You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 48 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Can't create accounts [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
BillShiver
Nuke Soldier
Nuke Soldier


Joined: Jan 30, 2003
Posts: 34

Location: USA

PostPosted: Sat Feb 01, 2003 5:19 pm Reply with quoteBack to top

I just haven't setup a uname yet. I run other test php scripts from mysql without uname and password invoked.

Can you tell me what this means?

http://www.outdoorscentral.com/analyze.php?zx=ls

Thanks
Bill
Find all posts by BillShiverView user's profileSend private messageVisit poster's website
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sat Feb 01, 2003 5:51 pm Reply with quoteBack to top

No uname eh? What is also interesting is that your site has no admins nor moderators. You can't even setup an author?

As for the link, its a complete directory listing. I placed it in analyzer because many times we ask folks about missing files, etc. Now with analyzer, we can look ourselves saving much time.

In the meantime, one more quick re-download of anal.tar.gz? Its release 1.89 now. This should be ready for release after another test or two.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
BillShiver
Nuke Soldier
Nuke Soldier


Joined: Jan 30, 2003
Posts: 34

Location: USA

PostPosted: Sun Feb 02, 2003 6:43 am Reply with quoteBack to top

I know the lack of a uname on the db is odd, but for testing purposes I do this because my server provider has to set those for me. I understand it could cause some probllems and would not do that on a working site.

In fact, I was set up as admin. The sysem told me I was "God". I went in and setup another just to be sure it worked and it did, so now there are two admins.

Here is the latest analyzer.

www.outdoorscentral.com/analyze.php

Thanks again, and I see that 7 is out. Don't know if I should bother with it at this point or not. What's your feeling?

Bill
Find all posts by BillShiverView user's profileSend private messageVisit poster's website
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sun Feb 02, 2003 10:16 am Reply with quoteBack to top

Odd for a host to disallow the samllest things, yet allow two vulnerabilties to exist? They don't even allow php.ini parsing.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
BillShiver
Nuke Soldier
Nuke Soldier


Joined: Jan 30, 2003
Posts: 34

Location: USA

PostPosted: Sun Feb 02, 2003 10:33 am Reply with quoteBack to top

I have no idea what php.ini parsing would be. On my very first post here I emphasized that I was a newbie and a dummy. While I have been building and hosting web sites for 9 years, its only in the past couple of months that I have been working with php and mysql. Obviously, I have lots to learn.

I have a virtual server and my provider tells me that they are working to implement new versions to address the vulnerability issues. I've been with them for 5 years and they have always been honest with me. I will ask about the parsing issue however.

I am downloading the 7 upgrade and will see how it works.

Again, I sincerely appreciate your input, suggestions, tips and assistance.

Bill
Find all posts by BillShiverView user's profileSend private messageVisit poster's website
BillShiver
Nuke Soldier
Nuke Soldier


Joined: Jan 30, 2003
Posts: 34

Location: USA

PostPosted: Sun Feb 02, 2003 12:55 pm Reply with quoteBack to top

Thought I would let you know that I uploaded all the beta7 files and pretty much everything works now. people can add accounts, etc.

I did notice that the bug in sessions.php, lines 198 and 199 is still there. I had to add double slashes // in front of these lines and all worked.

Anyway, its seems that most problems have been cured by 7.

Thanks,
Bill
Find all posts by BillShiverView user's profileSend private messageVisit poster's website
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sun Feb 02, 2003 1:06 pm Reply with quoteBack to top

Parsing php.ini, being able to either call it from memory (because at run time, php.ini gets loading into memory) and deliver the details of its configuration. If unable to get it from memory, be able to actually read php.ini and via PHP's internal functions, parse it... look for configuration settings and show them.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.364 Seconds - 158 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::