TP-Docs
HTML5 Icon HTML5 Icon HTML5 Icon
TP on Social Media

Recent

Welcome to TinyPortal. Please login or sign up.

Members
Stats
  • Total Posts: 196,004
  • Total Topics: 21,330
  • Online today: 468
  • Online ever: 8,223 (February 19, 2025, 04:35:35 AM)
Users Online
  • Users: 0
  • Guests: 107
  • Total: 107

You don't have permission to access

Started by sharp1, August 23, 2006, 07:58:51 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

sharp1

Ok this is one of the most aggravating thing ever, I have recently turned off the 'max char.' in posts... using wiki theme on rc2. After posting a decent list in the topic and pressing preview or post button I get this error:

Forbidden
You don't have permission to access /se7en/index.php on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.


I have uninstalled the few mods I had and other than that noth9ing has really changed in the index.php file, and the perms are 755, obviously I have access to index.php if the forum is coming up and I can make smaller posts... so why is this happening?

On normal occasions I would simply re-install the whole bit but this time I have place a number of hours in posting content and wouldnt know a damn thing about moving content ie posts from one forum to another, but I would think this error would have a quick fix

Crip

I have become comfortably numb!

Cripzone | Crip's Free 2.0.2 Themes



sharp1


Crip

I have become comfortably numb!

Cripzone | Crip's Free 2.0.2 Themes



sharp1

very very odd, I mean think about it, the post you made [reply] was the same size as the original topic post, yet making one in the google section less than half the size wouldnt work, now jus pasting the same article 3 times and I didnt have an issue... almost makes me wonder about the server here at work, slow as @#%* and always times out on me, but I didnt get a timeout error so anyways... thank you for checking, I will continue to test htis out...see what happenes, stay tuned

G6Cad

Also im not sure this error is related to TP at all ?

sharp1

well It must be, default doesnt have the same issue, I suppose it could be the wiki theme but the error comes from the main index.php, considering tp doesnt do anything at all for the wiki theme.... 9x will though, still waiting for bloc to get his goodnights sleep....

sharp1

g6, you seem like the type to always complain.... If your unsure of where or what the error belongs to then why add it MAY not belong to tp???? If you do know then a (move) reply would be nice, other than that your input wasnt of any help to me.

sharp1

Well here we go again... and this is what I am trying to place in a topic:


filetype:pl -intext:"/usr/bin/perl" inurl:webcal (inurl:webcal | inurl:add | inurl:delete | inurl:config)

WebCal allows you to create and maintain an interactive events calendar or scheduling system on your Web site. The file names explain themselves, but don't abuse the faulty admins.

Click HERE to test



"e107.org 2002/2003" inurl:forum_post.php?nt

e107 is prone to an input validation vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of this issue will permit an attacker to create arbitrary forum message posts.

http://www.securityfocus.com/bid/14699

Click HERE for test link



"File Upload Manager v1.3" "rename to"

thepeak file upload manager let you manage your webtree with up and downloading files.

Click HERE for test link



"Mail-it Now!" intitle:"Contact form" | inurl:contact.php


Mail-it Now! 1.5 (possibly prior versions) contact.php remote code execution

site: http://www.skyminds.net/source/
description: a mail form script


vulnerability: unsecure file creation -> remote code execution

when you post an attachment and upload it to the server (usually to "./upload/" dir )
the script rename the file in this way:
[time() function result] + [-] + [filename that user choose]
spaces are simply replaced with "_" chars.
So a user can post an executable attachment, calculate the time() result locally
then, if attachment is a file like this:

<?php error_reporting(0); system($HTTP_GET_VARS[command]); ?>

can launch commands on target system, example:

http://[target]/[path]/[time() result]-[filename.php]?command=cat%20/etc/passwd

u can find my poc code at this url: http://rgod.altervista.org/mailitnow.html

Click HERE for test link



"maxwebportal" inurl:"default" "snitz forums" +"homepage" -intitle:maxwebportal


Several vulnerabilities relating to this.

MaxWebPortal is a web portal and online community system which includes features such as web-based administration, poll, private/public events calendar, user customizable color themes, classifieds, user control panel, online pager, link, file, article, picture managers and much more. User interface allows members to add news, content, write reviews and share information among other registered users.

h**p://www.maxwebportal.com/

Click HERE for test link


Doesnt make any sense at all, I figured maybe the codes in the topic so I coded them out, yet still happens

sharp1

but it cant be the codes because I can enter each seg. in their own topic without issues

This website is proudly hosted on Crocweb Cloud Website Hosting.