You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 49 guest(s) and 2 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Serious Problem with Fortress Banning a legitimate link [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Wed Jun 09, 2004 1:39 pm Reply with quoteBack to top

Probably caused by missing backslash in regex pattern?

(eregi("\([^>]*\"?[^\)]*\)", $secvalue)) ||

_________________
I'm Image
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Wed Jun 09, 2004 2:21 pm Reply with quoteBack to top

What's happening is the way its written its picking up the parens, which isn't really bad in and of itself -- but you know this I suspect.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Wed Jun 09, 2004 2:29 pm Reply with quoteBack to top

Ahh I see. OK, please let me know if that's what I should do and I'll comment it out.

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Wed Jun 09, 2004 2:32 pm Reply with quoteBack to top

madman wrote:
Probably caused by missing backslash in regex pattern?

(eregi("\([^>]*\"?[^\)]*\)", $secvalue)) ||


Ah well heck, if that will take care of the issue I've posted here I'd rather do that than get rid of this line completely.

I guess I'll have to test it.

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
FHFGhost
Lieutenant
Lieutenant


Joined: Jan 26, 2003
Posts: 279

Location: Huntsville, AL

PostPosted: Wed Jun 09, 2004 2:37 pm Reply with quoteBack to top

It didn't fix the problem for me.

_________________
"I don't know what the key to success is, but the key to failure is trying to please everybody"..Bill Cosby
Image
Find all posts by FHFGhostView user's profileSend private messageSend e-mailVisit poster's websiteMSN Messenger
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Wed Jun 09, 2004 2:42 pm Reply with quoteBack to top

OK, guess I'll scratch testing that then.

Thanks for your feedback!

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Wed Jun 09, 2004 2:44 pm Reply with quoteBack to top

I still have to check the code myself... But I'll get back to you.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
Xeon
Sergeant
Sergeant


Joined: Aug 28, 2003
Posts: 144

Location: USA

PostPosted: Wed Jun 09, 2004 2:45 pm Reply with quoteBack to top

OK great! Thanks Zhen-Xjell

_________________
Xeon
http://www.credit-repair-combat.com/
Find all posts by XeonView user's profileSend private messageVisit poster's website
FHFGhost
Lieutenant
Lieutenant


Joined: Jan 26, 2003
Posts: 279

Location: Huntsville, AL

PostPosted: Wed Jun 09, 2004 2:48 pm Reply with quoteBack to top

Yes thx ZX

_________________
"I don't know what the key to success is, but the key to failure is trying to please everybody"..Bill Cosby
Image
Find all posts by FHFGhostView user's profileSend private messageSend e-mailVisit poster's websiteMSN Messenger
FHFGhost
Lieutenant
Lieutenant


Joined: Jan 26, 2003
Posts: 279

Location: Huntsville, AL

PostPosted: Thu Jun 10, 2004 8:31 pm Reply with quoteBack to top

Any results yet ZX?

_________________
"I don't know what the key to success is, but the key to failure is trying to please everybody"..Bill Cosby
Image
Find all posts by FHFGhostView user's profileSend private messageSend e-mailVisit poster's websiteMSN Messenger
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Fri Jun 11, 2004 8:16 am Reply with quoteBack to top

No not yet... I found a fix last night to the big phpbb search bug problem that everyone is reporting at phpbb.com that affects nukecops and computercops too.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
FHFGhost
Lieutenant
Lieutenant


Joined: Jan 26, 2003
Posts: 279

Location: Huntsville, AL

PostPosted: Tue Jun 15, 2004 12:06 pm Reply with quoteBack to top

Should I just comment out this line? Or will that not fix the problem?

_________________
"I don't know what the key to success is, but the key to failure is trying to please everybody"..Bill Cosby
Image
Find all posts by FHFGhostView user's profileSend private messageSend e-mailVisit poster's websiteMSN Messenger
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Tue Jun 15, 2004 12:12 pm Reply with quoteBack to top

Yes go ahead and comment out the line.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
BooBoo
Nuke Soldier
Nuke Soldier


Joined: Jun 15, 2004
Posts: 10


PostPosted: Tue Jun 15, 2004 7:34 pm Reply with quoteBack to top

Hi,

So should this code block be in the mainfile IF you have Fortress installed?

Code:
foreach ($_POST as $secvalue) {
if ((eregi("<[^>]script*\"?[^>]*>", $secvalue)) || (eregi("<[^>]style*\"?[^>]*>", $secvalue))) {
die ("<center><img src=images/logo.gif><br><br><b>The html tags you attempted to use are not allowed</b><br><br>[ <a href=\"javascript:history.go(-1)\"><b>Go Back</b></a> ]");
}
}


Even though it might be a bit aggressive it still looks like it looks after POST where fortress only looks after GET - or am I wrong?

BooBoo
Find all posts by BooBooView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Wed Jun 16, 2004 6:17 am Reply with quoteBack to top

I agree that the code is agressive, but I haven't done any testing on it.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.296 Seconds - 258 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::