[drupal-support] Too many security notices in banner module
o am getting a lot of security notices in the banner module. I will be glad if anyone will give me an idea why this is so. I get this notice for every single user. I have incldued some of the notices below. Regards Larry Location /banner_file.php?pos=0&path=files&tid=0&max=10<http://londonbusinessnetwork.com/?q=/banner_file.php?pos=0&path=files&tid=0&max=10> Terminated request because of suspicious input data: * a:3:{i:0;a:1:{i:0;a:1:{i:0;a:4:{i:0;s:1:"2";i:1;s:1:"5";i:2;s:2:"13";i:3;s:2:"22";}}}i:1;a:1:{i:0;a:4:{i:2;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"945";s:9:"day_views";s:3:"925";s:10:"week_views";s:3:"945";s:13:"day_max_views";s:1:"0";s:14:"week_max_views";s:1:"0";s:9:"max_views";s:1:"0";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:153:" document.write('<a href="?q=banner/2"><img src=\'?q=system/files&file=banners/networking_expo_newlogo_0.jpg\' border=0 width=\'100\' height=\'50\'></a>')";}i:5;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"814";s:9:"day_views";s:3:"814";s:10:"week_views";s:3:"814";s:13:"day_max_views";s:4:"1000";s:14:"week_max_views";s:4:"1000";s:9:"max_views";s:1:"0";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:148:" document.write('<a href="?q=banner/5"><img src=\'?q=system/files&file=banners/Lyncs Logo final 2_0.jpg\' border=0 width=\'127\' height=\'42\'></a>')";}i:13;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"331";s:9:"day_views";s:3:"331";s:10:"week_views";s:3:"331";s:13:"day_max_views";s:3:"500";s:14:"week_max_views";s:3:"500";s:9:"max_views";s:3:"500";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:519:" document.write('<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase=" http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=..." width="125" height="125"> <param name="movie" value="?q=system/files&file=banners/banner1.swf"> <param name="quality" value="high"> <embed src="?q=system/files&file=banners/banner1.swf" quality="high" pluginspage="http://www.macromedia.com/go/getflashplayer" type="application/x-shockwave-flash" width="125" height="125"></embed></object>')";}i:22;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"326";s:9:"day_views";s:3:"326";s:10:"week_views";s:3:"326";s:13:"day_max_views";s:3:"500";s:14:"week_max_views";s:4:"1000";s:9:"max_views";s:4:"1000";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:138:" document.write('<a href="?q=banner/22"><img src=\'?q=system/files&file=banners/LOGO22_0.gif\' border=0 width=\'125\' height=\'125\'></a>')";}}}i:2;i:1128065349;}*. Severity notice notice Hostname 195.93.21.8 <http://195.93.21.8> Upcoming events - If you could only attend one business networking event a year<http://londonbusinessnetwork.com/?q=if_you_could_only_attend_one_business_networking_event_a_year> (story)(57 days) - If you could only attend one business networking event a year<http://londonbusinessnetwork.com/?q=if_you_could_only_attend_one_business_networking_event_a_year_0> (story)(57 days) [image: Add to iCalendar] <webcal://londonbusinessnetwork.com/?q=event/ical> more <http://londonbusinessnetwork.com/?q=event> We recommend <http://www.amazon.co.uk/exec/obidos/redirect?tag=itsupport-21%26link_code=xm2%26camp=2025%26creative=165953%26path=http://www.amazon.co.uk/gp/redirect.html%253fASIN=B000299SM0%2526tag=itsupport-21%2526lcode=xm2%2526cID=2025%2526ccmID=165953%2526location=/o/ASIN/B000299SM0%25253FSubscriptionId=0JEKXTWNECEXBJGY7RR2> -- London Networking EXPO™ - "The Ultimate Business Networking Experience™ in Europe! Tel 08701994474
Did you resolve this ? You can have a look at function valid_input_data in common.inc, looking through the regexp I was able to understand what was wrong with my input, it was because I put a $data... Also remember that uid 1 by´pass theses checks. ----- Original Message ----- From: Larry To: drupal-support@drupal.org Sent: Friday, September 30, 2005 2:37 AM Subject: [drupal-support] Too many security notices in banner module o am getting a lot of security notices in the banner module. I will be glad if anyone will give me an idea why this is so. I get this notice for every single user. I have incldued some of the notices below. Regards Larry Location /banner_file.php?pos=0&path=files&tid=0&max=10 Terminated request because of suspicious input data: a:3:{i:0;a:1:{i:0;a:1:{i:0;a:4:{i:0;s:1:"2";i:1;s:1:"5";i:2;s:2:"13";i:3;s:2:"22";}}}i:1;a:1:{i:0;a:4:{i:2;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"945";s:9:"day_views";s:3:"925";s:10:"week_views";s:3:"945";s:13:"day_max_views";s:1:"0";s:14:"week_max_views";s:1:"0";s:9:"max_views";s:1:"0";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:153:" document.write('<a href="?q=banner/2"><img src=\'?q=system/files&file=banners/networking_expo_newlogo_0.jpg\' border=0 width=\'100\' height=\'50\'></a>')";}i:5;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"814";s:9:"day_views";s:3:"814";s:10:"week_views";s:3:"814";s:13:"day_max_views";s:4:"1000";s:14:"week_max_views";s:4:"1000";s:9:"max_views";s:1:"0";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:148:" document.write('<a href="?q=banner/5"><img src=\'?q=system/files&file=banners/Lyncs Logo final 2_0.jpg\' border=0 width=\'127\' height=\'42\'></a>')";}i:13;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"331";s:9:"day_views";s:3:"331";s:10:"week_views";s:3:"331";s:13:"day_max_views";s:3:"500";s:14:"week_max_views";s:3:"500";s:9:"max_views";s:3:"500";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:519:" document.write('<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=... " width="125" height="125"> <param name="movie" value="?q=system/files&file=banners/banner1.swf"> <param name="quality" value="high"> <embed src="?q=system/files&file=banners/banner1.swf" quality="high" pluginspage=" http://www.macromedia.com/go/getflashplayer" type="application/x-shockwave-flash" width="125" height="125"></embed></object>')";}i:22;O:8:"stdClass":9:{s:5:"views";i:0;s:11:"total_views";s:3:"326";s:9:"day_views";s:3:"326";s:10:"week_views";s:3:"326";s:13:"day_max_views";s:3:"500";s:14:"week_max_views";s:4:"1000";s:9:"max_views";s:4:"1000";s:8:"filename";s:21:"?q=system/files&file=";s:4:"html";s:138:" document.write('<a href="?q=banner/22"><img src=\'?q=system/files&file=banners/LOGO22_0.gif\' border=0 width=\'125\' height=\'125\'></a>')";}}}i:2;i:1128065349;}. Severity notice notice Hostname 195.93.21.8 Upcoming events a.. If you could only attend one business networking event a year (story)(57 days) b.. If you could only attend one business networking event a year (story)(57 days) more We recommend -- London Networking EXPO™ - "The Ultimate Business Networking Experience™ in Europe! Tel 08701994474 ------------------------------------------------------------------------------ -- [ Drupal support list | http://lists.drupal.org/ ]
participants (2)
-
Larry -
Nicolas Tostin