You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 59 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Confused by analyzer.php [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
safecracker4hire
Nuke Cadet
Nuke Cadet


Joined: Feb 18, 2003
Posts: 9


PostPosted: Wed Mar 19, 2003 9:25 am Reply with quoteBack to top

I have installed 6.5 full and have run analyze.php on it. Analyze has found the following errors:

MySQL server version 3.23.54 (I have sent an email to my server to update this)

magic_quotes_gpc is not enabled, yet when I run phpinfo.php from the same domain it shows the magic_quotes_gpc value as ON. (magic_quotes_runtime is OFF and magic_quotes_sybase is OFF)

WebMail attack - mailattach.php was found and should be deleted... I thought that I read a post here stating that FB has fixed this in 6.5... has it been fixed?

phpBB2 forums are at risk (showing as version 2.0.2). I checked the forums and everything is clearly labelled version 2.1 from NukeCops. I understand that FB did not include some of the database changes with the port, but am wondering if it is still at risk?

I have removed mailattach.php for now, but am confused by the phpBB error and the magic_quotes_gpc error. Any comments would be greatly appreciated!

analyze.php ==> http://mysafetech.com/analyze.php
phpinfo.php ==> http://mysafetech.com/phpinfo.php
Find all posts by safecracker4hireView user's profileSend private message
EuroMagic
Nuke Cadet
Nuke Cadet


Joined: Feb 26, 2003
Posts: 2

Location: Denmark / Copenhagen

PostPosted: Wed Mar 19, 2003 12:26 pm Reply with quoteBack to top

I also got some clear miss information from analyzer!!!!!!!!!
Find all posts by EuroMagicView user's profileSend private messageYahoo MessengerMSN MessengerICQ Number
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Wed Mar 19, 2003 1:10 pm Reply with quoteBack to top

That's odd, I have to check the code again. If you look http://mysafetech.com/analyze.php?zx=phpini you'll see that both local and global for magic quotes is "1", or "on". Analyzer correctly reports that, but not sure why its missing on the warning. Thanks for the heads up, I'll inspect the code again.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
safecracker4hire
Nuke Cadet
Nuke Cadet


Joined: Feb 18, 2003
Posts: 9


PostPosted: Wed Mar 19, 2003 1:32 pm Reply with quoteBack to top

Hi ZX;

Thanks for the reply... I feel a bit less confused now! Wink

Any ideas as to the phpBB warning?
Find all posts by safecracker4hireView user's profileSend private message
vmack
Nuke Soldier
Nuke Soldier


Joined: Jan 30, 2003
Posts: 28

Location: USA

PostPosted: Thu Mar 20, 2003 12:44 am Reply with quoteBack to top

I also get the mailattach and phpbb 2.0.2 warning in 6.5 final install?
Find all posts by vmackView user's profileSend private messageVisit poster's website
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Thu Mar 20, 2003 3:50 am Reply with quoteBack to top

If using 6.5 ignore both warnings, to get rid of the phpBB warning in phpMyAdmin type update nuke_bbconfig set version = .0.4 change the nuke value to whatever your prefix is, else edit this value manually.

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
safecracker4hire
Nuke Cadet
Nuke Cadet


Joined: Feb 18, 2003
Posts: 9


PostPosted: Thu Mar 20, 2003 6:52 am Reply with quoteBack to top

I would assume that this is part of the database changes that were not implemented by FB... I do not have a 'version' field in _bbconfig.
Find all posts by safecracker4hireView user's profileSend private message
chatserv
General
General


Joined: Jan 12, 2003
Posts: 3128

Location: Puerto Rico

PostPosted: Thu Mar 20, 2003 10:10 am Reply with quoteBack to top

Not sure if this would be the case with you but when i view the bbconfig table through phpMyAdmin because it has so many fields i only see half of them in the page but if i click next i will see the other half, among these version.

_________________
Feed a man a fish and you feed him for a day. Teach a man to fish and you feed him for a lifetime.
ScriptHeaven | NukeResources
Find all posts by chatservView user's profileSend private messageVisit poster's website
safecracker4hire
Nuke Cadet
Nuke Cadet


Joined: Feb 18, 2003
Posts: 9


PostPosted: Thu Mar 20, 2003 10:49 am Reply with quoteBack to top

DUH! Embarassed I don't know why that never even occured to me!

You are correct! The version field was the last in the table and set to .0.2 (now .0.4). Thanks!
Find all posts by safecracker4hireView user's profileSend private message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Fri Mar 21, 2003 10:56 pm Reply with quoteBack to top

Yah CS is right... our forums port is in the 6.5 final, and our copyright notice is there too. You can see it right at phpnuke.org. Only problem is, fbc forgot to change the version from .0.2 to .0.4. Of course that in itself isn't a security issue.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
American
Corporal
Corporal


Joined: Jan 17, 2003
Posts: 58


PostPosted: Mon Mar 24, 2003 6:05 pm Reply with quoteBack to top

If you go to your PHPbb admin and look at the bottom of the admin page on the right you will see:

Powered by phpBB 2.0.2 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem, sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

_________________
Brad
Find all posts by AmericanView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.744 Seconds - 178 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::