Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ User Suspension Doesn't Work :: Archived


User Suspension Doesn't Work :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Sun Jul 18, 2004 11:05 pm
Post subject: User Suspension Doesn't Work

When I try to suspend a user I am getting a 404 page cannot be found. I would rather delete this user but, when I do, half my forum threads vanish into this air because many were started by him. Yes, this is the same guy my .htaccess file won't stop (and still isn't stopping BTW). Can I not delete accounts on the site without losing half my forums? I dont want his posts gone. Just his account...


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 12:11 am
Post subject: Re: User Suspension Doesn

hmm, what you could do is rename him and change his password Smile
Admin->Members:Modify

Before you do, just check his IP list - if he's still getting in, is it with different IPs?

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Mon Jul 19, 2004 12:17 am
Post subject: Re: User Suspension Doesn

Phoenix wrote:
hmm, what you could do is rename him and change his password Smile
Admin->Members:Modify

Before you do, just check his IP list - if he's still getting in, is it with different IPs?

I have 3 known IPs on him but they do not appear to be proxies as he uses them for a long time (probably friends computers). That's why I asked in another post how to stop proxy use. I know it's possible because you can not use them on IRC servers. There has to be a way to block them.

I have changed his username and password already. BTW your signature appears to refer to M$ Windows LOL.


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 12:29 am
Post subject: Re: User Suspension Doesn

Banning proxies won't stop him, and will most likely alienate some of your other users. It is possible to ban proxies, though the code isn't in 8.2a any longer - some of the code reappears in 8.2b, so someone may be able to work with that.

If you have changed his username and password, how can he still be logging in, unless he is just re-registering - if that is the case, you may need to vet each member?

My sig is dynamic so I can't be sure which one you saw, but most quotes could apply to M$ these days Laughing

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Mon Jul 19, 2004 12:33 am
Post subject: Re: User Suspension Doesn

Phoenix wrote:
Banning proxies won't stop him, and will most likely alienate some of your other users. It is possible to ban proxies, though the code isn't in 8.2a any longer - some of the code reappears in 8.2b, so someone may be able to work with that.

If you have changed his username and password, how can he still be logging in, unless he is just re-registering - if that is the case, you may need to vet each member?

My sig is dynamic so I can't be sure which one you saw, but most quotes could apply to M$ these days Laughing

Something about if you build something that even a fool can use then it will only be used by fools. Very Happy

As for alienating other users...I simply don't care if that happens. If they want to use the site then they can use their own IP or stay away. The only reason (in my mind) to use a proxy is if you have something to hide. I know many use them for security but when I am forced to choose between my security and theirs mine will win every time. Where can I find the code to stop proxy use? I wish to implement it immediately. Once Dungeon Siege II releases my membership will hit 60,000 and I simply cannot keep track of who is who if they are using proxies.


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad


Last edited by Eccentricity R.I.P. on Mon Jul 19, 2004 12:40 am; edited 2 times in total
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 12:36 am
Post subject: Re: User Suspension Doesn

ah, yes, Murphy was a wise Irishman Laughing

Thought it might have been the golden rule - he who owns the gold makes the rules.

Protector has that capability - DJ is back in a couple of days, better to get a solution from him or one of the others, so that it integrates with CPG-Nuke.

I don't understand why the htaccess solution doesn't work for you.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)


Last edited by Phoenix on Mon Jul 19, 2004 12:41 am; edited 1 time in total
Back to top
View user's profile Visit poster's website Photo Gallery
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Mon Jul 19, 2004 12:41 am
Post subject: Re: User Suspension Doesn

Phoenix wrote:
ah, yes, Murphy was a wise Irishman Laughing

Thought it might have been the golden rule - he who owns the gold makes the rules.

Protector has that capability - DJ is back in a couple of days, better to get a solution from him or one of the others, so that it integrates with CPG-Nuke.

I am running protector now but i haven't seen a function relating to proxies.


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 12:42 am
Post subject: Re: User Suspension Doesn

It's there in the setup - you can ban proxies.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Mon Jul 19, 2004 12:46 am
Post subject: Re: User Suspension Doesn

Phoenix wrote:
It's there in the setup - you can ban proxies.

If it is, I don't see it. Under settings I see no mention of proxies. Under banned IP it gives 2 options only. IP or IP range. This is version 1.3.


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 12:51 am
Post subject: Re: User Suspension Doesn

Just finding the one remaining site I have it on - will advise.

Okay, Admin->Protector->Settings, look for "Deny Proxy:" on left side of that panel, about 3/4 down

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Mon Jul 19, 2004 12:55 am
Post subject: Re: User Suspension Doesn

Phoenix wrote:
Just finding the one remaining site I have it on - will advise.

Okay, Admin->Protector->Settings, look for "Deny Proxy:" on left side of that panel, about 3/4 down

OK One sec. brb

Here is what I have: It isn't there. Which version are you using. Mine is for PhP nuke which I ported to cpg because I couldn't find one for CPG. If you know where a cpg version can be found I would appreciate it.

Edit: deleted pic - contained IP - served it's purpose anyway.


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad


Last edited by Eccentricity R.I.P. on Mon Jul 19, 2004 1:02 am; edited 1 time in total
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 1:01 am
Post subject: Re: User Suspension Doesn

I left mine at 1.14.b2, and it is on a phpnuke site which I haven't upgraded yet.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Eccentricity R.I.P.
Heavy poster
Heavy poster

Offline Offline
Joined: Jun 10, 2004
Posts: 212
Location: Raleigh, NC
PostPosted: Mon Jul 19, 2004 1:07 am
Post subject: Re: User Suspension Doesn

Phoenix wrote:
I left mine at 1.14.b2, and it is on a phpnuke site which I haven't upgraded yet.

Ahh that explains it then. I love CPG but I am forced to run insecure modules and themes for phpnuke because of a lack of availability of cpg modules and themes. I convert the database queries, when needed, but I am sure there are more changes that I need to make as well. I have never gotten the collapsable blocks to work on any phpnuke theme by following the instructions in the FAQ's. Not sure why because I follow them to the letter.

My biggest headache has been the inability to use the themes that I really like. Ones which are RPG related like Zammerol and ZammerDiablo. I wind up converting phpnuke themes and I am constantly fearful that I have created a security hole. Is there a site which offers a significant choice in cpgnuke themes?


Eccentricity R.I.P. please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 1:34 am
Post subject: Re: User Suspension Doesn

Okay, untested, so ensure file backed up first. mainfile.php, insert the following code before line 25 which should be '// comment first line uncomment second for debugging'
You may need to disable blocker before doing so?
PHP:

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Mon Jul 19, 2004 1:38 am
Post subject: Re: User Suspension Doesn

I can confirm that it blocks my proxy.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

devamı...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy