View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 14650 | Feature requests | Security | public | 2019-03-14 18:07 | 2023-02-08 16:11 |
| Reporter | DenisChenu | Assigned To | |||
| Priority | none | Severity | feature | ||
| Status | new | Resolution | open | ||
| Summary | 14650: Really throw error when user try to hack server | ||||
| Description | Looking at https://github.com/LimeSurvey/LimeSurvey/commit/1ed10d3c423187712b8f6a8cb2bc9d5cc3b2deb8
| ||||
| Additional Information | Soluytion van be create a function like this getAbsoluteFileName($fileName,$basedirectory) Check final dir : throw a 400 if different | ||||
| Tags | No tags attached. | ||||
| Bug heat | 256 | ||||
| Story point estimate | 40 | ||||
| Users affected % | 0 | ||||
| related to | 13652 | closed | Feature requests | Revert to inherited button for modified files |
|
Maybe in 4.0 if you're OK ? |
|
|
fail2ban for example : https://stackoverflow.com/questions/24250946/fail2ban-to-block-403-errors-apache But better : https://github.com/fail2ban/fail2ban/blob/master/config/filter.d/apache-noscript.conf (for 401 here) |
|
|
We might want to document desired behaviour on the code guideline? |
|
|
@ollehar : i have 2 times where we need to have log about attack on server. With redirect : no way to log Why 0% user affected ? |
|
Ah yes, OK. We clearly need more log possibility. |
|
|
2 times out of millions and millions of requests....? Not sure it's an application responsibility either. :d |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2019-03-14 18:07 | DenisChenu | New Issue | |
| 2019-03-14 18:07 | DenisChenu | Assigned To | => LouisGac |
| 2019-03-14 18:07 | DenisChenu | Status | new => feedback |
| 2019-03-14 18:07 | DenisChenu | Note Added: 50991 | |
| 2019-03-14 18:07 | DenisChenu | Assigned To | LouisGac => |
| 2019-03-18 15:45 | DenisChenu | Note Added: 51032 | |
| 2019-03-18 15:45 | DenisChenu | Status | feedback => new |
| 2019-03-18 15:45 | DenisChenu | Relationship added | related to 13652 |
| 2019-03-18 15:48 | DenisChenu | Note Edited: 51032 | |
| 2019-04-05 09:21 | Mazi | Issue Monitored: Mazi | |
| 2023-02-08 16:07 | ollehar | Story point estimate | => 5 |
| 2023-02-08 16:07 | ollehar | Users affected % | => 0 |
| 2023-02-08 16:08 | ollehar | Story point estimate | 5 => 40 |
| 2023-02-08 16:08 | ollehar | Note Added: 73742 | |
| 2023-02-08 16:08 | ollehar | Bug heat | 254 => 256 |
| 2023-02-08 16:09 | DenisChenu | Note Added: 73743 | |
| 2023-02-08 16:11 | DenisChenu | Note Added: 73744 | |
| 2023-02-08 16:11 | ollehar | Note Added: 73745 |