FIXED CTracker errors
Subject: Re: CTracker Errors
When adding a user to a group ( Users&groups fuction)it give a ctracker error, how to fix this
Subject: Re: CTracker Errors
does anyone have this error too? Because i dont have an error when i add an user to one group.
Lordpeter wrote: [View Post]
does anyone have this error too? Because i dont have an error when i add an user to one group.
Subject: Re: CTracker Errors
Subject: Re: CTracker Errors
Error when trying to "Tell a Friend" about an specific topic.
And the CTracker Log says this:
It happens just in ONE topic.
Hail!
Running at IcePhoenix
Quote:
And the CTracker Log says this:
Quote:
It happens just in ONE topic.
Hail!
Running at IcePhoenix
Subject: Re: CTracker Errors
Image error.
An image posted with www prefix gives a CT-error, without the www-prefix it works fine.
When thinking further this might have something to do with how the remote host configures the .htaccess??
testing it here now.
with the www -> no picture (CT-error)
without www it;s just fine.
And the link to the error. As you can see, it also goes wrong on icyphoenix.com.
An image posted with www prefix gives a CT-error, without the www-prefix it works fine.
When thinking further this might have something to do with how the remote host configures the .htaccess??
testing it here now.
with the www -> no picture (CT-error)
without www it;s just fine.
And the link to the error. As you can see, it also goes wrong on icyphoenix.com.
Subject: Re: CTracker errors
try this
open ctracker/engines/ct_security.php
find
find www and cut
see results
if you have more problems - try to find ctracker stopping word :wink:
open ctracker/engines/ct_security.php
find
- $ct_rules = array(
- 'http_', '_server', 'delete%20', 'delete ', 'drop%20', 'drop ', 'create%20',
- 'create ', 'update%20', 'update ', 'insert%20', 'insert ',
- 'select%20', 'select ', 'bulk%20', 'bulk ', 'union%20', 'union ',
- 'or%20', 'or ', 'and%20', 'and ', 'exec', '@@', '%22', '"', 'openquery',
- 'openrowset', 'msdasql', 'sqloledb', 'sysobjects', 'syscolums',
- 'syslogins', 'sysxlogins', 'char%20', 'char ', 'into%20', 'into ',
- 'load%20', 'load ', 'msys', 'alert%20', 'alert ', 'eval%20', 'eval ',
- 'onkeyup', 'x5cx', 'fromcharcode', 'javascript:', 'javascript.', 'vbscript:',
- 'vbscript.', 'http-equiv', '->', 'expression%20', 'expression ',
- 'url%20', 'url ', 'innerhtml', 'document.', 'dynsrc', 'jsessionid',
- 'style%20', 'style ', 'phpsessid', '<applet', '<div', '<emded', '<iframe', '<img',
- '<meta', '<object', '<script', '<textarea', 'onabort', 'onblur',
- 'onchange', 'onclick', 'ondblclick', 'ondragdrop', 'onerror',
- 'onfocus', 'onkeydown', 'onkeypress', 'onload', 'onmouse',
- 'onmove', 'onreset', 'onresize', 'onselect', 'onsubmit',
- 'onunload', 'onreadystatechange', 'xmlhttp', 'uname%20', 'uname ',
- 'id%20', 'id ', 'ls%20', 'ls ', 'cat%20', 'cat ', 'rm%20', 'rm ',
- 'kill%20', 'kill ', 'mail%20', 'mail ', 'wget%20', 'wget ', 'wget(',
- 'pwd%20', 'pwd ', 'objectclass', 'objectcategory', '<!-%20', '<!- ',
- 'total%20', 'total ', 'http%20request', 'http request', 'phpb8b4f2a0',
- 'phpinfo', 'php:', 'globals', '%2527', '%27', ''', 'chr(',
- 'chr=', 'chr%20', 'chr ', '%20chr', ' chr', 'cmd=', 'cmd%20', 'cmd',
- '%20cmd', ' cmd', 'rush=', '%20rush', ' rush', 'rush%20', 'rush ',
- 'union%20', 'union ', '%20union', ' union', 'union(', 'union=',
- '%20echr', ' echr', 'esystem', 'cp%20', 'cp ', 'cp(', '%20cp', ' cp',
- 'mdir%20', 'mdir ', '%20mdir', ' mdir', 'mdir(', 'mcd%20', 'mcd ',
- 'mrd%20', 'mrd ', 'rm%20', 'rm ', '%20mcd', ' mcd', '%20mrd', ' mrd',
- '%20rm', ' rm', 'mcd(', 'mrd(', 'rm(', 'mcd=', 'mrd=', 'mv%20', 'mv ',
- 'rmdir%20', 'rmdir ', 'mv(', 'rmdir(', 'chmod(', 'chmod%20', 'chmod ',
- 'cc%20', 'cc ', '%20chmod', ' chmod', 'chmod(', 'chmod=', 'chown%20', 'chown ',
- 'chgrp%20', 'chgrp ', 'chown(', 'chgrp(', 'locate%20', 'locate ', 'grep%20', 'grep ',
- 'locate(', 'grep(', 'diff%20', 'diff ', 'kill%20', 'kill ', 'kill(', 'killall',
- 'passwd%20', 'passwd ', '%20passwd', ' passwd', 'passwd(', 'telnet%20', 'telnet ',
- 'vi(', 'vi%20', 'vi ', 'nigga(', '%20nigga', ' nigga', 'nigga%20', 'nigga ',
- 'fopen', 'fwrite', '%20like', ' like', 'like%20', 'like ', '$_',
- '$get', '.system', 'http_php', '%20getenv', ' getenv', 'getenv%20', 'getenv ',
- 'new_password', '/password', 'etc/', '/groups', '/gshadow',
- 'http_user_agent', 'http_host', 'bin/', 'wget%20', 'wget ', 'uname%5c',
- 'uname', 'usr', '/chgrp', '=chown', 'usr/bin', 'g%5c',
- 'g', 'bin/python', 'bin/tclsh', 'bin/nasm', 'perl%20', 'perl ', '.pl',
- 'traceroute%20', 'traceroute ', 'tracert%20', 'tracert ', 'ping%20', 'ping ',
- '/usr/x11r6/bin/xterm', 'lsof%20', 'lsof ', '/mail', '.conf', 'motd%20', 'motd ',
- 'http/1.', '.inc.php', 'config.php', 'cgi-', '.eml', 'file%5c://',
- 'file:', 'file://', 'window.open', 'img src', 'img%20src', 'img src',
- '.jsp', 'ftp.', 'xp_enumdsn', 'xp_availablemedia',
- 'xp_filelist', 'nc.exe', '.htpasswd', 'servlet', '/etc/passwd', '/etc/shadow',
- 'wwwacl', '~root', '~ftp', '.js', '.jsp', '.history',
- 'bash_history', '~nobody', 'server-info', 'server-status',
- '%20reboot', ' reboot', '%20halt', ' halt', '%20powerdown', ' powerdown',
- '/home/ftp', '=reboot', 'www/', 'init%20', 'init ','=halt', '=powerdown',
- 'ereg(', 'secure_site', 'chunked', 'org.apache', '/servlet/con',
- '/robot', 'mod_gzip_status', '.inc', '.system', 'getenv',
- 'http_', '_php', 'php_', 'phpinfo()', '<?php', '?>', '%3C%3Fphp',
- '%3F>', 'sql=', '_global', 'global_', 'global[', '_server',
- 'server_', 'server[', '/modules', 'modules/', 'phpadmin',
- 'root_path', '_globals', 'globals_', 'globals[', 'iso-8859-1',
- '?hl=', '%3fhl=', '.exe', '.sh', '%00', rawurldecode('%00'), '_env'
- );
find www and cut
see results
if you have more problems - try to find ctracker stopping word :wink:
Subject: Re: CTracker Errors
i have this ctracker error when i want to delete an user from a group :?
Subject: Re: CTracker Errors
Hmm sorry, did not work, I have the same code as you stated and there's no plain www in it. 2 times wwwacl and www/, but both didn't do the trick.
difus wrote: [View Post]
Hmm sorry, did not work, I have the same code as you stated and there's no plain www in it. 2 times wwwacl and www/, but both didn't do the trick.
Subject: Re: CTracker errors
it means that it isn't www
do test
replace all this code with
let me know
do test
replace all this code with
let me know
Subject: Re: CTracker errors
Thanks for pointing this out... I'll try to have a look and figure out how to solve it without removing WWW in the CT check how difus is suggesting.
difus, your solution will work, but I have to check if there is a better way for doing it without removing all the security checks of CT. Thanks for pointing us to the solution. :wink:
Steno wrote: [View Post]
Thanks for pointing this out... I'll try to have a look and figure out how to solve it without removing WWW in the CT check how difus is suggesting.
difus, your solution will work, but I have to check if there is a better way for doing it without removing all the security checks of CT. Thanks for pointing us to the solution. :wink:
Subject: Re: CTracker Errors
I am having trouble with Cracker Tracker submitting an article to the Knowledge Base. The problem definitely appears to be in the Title. These triggered an alert:
Huntsville Lakes Council -- Who we are and what we do.
The Huntsville Lakes Council
The HLC
These did not:
Lets try a new title
This is yet another test.
Mission Statement
This is a fresh install -- 1.0.5.5 unzipped, then 1.0.6.6 files copied over, then install.php run -- on a fresh database. Logged in as Admin, no other users registered. I tried to disable Cracker Tracker through the ACP, turning off everything I could find in "Settings", but it still reports "Active" when "Maintenance and Tests" is viewed and obviously still reads the titles.
Huntsville Lakes Council -- Who we are and what we do.
The Huntsville Lakes Council
The HLC
These did not:
Lets try a new title
This is yet another test.
Mission Statement
This is a fresh install -- 1.0.5.5 unzipped, then 1.0.6.6 files copied over, then install.php run -- on a fresh database. Logged in as Admin, no other users registered. I tried to disable Cracker Tracker through the ACP, turning off everything I could find in "Settings", but it still reports "Active" when "Maintenance and Tests" is viewed and obviously still reads the titles.
Subject: Re: CTracker errors
I have fixed this... and I'll check again KB, even if I should already have solved it.
Steno wrote: [View Post]
I have fixed this... and I'll check again KB, even if I should already have solved it.
Page 2 of 3
You cannot post new topicsYou cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events
This is a "Lo-Fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Powered by Icy Phoenix based on phpBB
Generation Time: 0.3372s (PHP: 7% SQL: 93%)
SQL queries: 29 - Debug Off - GZIP Enabled