You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 66 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Admin Secure 1.7 Released [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Fri May 28, 2004 2:37 pm Reply with quoteBack to top

Admin Secure 1.7 comes with tons of new features: Safe Requests Mode will force any request strings containing dangerous strings signatures (union, join, exec, select, insert, grant, etc) translated as HTML entities; Safe HTML Strings will translating "<" and ">" characters into &lt; and &gt; entities, respectively. This will always prevent users submitting any of HTML formatted text. Both of them are extreme features intended for paranoid administrators. Smile

Another features are comes from people's requests: Site Close/Open option, Delete unapproved admins (even they're God Admins) in Admin Approval page, SQL injection and forbidden HTML tags deep scanning modes, visitor's tracking system, maximum allowable visitors at the same time, and more. Version 1.7 also comes with better appearances and layouts for conveniences.

Features:
- Blocking known PHP-Nuke exploits.
- Prevent fake admin account access through input requests.
- Blocking cross-site scripting in modules.php and index.php files.
- Ensuring admin account session taken from cookie.
- Prevent unauthorized admin account creation, deletion, and modification.
- Compare admin account validity through "mirrored" database table.
- Changes to admin accounts (create, edit, delete) require God admin approval.
- E-mail notification. An alert sent along with additional info.
- Banning system for accessing site and PHP-Nuke modules.
- Log site activities.
- Flood Protection.
- And more.

Changes in This Version:
- Add: Safe Requests Mode
- Add: Safe HTML Strings
- Add: Automatic Database Checking (thanks to Anonymous)
- Add: Automatic Database Optimization (thanks to Anonymous)
- Add: Site Close/Open option in Administration Panel
- Add: Unapproved admin accounts deletion from Administration Panel
- Add: Confirmation Prompt
- Add: Selectable Blocking page (either html page or server response codes)
- Add: SQL Injection deep scanning mode (thanks to Anonymous)
- Add: Illegal HTML Tags deep scanning mode (thanks to Anonymous)
- Add: Tracking System (thanks to John1000)
- Add: Maximum Site Visitors (thanks to John1000)
- Add: Send mail notification as MIME mail
- Add: Send mail notification using IMAP (if supported by server)
- Upd: Strengthen Admin Secure global variables
- Upd: Improve Admin Secure Administration Panel interface
- Upd: Improve SQL Injection checking algorithm
- Upd: Flood protection auto-disable in admin/user login
- Fix: False illegal html tags checking in phpbb/bb2nuke Forum preview mode
- Fix: False illegal html tags checking in Private Messages preview mode
- Fix: Corrupt downloaded ban/log files if gz output enabled by server

File details:
- ZIP Packed File 315,234 Bytes (MD5 File: DBF87AF247C4DF80394A9011C667370A)
- TGZ Packed File 259,624 Bytes (MD5 File: 2F1CD7E519B0BD2C0753C6CDDD9589C2)

Download Link:
- SourceForge (both file types)
- Author's Homepage (ZIP only, no account registration required)
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Sat May 29, 2004 6:55 am Reply with quoteBack to top

Very nice, how is the performance? I hear nothing but good about this.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Sat May 29, 2004 9:02 am Reply with quoteBack to top

Zhen-Xjell wrote:
Very nice, how is the performance? I hear nothing but good about this.


Performances are greatly improved since 1.6, and seem no differences in 1.7. But I let users decide whenever their site is a bit slower or not after AS installation.
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
chevy0
Nuke Cadet
Nuke Cadet


Joined: May 29, 2004
Posts: 4


PostPosted: Sat May 29, 2004 10:29 am Reply with quoteBack to top

how do i make another account god admin?
Find all posts by chevy0View user's profileSend private message
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Sat May 29, 2004 10:50 am Reply with quoteBack to top

chevy0 wrote:
how do i make another account god admin?


In Nuke admin menu, you can create another God admin by setting their "realname" as God and their nickname must be differ than another God admins. If Admin Secure installed, as "first" God Admin, you should approve this new account from AS Administration Panel.
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
chevy0
Nuke Cadet
Nuke Cadet


Joined: May 29, 2004
Posts: 4


PostPosted: Sat May 29, 2004 11:01 am Reply with quoteBack to top

thanks!

and thanks for this nice script ;]
Find all posts by chevy0View user's profileSend private message
atko
Nuke Cadet
Nuke Cadet


Joined: May 27, 2004
Posts: 6


PostPosted: Sun May 30, 2004 1:09 am Reply with quoteBack to top

Looks good. I have Protector installed at the moment. Does this have more features, it does appear so? Also could I install this alongside Protector or is it advisable to have one or the other? Thanks for a great addon and any help appreciated.
Find all posts by atkoView user's profileSend private message
foxyfemfem
Support Staff
Support Staff


Joined: Jan 23, 2003
Posts: 668

Location: USA

PostPosted: Sun May 30, 2004 2:31 am Reply with quoteBack to top

Hello,

I downloaded the AS from author's website, there was no install.txt file. The only txt file was the readme. I will download it from SourceForge and see if there's an install.txt file. Without this file I am totally lost when it come to installation.

_________________
If you shoot for the moon and miss, you'll still be amongst the stars.
Find all posts by foxyfemfemView user's profileSend private message
SaraHol
Corporal
Corporal


Joined: Aug 29, 2003
Posts: 71


PostPosted: Sun May 30, 2004 2:58 am Reply with quoteBack to top

A couple of questions:

a) It seems to only support Nuke up to 7.2, and no lower than 6.9? Is that right? My sites are 6.5 and 7.3!

b) Your install.txt (which I found in the zip) states: "At the the top of this script, below the "<?php" (PHP code start tag), add these new lines:". I assume this means AFTER the UTC if you have it installed?
Find all posts by SaraHolView user's profileSend private message
voytas
Nuke Cadet
Nuke Cadet


Joined: May 30, 2004
Posts: 2


PostPosted: Sun May 30, 2004 4:29 am Reply with quoteBack to top

i have just installed AS 1.7 and there is problem. i can not enter to forum configuration. there is a blank page.
i use pure phpnuke 7.2.
anythig else seems work great.
Find all posts by voytasView user's profileSend private message
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Sun May 30, 2004 10:11 am Reply with quoteBack to top

Quote:
Looks good. I have Protector installed at the moment. Does this have more features, it does appear so? Also could I install this alongside Protector or is it advisable to have one or the other? Thanks for a great addon and any help appreciated.


Atko, As far as I know and heard, there's no conflicts between Protector System and Admin Secure.

Quote:
I downloaded the AS from author's website, there was no install.txt file. The only txt file was the readme. I will download it from SourceForge and see if there's an install.txt file. Without this file I am totally lost when it come to installation.


Foxy, the install.txt is in the root of archive file, not in the docs directory. Smile

Quote:
It seems to only support Nuke up to 7.2, and no lower than 6.9? Is that right? My sites are 6.5 and 7.3!


Admin Secure support PHP-Nuke 5.5 to 7.2 (7.3 was tested and runs fine, but Admin Secure does not offer tech support this version except for phpnuke clubs, until public version released).

cPortal is based on PHP-Nuke 5.5 and Admin Secure integrated with it. If you currently use PHP-Nuke 6.0 and below, be sure to edit asconfig.php and set $db_compat variable to non-zero.

Quote:
Your install.txt (which I found in the zip) states: "At the the top of this script, below the "<?php" (PHP code start tag), add these new lines:". I assume this means AFTER the UTC if you have it installed?


You can put the inclusion and path detection function either before or after UTC embedded code. This is only an script inclusion code. The actual Admin Secure execution is performed in the last mainfile.php file.

Quote:
i have just installed AS 1.7 and there is problem. i can not enter to forum configuration. there is a blank page. i use pure phpnuke 7.2.


This was a known issue that still has no solution, because only few people got this even compared to other with the same specs (but different server). If you are using phpbb/bb2nuke 2.0.8, open modules/Forums/admin/pagestart.php and try to find this line of code:

Code:
if ($cookie[2] == $row2['user_password'] && ($row2['user_password'] != "" && $row2['user_level'] == 2) && ($row[radminsuper] == 1 OR $row[radminforum] == 1)) {


Replace with:

Code:
if ($cookie[2] == $row2['user_password'] && ($row[radminsuper] == 1 OR $row[radminforum] == 1)) {


Or, if the above doesn't work, replace with:

Code:
if ($row[radminsuper] == 1 OR $row[radminforum] == 1) {


My advice to admins who installing phpbb/bb2nuke 2.0.8, get the latest patch of this mod from NukeCops and be sure to run the table upgrade scripts. I saw many people do upgrading by only copying and overwrites old forum script files without updating database tables. I hope this small solution can solve your problem. Smile

_________________
I'm Image
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
phantomk
Nuke Soldier
Nuke Soldier


Joined: Apr 28, 2004
Posts: 10


PostPosted: Mon May 31, 2004 4:57 am Reply with quoteBack to top

Luv this mod Madman, Currently useing phpNuke 6.9, with all the security updates I can possibly find, along with Fortress, great tool and best part its small and easy to install, Admin Secure, wonderfull for admin protection, Protector for my main ban magement, and Sentinel for a backup incase anything odd should happen. I have each mod working without any conflictions or problems. Should see about getting together and sorting out one big security addon incorperating each mod into one admin panel with one install. Just a thought. Very Happy

-PK
Find all posts by phantomkView user's profileSend private message
Imago
Captain
Captain


Joined: Jan 17, 2003
Posts: 629

Location: Europe

PostPosted: Mon May 31, 2004 6:06 am Reply with quoteBack to top

I hate Admin Secure as my IP has been banned on several sites when trying to submit news with simple html in them. Now I see only page 404.

May I suggest to not treat HTML as a mallicious code. Smile

_________________
www.vdsp.net | www.indopedia.org | www.orientalia.org | www.indology.net | www.yogadarsana.org | www.husserl.info | www.medicum.net
Find all posts by ImagoView user's profileSend private messageVisit poster's website
madman
Support Mod
Support Mod


Joined: Feb 15, 2004
Posts: 806


PostPosted: Mon May 31, 2004 12:03 pm Reply with quoteBack to top

Imago wrote:
I hate Admin Secure as my IP has been banned on several sites when trying to submit news with simple html in them. Now I see only page 404.


Very Happy
Not all html tags are restricted by Admin Secure. For example, text bold <b></b> is still allowed. Tags containing scripting code (or any malicious codes) will trigger security alerts, here some examples:

Code:
<a href="javascript:void()" onClick="window.alert('boo!');">Click here</a>
<span onLoad="document.href='http://foo.bar/hack.pl?id=destroy';">blabla</span>
<img src="admin.php?op=blabla" />


You'll see how html tags can also exploit your site (e.g. admin auto creation) and your users (e.g. cookie stealing). Html tags can also be used for site defacements or inject your site's visitors with malicious client-side scripting.

When submitting a news, try to keep following site's layout without having to use additional html formatting such as using style tag. I saw some nice "submit news" module replacements which only allow text formatting using bbcode style.

Imago wrote:
May I suggest to not treat HTML as a mallicious code. Smile


It is up to the site admin who using Admin Secure, because html filtering option is adjustable.

_________________
I'm Image
Find all posts by madmanView user's profileSend private messageVisit poster's websiteYahoo MessengerMSN Messenger
actingbiz1
Corporal
Corporal


Joined: May 15, 2004
Posts: 64


PostPosted: Wed Jun 09, 2004 12:53 pm Reply with quoteBack to top

A few questions....

What does this do, how do I install and is it very easy to install?
Find all posts by actingbiz1View user's profileSend private message
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.printer-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.269 Seconds - 347 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::