|
|
| |
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ User Suspension Doesn't Work :: Archived
User Suspension Doesn't Work :: ArchivedPost any security related questions in here.
Please send discovered reports to security @ cpgnuke.com Do Not post links to exploits or hacker sites - your post will be edited/deleted. If you think you've been hacked, FIRST go through your server logs.
Go to page 1, 2 Next
| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
Posted: Sun Jul 18, 2004 11:05 pm Post subject: User Suspension Doesn't Work |
|
When I try to suspend a user I am getting a 404 page cannot be found. I would rather delete this user but, when I do, half my forum threads vanish into this air because many were started by him. Yes, this is the same guy my .htaccess file won't stop (and still isn't stopping BTW). Can I not delete accounts on the site without losing half my forums? I dont want his posts gone. Just his account...
Eccentricity R.I.P. please enter your server specs in your user profile!
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 12:11 am Post subject: Re: User Suspension Doesn |
|
hmm, what you could do is rename him and change his password
Admin->Members:Modify
Before you do, just check his IP list - if he's still getting in, is it with different IPs?
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
Posted: Mon Jul 19, 2004 12:17 am Post subject: Re: User Suspension Doesn |
|
| Phoenix wrote: |
hmm, what you could do is rename him and change his password
Admin->Members:Modify
Before you do, just check his IP list - if he's still getting in, is it with different IPs? |
I have 3 known IPs on him but they do not appear to be proxies as he uses them for a long time (probably friends computers). That's why I asked in another post how to stop proxy use. I know it's possible because you can not use them on IRC servers. There has to be a way to block them.
I have changed his username and password already. BTW your signature appears to refer to M$ Windows LOL.
Eccentricity R.I.P. please enter your server specs in your user profile!
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 12:29 am Post subject: Re: User Suspension Doesn |
|
Banning proxies won't stop him, and will most likely alienate some of your other users. It is possible to ban proxies, though the code isn't in 8.2a any longer - some of the code reappears in 8.2b, so someone may be able to work with that.
If you have changed his username and password, how can he still be logging in, unless he is just re-registering - if that is the case, you may need to vet each member?
My sig is dynamic so I can't be sure which one you saw, but most quotes could apply to M$ these days
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
Posted: Mon Jul 19, 2004 12:33 am Post subject: Re: User Suspension Doesn |
|
| Phoenix wrote: |
Banning proxies won't stop him, and will most likely alienate some of your other users. It is possible to ban proxies, though the code isn't in 8.2a any longer - some of the code reappears in 8.2b, so someone may be able to work with that.
If you have changed his username and password, how can he still be logging in, unless he is just re-registering - if that is the case, you may need to vet each member?
My sig is dynamic so I can't be sure which one you saw, but most quotes could apply to M$ these days  |
Something about if you build something that even a fool can use then it will only be used by fools.
As for alienating other users...I simply don't care if that happens. If they want to use the site then they can use their own IP or stay away. The only reason (in my mind) to use a proxy is if you have something to hide. I know many use them for security but when I am forced to choose between my security and theirs mine will win every time. Where can I find the code to stop proxy use? I wish to implement it immediately. Once Dungeon Siege II releases my membership will hit 60,000 and I simply cannot keep track of who is who if they are using proxies.
Eccentricity R.I.P. please enter your server specs in your user profile!
Last edited by Eccentricity R.I.P. on Mon Jul 19, 2004 12:40 am; edited 2 times in total |
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 12:36 am Post subject: Re: User Suspension Doesn |
|
ah, yes, Murphy was a wise Irishman
Thought it might have been the golden rule - he who owns the gold makes the rules.
Protector has that capability - DJ is back in a couple of days, better to get a solution from him or one of the others, so that it integrates with CPG-Nuke.
I don't understand why the htaccess solution doesn't work for you.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Last edited by Phoenix on Mon Jul 19, 2004 12:41 am; edited 1 time in total |
|
| Back to top |
|
 |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 12:42 am Post subject: Re: User Suspension Doesn |
|
It's there in the setup - you can ban proxies.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
Posted: Mon Jul 19, 2004 12:46 am Post subject: Re: User Suspension Doesn |
|
| Phoenix wrote: |
| It's there in the setup - you can ban proxies. |
If it is, I don't see it. Under settings I see no mention of proxies. Under banned IP it gives 2 options only. IP or IP range. This is version 1.3.
Eccentricity R.I.P. please enter your server specs in your user profile!
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 12:51 am Post subject: Re: User Suspension Doesn |
|
Just finding the one remaining site I have it on - will advise.
Okay, Admin->Protector->Settings, look for "Deny Proxy:" on left side of that panel, about 3/4 down
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
Posted: Mon Jul 19, 2004 12:55 am Post subject: Re: User Suspension Doesn |
|
| Phoenix wrote: |
Just finding the one remaining site I have it on - will advise.
Okay, Admin->Protector->Settings, look for "Deny Proxy:" on left side of that panel, about 3/4 down |
OK One sec. brb
Here is what I have: It isn't there. Which version are you using. Mine is for PhP nuke which I ported to cpg because I couldn't find one for CPG. If you know where a cpg version can be found I would appreciate it.
Edit: deleted pic - contained IP - served it's purpose anyway.
Eccentricity R.I.P. please enter your server specs in your user profile!
Last edited by Eccentricity R.I.P. on Mon Jul 19, 2004 1:02 am; edited 1 time in total |
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 1:01 am Post subject: Re: User Suspension Doesn |
|
I left mine at 1.14.b2, and it is on a phpnuke site which I haven't upgraded yet.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Eccentricity R.I.P. Heavy poster


Offline Joined: Jun 10, 2004 Posts: 212 Location: Raleigh, NC
|
Posted: Mon Jul 19, 2004 1:07 am Post subject: Re: User Suspension Doesn |
|
| Phoenix wrote: |
| I left mine at 1.14.b2, and it is on a phpnuke site which I haven't upgraded yet. |
Ahh that explains it then. I love CPG but I am forced to run insecure modules and themes for phpnuke because of a lack of availability of cpg modules and themes. I convert the database queries, when needed, but I am sure there are more changes that I need to make as well. I have never gotten the collapsable blocks to work on any phpnuke theme by following the instructions in the FAQ's. Not sure why because I follow them to the letter.
My biggest headache has been the inability to use the themes that I really like. Ones which are RPG related like Zammerol and ZammerDiablo. I wind up converting phpnuke themes and I am constantly fearful that I have created a security hole. Is there a site which offers a significant choice in cpgnuke themes?
Eccentricity R.I.P. please enter your server specs in your user profile!
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 1:34 am Post subject: Re: User Suspension Doesn |
|
Okay, untested, so ensure file backed up first. mainfile.php, insert the following code before line 25 which should be '// comment first line uncomment second for debugging'
You may need to disable blocker before doing so?
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Mon Jul 19, 2004 1:38 am Post subject: Re: User Suspension Doesn |
|
I can confirm that it blocks my proxy.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
|
|
All times are GMTGo to page 1, 2 Next
|
| |
 |
 Welcome Anonymous
|
|
|
|