PEAK XOOPS - Protector overcautious? in englishin japanese

Protector overcautious?

  • You cannot open a new topic into this forum
  • Guests cannot post into this forum
Previous post - Next post | Parent - Children.1 .2 .3 .4 | Posted on 2009/4/7 15:51
franki  企霹始   Posts: 3
This happened lately on xoops.org. I just wanted to inform a person in charge of a possible attack vector that was reported by Protector. I copied the message and put them into quotes and send it via PM.

Protector thought this was an attack (happens also with CBB). Maybe the error messages should be specially reformatted to be easily copied and distributed within XOOPS?

Any ideas?
Votes:8 Average:8.75
Previous post - Next post | Parent - No child | Posted on 2009/4/11 17:21
GIJOE  黎扦烦菱   Posts: 4110
hi franki.

As I rarely visit xoops.org, I don't know the setting of the site at all.

Which kind of error messages are displayed?

XSS?
SQL Injection?

You can send the content via PM of this site.

In fact, protector can be overcautions upon its setting.
But I can also say that overcautions might be better than without cautions.
Votes:10 Average:9.00
Previous post - Next post | Parent - Children.1 | Posted on 2009/4/14 18:48
franki  企霹始   Posts: 3
The attack was ISOCOM and I sent you a PM with the message. Seems to be no problem here. So it must be a setting on xoops.org I assume.
Votes:9 Average:10.00
Previous post - Next post | Parent - No child | Posted on 2009/4/15 13:27
GIJOE  黎扦烦菱   Posts: 4110
hi franki.

ISOCOM?

It sounds just an issue that xoops.org sets the Protector too sensitive.

Just set them "Sanitizing" or "None".
"Action if an isolated comment-in is found"
"Action if a UNION is found"

This is not a problem of Protector but the site.
Claim it to the administrator of the site.


And, Protector has already moved into "DBLayer Anti SQL Injection".
Both "ISOCOM" or "UNION" were older and useless way, now.
Votes:11 Average:10.00
Previous post - Next post | Parent - No child | Posted on 2009/4/15 19:44
franki  企霹始   Posts: 3
Thx for support, I'll pass the information to the administrator.
Votes:9 Average:10.00
Previous post - Next post | Parent - No child | Posted on 2010/6/26 3:29
danieljones2006  企霹始   Posts: 1
You shouldn't copied the message and putting them into quotes and sending it via PM is ought to be treated as an attack. Yes administrator must be informed.
Votes:6 Average:10.00

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!