You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 50 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - A dumb question.... [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Sun Jun 13, 2004 5:38 am Reply with quoteBack to top

Umm.,...Its just one file!?
Find all posts by actingbiz1View user's profileSend private message
bretonmage
Captain
Captain


Joined: Feb 21, 2004
Posts: 421


PostPosted: Sun Jun 13, 2004 6:01 am Reply with quoteBack to top

Yes.

_________________
Image
Find all posts by bretonmageView user's profileSend private message
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Sun Jun 13, 2004 8:03 am Reply with quoteBack to top

Ok, does it have some sortof interface? How do I know its working? i type
http://vercettihq.gta-nation.com/fortress.php and it goes to index.php
Find all posts by actingbiz1View user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sun Jun 13, 2004 8:20 am Reply with quoteBack to top

Fortress.php is not allowed to be called directly. You can see how it works here:

http://nukecops.com/fortress.htm
http://nukecops.com/fortress.csv

Read the fortress.php for instructions (including the end of the file).

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Sun Jun 13, 2004 11:05 am Reply with quoteBack to top

ok great thanks!

EDIT: Where/how do I access the .htm and csv files?
Find all posts by actingbiz1View user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sun Jun 13, 2004 12:15 pm Reply with quoteBack to top

They should get created by the web server, if not, you can manually create them... read the end of the fortress.php file.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Sun Jun 13, 2004 3:18 pm Reply with quoteBack to top

It only had PHP code no real instructions....
Find all posts by actingbiz1View user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sun Jun 13, 2004 3:21 pm Reply with quoteBack to top

Really? Is has this inside:

Quote:
SUPPORT
If Fortress(TM) is unable to create fortress.csv and fortress.htm then simply create them yourself
using the text below and ensure your web server can append (write) information to them.


Just copy/paste the ode below into their respective filesnames.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Sun Jun 13, 2004 4:58 pm Reply with quoteBack to top

Oops! I didnt see that lol...I'll look in the script again
nope....heres the whole code:

Code:
<?php
/*   Fortress Beta 1.01 by Nuke Cops, Zhen-Xjell
   http://nukecops.com - Computer Cops, LLC
        Copyright 2004, All Rights Reserved

License: You may not modify or distribute any parts of the Fortress code without
obtaining written authorsization from the Copyright holder.  Doing so is considered
a breach of Copyright.  Receiving written authorsization requires that the Copright
and Credits remains in tact. 

Platform:
Fortress is written to be called by any PHP developed website.  For troubleshooting
or installation helps, visit the Copryight holder's website: http://nukecops.com.

Description:
Fortress is a unique application that provides a multi-faceted approach to security
and alert notifications.  Fortress is a live work in progress and will be updated
when milestones are met, and if any patches are released.

Example Use:
Fortress when used with Union Tap Code (UTC) also from Nuke Cops will email alerts
if attacks are spotted to the site webmaster. 

Installation:
Save fortress.php in your PHP-Nuke root folder.  This is generally where "config.php"
is located. 

Configuration:
Go down to the configuration section of Fortress, after this comment section and
modify the variables: $sitename, $to, $subject, $realname, and $domain.

Usage:
Use signifies agreement to the Acceptable Use Policy at Nuke Cops.

Operation:
Phase 1
   When Fortress is triggered, a silent email is activated.  The suspect is unaware
they are being tracked.

Credits:
The original proof of concept and work in this technology was founded by Allevon,
an Elite Nuker at Nuke Cops and owner of http://allevontech.com.  The email alert
proof of concept was inspired by Mister, a loyal Nuke Cops member and owner of
http://protector.warcenter.se.  Testing was done by dsnail2000, IACOJ, Sting, and
Zhen-Xjell.

History:
Fortress is the first in its class that doesn't interface with PHP-Nuke.  Fortress
protects itself on sites using REGISTER_GLOBALS, and it takes on a truly intelligent
operation where users do not know of its existence.  Silent operation ensures all
suspects continue leaving more proof and evidence that they are being malicious.
This information arms you in whatever path you take for action.

Union Tap Code:
The following code is called Union Tap Code.  It is not part of the Fortress code,
but it is quoted here for easy access.  To install it and call Fortress, open
mainfile.php and after the first line: "<?php" install the following code:

[----CUT----]
   // Union Tap Code (UTC) - Fortress Integrated
   // Copyright Zhen-Xjell 2004 http://nukecops.com
   // Beta 4b Code to prevent UNION SQL Injections
   // GNU GPL License 2

   // The following catches C-like comment code within all SQL Injections, not just Union.
   // White paper available here: http://www.securiteam.com/securityreviews/5FP0O0KCKM.html
   // Also caught are plaintext and base64 version of the Union SQL Injection code.
   define('ZERO', true);
   include('fortress.php');
   if (strstr($loc,"*")) {
           $method = "CLIKE";
           AlertMail($method);
   }
   if (preg_match("/([OdWo5NIbpuU4V2iJT0n]{5}) /", $loc, $matches)) {
           $method = "UNION";
           AlertMail($method);
   }
   ReleaseVars();
[----CUT----]
               .end.   */





/*   Start Configuration Section   */

// You Must Configure This Section
$sitename = "Nuke Cops"; // Enter your website name here.
$domain = "http://nukecops.com"; // Enter your full website URL here.  Include "http://".  Do not include a trailing "/".
$to = "zx@nukecops.com"; // Enter the email address Alerts should be sent to.
$realname = "Zhen-Xjell"; // Enter the full name such that email Alerts may be properly titled.
$subject = "Fortress Alarm @ $sitename"; // You may change the Subject here (optional).
/*   End Configuration Section   */







/*    Do Not Edit Settings Below   */

$ver = "Beta 1.01"; // Internal variable for Fortress version.

if (defined('ZERO')) {

   // Protecting against possible Register_Global attacks
   unset($matches);
   unset($rawloc);
   unset($loc);
   unset($addr);
   unset($refer);
   unset($agents);
   unset($method);
   unset($cookies);
   unset($authors);
   unset($uri);
   unset($rawuri);
   unset($port);
   unset($host);

   $server=$_SERVER["SERVER_NAME"];
   $rawloc=$_SERVER["QUERY_STRING"];
   $loc=rawurldecode($_SERVER["QUERY_STRING"]);
   $addr=$_SERVER["REMOTE_ADDR"];
   $refer=$_SERVER["HTTP_REFERER"];
   $agents=$_SERVER["HTTP_USER_AGENT"];
   $cookiess=explode(":", base64_decode($_COOKIE["user"]));
   $authorss=explode(":", base64_decode($_COOKIE["admin"]));
   $rawuri=$_SERVER["REQUEST_URI"];
   $uri=rawurldecode($_SERVER["REQUEST_URI"]);
   $port=$_SERVER["REMOTE_PORT"];
   $host=$_SERVER["REMOTE_HOST"];

} else { Header("Location: index.php"); }

function AlertMail($method) {

   global $server, $rawloc, $loc, $addr, $refer, $agents, $sitename, $domain, $to, $realname, $ver, $matches, $method, $subject, $cookies, $authors, $uri, $rawuri, $port, $host;

   if ($method == "CLIKE") { $matches[1] = "A C-Like Comment Code Entry"; }
   $body = "Fortress Alarm!\r\n"
   ."---------------\r\n"
   ."\r\n"
   ."An attack on $server has triggered Fortress to send a high-priority email to you."
   ." Other methods may be included in this attack, but it only takes one to trigger an Alert."
   ." It is that trigger which is reported below:\r\n\r\n"
        ."Timestamp: " . date("l dS of F Y h:i:s A") ."\r\n"
   ."Attack: $matches[1]\r\n"
   ."Query: $loc\r\n"
   ."Raw Query: $rawloc\r\n"
   ."Method: $domain" . "$uri\r\n"
   ."Raw Method: $domain" . "$rawuri\r\n"
   ."Suspect Host: $host\r\n"
   ."Suspect IP: $addr\r\n"
   ."Remote Port: $port\r\n"
   ."Suspect Agents: $agents\r\n"
   ."User Cookie: $cookies[1]\r\n"
   ."Admin Cookie: $authors[0]\r\n"
   ."Referred: $refer\r\n"
   ."\r\n\r\n"
   ."---\r\n"
   ."Fortress $ver\r\n"
   ."Brought to you exclusively by http://nukecops.com.  Keep it secure!\r\n";
   $to = $realname . " <$to>";
   $headers = "From: Fortress\r\n"
   ."Priority: urgent\r\n"
   ."Importance: High\r\n"
   ."Precedence: special-delivery\r\n"
        ."Organization: $sitename\r\n"
   ."MIME-Version: 1.0\r\n"
   ."Content-Type: text/plain\r\n"
   ."Content-Transfer-Encoding: 8bit\r\n"
   ."X-Priority: 1\r\n"
   ."X-MSMail-Priority: High\r\n"
        ."X-Mailer: PHP/" . phpversion() ."\r\n"
   ."X-Fortress: $ver by http://nukecops.com\r\n";
   mail($to, $subject, $body, $headers);
   Header("Location: index.php");

}

function ReleaseVars() {

        unset($matches);
        unset($rawloc);
        unset($loc);
        unset($addr);
        unset($refer);
        unset($agents);
        unset($method);
        unset($cookies);
        unset($authors);
        unset($uri);
        unset($rawuri);
        unset($port);
        unset($host);
   unset($subject);
   unset($sitename);
   unset($domain);
   unset($to);
   unset($realname);

}

?>
Find all posts by actingbiz1View user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Mon Jun 14, 2004 12:17 pm Reply with quoteBack to top

You are using beta 1.01. Please grab 1.20 beta.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Mon Jun 14, 2004 5:46 pm Reply with quoteBack to top

Ok can you send me a link?
Find all posts by actingbiz1View user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Mon Jun 14, 2004 5:48 pm Reply with quoteBack to top

Its right in the My_Downloads page.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
vandalizer
Nuke Cadet
Nuke Cadet


Joined: Jan 20, 2004
Posts: 2

Location: Toronto

PostPosted: Fri Nov 05, 2004 10:18 pm Reply with quoteBack to top

I installed the fortress.htm and the fortress.csv files myself. The htm works so I think but I was wounder if the csv file will auto update as time goes bye.

So far this is all I see http://www.extremerigs.com/main/fortress.csv
And I see http://www.extremerigs.com/main/fortress.htm

I think I did everything I should have.

How will I know if Fortress is really working or if I missed something?

Thanks guys, you all do a great job by the way!
Find all posts by vandalizerView user's profileSend private messageVisit poster's website
Ruger
Nuke Cadet
Nuke Cadet


Joined: May 23, 2004
Posts: 4


PostPosted: Sun Dec 12, 2004 12:29 am Reply with quoteBack to top

Has Zhen-Xjell, Fortress, and fortress.cc gone to the wayside? Whats the deal?
Find all posts by RugerView user's profileSend private messageVisit poster's website
Evaders99
Site Admin
Site Admin


Joined: Aug 17, 2003
Posts: 12346


PostPosted: Sun Dec 12, 2004 12:32 pm Reply with quoteBack to top

Yes, ZX has left and Fortress is no longer being developed.

_________________
Helping those that help themselves
Read FIRST or DIE!

"Fighting is terrible, but not as terrible as losing the will to fight."
Star Wars Rebellion Network - Need Help? Evaders Squadron Coding
Find all posts by Evaders99View user's profileSend private messageVisit poster's websiteAIM Address
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.254 Seconds - 182 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::