused, i don't want to ban something without reason Crying or Very sad
 
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Fri Jun 11, 2004 6:03 pm Reply with quote

Just a quick note, the UserAgent is also banned if you are using the Harvester option. That leads me to believe this is something you want banned.
 
View user's profile Send private message
akis







PostPosted: Sat Jun 12, 2004 3:22 am Reply with quote

Raven, i have the Harvester option Off.
 
Raven







PostPosted: Sat Jun 12, 2004 4:45 am Reply with quote

Raven wrote:
Just a quick note, the UserAgent is also banned if you are using the Harvester option. That leads me to believe this is something you want banned.
Note, I said if you are using the Harvester option. I was just alerting you that it would have been caught HAD you been using it. Regardless, I don't know why you want your site raped, but that's your business Confused
 
akis







PostPosted: Sat Jun 12, 2004 9:46 am Reply with quote

raven, sorry my english are not very good, and i don't understand you very well.

i have harvest option off because when i have it on, my site is very slow.

about the [ Only registered users can see links on this board! Get registered or login! ]"STYLE=\"text-decoration:

sixonetonoffun said that maybe this is something not normal about profiles config. somewhere in site where profiles links exist there is an error in the theme thats causing the crawler to pickup the \"STYLE=\"text-decoration:


is there any explanation of what is and why is banned? because as i told in previous post, there is no such a link in my site nowhere.

This was a Script abuse, you say that i have to have the harvest option on, and that was happened was a "rape" attempt of my site from a crawler?

give me your lights Smile
 
sixonetonoffun







PostPosted: Sat Jun 12, 2004 10:18 am Reply with quote

style= is banned because style attributes can be used to enable script based attacks. cookie harvesting and redirections are very common abuses of style=.
 
akis







PostPosted: Sat Jun 12, 2004 12:08 pm Reply with quote

sorry if i make you be tired of my questions, but i would like to know if the
[ Only registered users can see links on this board! Get registered or login! ]"STYLE=\"text-decoration:

is a hack attempt or something else not bad thing.

tnx
 
Raven







PostPosted: Sat Jun 12, 2004 12:27 pm Reply with quote

There should never be this type of query, so whether it is a hack attempt or not, it isn't a natural query from nuke.
 
akis







PostPosted: Sat Jun 12, 2004 3:02 pm Reply with quote

ok, thanks Smile

but it is strange, isn't it?
 
sixonetonoffun







PostPosted: Sat Jun 12, 2004 5:16 pm Reply with quote

I'd check out all your user blocks because that looks like a line from block-Forums.php to me or one of the custom versions of it.

Here is another example of where bad urls like that come from this user posted a nice html formated story at [ Only registered users can see links on this board! Get registered or login! ] but as you can see there are a lot of nasty urls in there that are probably being parsed by not so smart search engines like the notorious ia_archiver!

If links to one of our sites get hosed like that we may find this happening a lot. Even if the site allowed html I'm sure they don't allow usuage of styles like this submitted from users.
 
akis







PostPosted: Sat Jun 12, 2004 6:01 pm Reply with quote

sixonetonoffun, i found the ("STYLE=\"text-decoration: none) in a scroll forum block i have, but i have it visible only for administrators, and i don't have any other forum block or else, visible to all, with that code inside.

I thought that crawlers can't "see" "only for administrators" things.

Anyway, i put out this code from that block, even noone can see it.

Thank you very much again for the help, i appreciate it Very Happy
 
Raven







PostPosted: Sat Jun 12, 2004 6:45 pm Reply with quote

Crawlers will see everything they want to. Even robots.txt are on an "if you want to abide by" agreement. They do not have to honor them. That's why we usually ban them Evil or Very Mad
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©