View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
14650 | Feature requests | Security | public | 2019-03-14 18:07 | 2023-02-08 16:11 |
Reporter | DenisChenu | Assigned To | |||
Priority | none | Severity | feature | ||
Status | new | Resolution | open | ||
Summary | 14650: Really throw error when user try to hack server | ||||
Description | Looking at https://github.com/LimeSurvey/LimeSurvey/commit/1ed10d3c423187712b8f6a8cb2bc9d5cc3b2deb8
| ||||
Additional Information | Soluytion van be create a function like this getAbsoluteFileName($fileName,$basedirectory) Check final dir : throw a 400 if different | ||||
Tags | No tags attached. | ||||
Bug heat | 256 | ||||
Story point estimate | 40 | ||||
Users affected % | 0 | ||||
related to | 13652 | closed | Feature requests | Revert to inherited button for modified files |
Maybe in 4.0 if you're OK ? |
|
fail2ban for example : https://stackoverflow.com/questions/24250946/fail2ban-to-block-403-errors-apache But better : https://github.com/fail2ban/fail2ban/blob/master/config/filter.d/apache-noscript.conf (for 401 here) |
|
We might want to document desired behaviour on the code guideline? |
|
@ollehar : i have 2 times where we need to have log about attack on server. With redirect : no way to log Why 0% user affected ? |
|
Ah yes, OK. We clearly need more log possibility. |
|
2 times out of millions and millions of requests....? Not sure it's an application responsibility either. :d |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2019-03-14 18:07 | DenisChenu | New Issue | |
2019-03-14 18:07 | DenisChenu | Assigned To | => LouisGac |
2019-03-14 18:07 | DenisChenu | Status | new => feedback |
2019-03-14 18:07 | DenisChenu | Note Added: 50991 | |
2019-03-14 18:07 | DenisChenu | Assigned To | LouisGac => |
2019-03-18 15:45 | DenisChenu | Note Added: 51032 | |
2019-03-18 15:45 | DenisChenu | Status | feedback => new |
2019-03-18 15:45 | DenisChenu | Relationship added | related to 13652 |
2019-03-18 15:48 | DenisChenu | Note Edited: 51032 | |
2019-04-05 09:21 | Mazi | Issue Monitored: Mazi | |
2023-02-08 16:07 | ollehar | Story point estimate | => 5 |
2023-02-08 16:07 | ollehar | Users affected % | => 0 |
2023-02-08 16:08 | ollehar | Story point estimate | 5 => 40 |
2023-02-08 16:08 | ollehar | Note Added: 73742 | |
2023-02-08 16:08 | ollehar | Bug heat | 254 => 256 |
2023-02-08 16:09 | DenisChenu | Note Added: 73743 | |
2023-02-08 16:11 | DenisChenu | Note Added: 73744 | |
2023-02-08 16:11 | ollehar | Note Added: 73745 |