Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ new security problem with old netscape :: Archived


new security problem with old netscape :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Sat Jan 14, 2006 10:18 pm
Post subject: new security problem with old netscape

I tried going to my site www.fitnecise.net using netscape, and was immediately banned for:


nknown user-agent

You are banned from this site due to a unknown user-agent.



but coming to this site I was not banned. what happened there?

using 9.1.0.5


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
xfsunoles
XHTML Specialist
XHTML Specialist

Offline Offline
Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida
PostPosted: Sun Jan 15, 2006 1:17 am
Post subject: Re: new security problem with netscape

You didn't tell which Version of Netscape you use?


xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger Photo Gallery
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Sun Jan 15, 2006 1:33 am
Post subject: Re: new security problem with netscape

true, its old, 4.06

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Sun Jan 15, 2006 2:18 am
Post subject: Re: new security problem with netscape

We don't have the UA specifics of 4.06 since it's very outdated.
Use the following script to provide us the info we need to allow it.
PHP:
<?php
echo $_SERVER['HTTP_USER_AGENT'];


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
DaveTomneyUK
Gold Supporter
Gold Supporter

Offline Offline
Joined: Aug 14, 2004
Posts: 215
Location: UK, England
PostPosted: Sun Jan 15, 2006 3:48 am
Post subject: Re: new security problem with netscape

Maybe it was not included with the user agent file because not many user netscape much now. I thought they stopped making new version of that program.


DaveTomneyUK's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / Apache2.2.8 / MySQL5.0.45 / PHP5.2.6 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger
heroicimages
Newbie
Newbie

Offline Offline
Joined: Apr 19, 2006
Posts: 29

PostPosted: Thu May 18, 2006 8:50 pm
Post subject: Re: new security problem with netscape

What about Safari 2.0.3 ? I get the same message at myndworx.com/ and dfmods.com/. But my own site works fine, and I'm here...

I'll try Firefox...

That's too bad -- it's fine with Firefox. One more thing Apple needs to fix in Safari, I guess!


heroicimages's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.34/4.1.18-Standard/5.0.5/Dragonfly 9.0.6.1
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Fri May 19, 2006 9:23 am
Post subject: Re: new security problem with netscape

heroicimages wrote:
What about Safari 2.0.3 ? I get the same message at myndworx.com/ and dfmods.com/. But my own site works fine, and I'm here...

I'll try Firefox...

That's too bad -- it's fine with Firefox. One more thing Apple needs to fix in Safari, I guess!

For testing purposes would you please try if you can visit my site with your Safari browser?


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
xfsunoles
XHTML Specialist
XHTML Specialist

Offline Offline
Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida
PostPosted: Fri May 19, 2006 3:38 pm
Post subject: Re: new security problem with netscape

heroicimages wrote:
What about Safari 2.0.3 ? I get the same message at myndworx.com/ and dfmods.com/. But my own site works fine, and I'm here...

I'll try Firefox...

That's too bad -- it's fine with Firefox. One more thing Apple needs to fix in Safari, I guess!

Are you using an Intel Mac machine?

_________________

Firefox is my Favorite Browser

xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger Photo Gallery
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Mon May 22, 2006 4:59 pm
Post subject: Re: new security problem with old netscape

forgot about this thread. anyway, had another problem today. user got the same message, and he's using "a new macbook pro. I've tried on firefox, safari, and IE."

if I add his IP to htaccess it will let him in correct?

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
xfsunoles
XHTML Specialist
XHTML Specialist

Offline Offline
Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida
PostPosted: Mon May 22, 2006 5:05 pm
Post subject: Re: new security problem with old netscape

run0 wrote:
forgot about this thread. anyway, had another problem today. user got the same message, and he's using "a new macbook pro. I've tried on firefox, safari, and IE."

if I add his IP to htaccess it will let him in correct?

no, its Security Class need to identify UA or you can disable unknown UA by Security Admin. Security Class identify PPC Apple OS but not Intel Apple OS.

_________________

Firefox is my Favorite Browser

xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger Photo Gallery
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Mon May 22, 2006 5:08 pm
Post subject: Re: new security problem with old netscape

xfsunoles wrote:
run0 wrote:
forgot about this thread. anyway, had another problem today. user got the same message, and he's using "a new macbook pro. I've tried on firefox, safari, and IE."

if I add his IP to htaccess it will let him in correct?

no, its Security Class need to identify UA or you can disable unknown UA by Security Admin. Security Class identify PPC Apple OS but not Intel Apple OS.

thanks, i'll do that for now.

so is this apple's fault or the security? I will report it as a bug if it hasn't been already, a workaround would be nice

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Mon May 22, 2006 5:18 pm
Post subject: Re: new security problem with old netscape

run0 wrote:

so is this apple's fault or the security? I will report it as a bug if it hasn't been already, a workaround would be nice

Yeah, you can report it.

It's about this code from includes/classes/security.php (lines 248-266)

PHP:


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Mon May 22, 2006 5:41 pm
Post subject: Re: new security problem with old netscape

I just remembered this is only in CVS so it will just be disregarded anyways.

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
alva
1000+ Posts Club
1000+ Posts Club

Offline Offline
Joined: May 31, 2005
Posts: 1150
Location: The Netherlands
PostPosted: Mon May 22, 2006 6:18 pm
Post subject: Re: new security problem with old netscape

run0 wrote:
I just remembered this is only in CVS so it will just be disregarded anyways.

The last weeks/months most of the bugs and fixes in Projects are about cvs. That's because:

1) almost all 9.0.6.1 problems are non-existant in cvs even if only a few of the solutions are available as a true 9.0.6.1 patch/ branche.
2) the new features and approaches have introduced new problems that need to be dealt with, too.


alva's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache/5.0.24/5/9.1 CVS
Back to top
View user's profile Visit poster's website
ofigustavo
Nice poster
Nice poster

Offline Offline
Joined: Aug 21, 2005
Posts: 109
Location: Canary Islands-Spain
PostPosted: Wed May 31, 2006 1:07 pm
Post subject: Re: new security problem with old netscape

fast solution? change to a newest version of netscape, or firefox. Browsers too old have a lot of problems with websites,scripts,etc,etc,etc.


ofigustavo please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

もっと読む

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy