View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update | 
|---|---|---|---|---|---|
| 14650 | Feature requests | Security | public | 2019-03-14 18:07 | 2023-02-08 16:11 | 
| Reporter | DenisChenu | Assigned To | |||
| Priority | none | Severity | feature | ||
| Status | new | Resolution | open | ||
| Summary | 14650: Really throw error when user try to hack server | ||||
| Description | Looking at https://github.com/LimeSurvey/LimeSurvey/commit/1ed10d3c423187712b8f6a8cb2bc9d5cc3b2deb8 
 | ||||
| Additional Information | Soluytion van be create a function like this getAbsoluteFileName($fileName,$basedirectory) Check final dir : throw a 400 if different | ||||
| Tags | No tags attached. | ||||
| Bug heat | 256 | ||||
| Story point estimate | 40 | ||||
| Users affected % | 0 | ||||
| related to | 13652 | closed | Feature requests | Revert to inherited button for modified files | 
| Maybe in 4.0 if you're OK ? | |
| 
 fail2ban for example : https://stackoverflow.com/questions/24250946/fail2ban-to-block-403-errors-apache But better : https://github.com/fail2ban/fail2ban/blob/master/config/filter.d/apache-noscript.conf (for 401 here) | |
| We might want to document desired behaviour on the code guideline? | |
| @ollehar : i have 2 times where we need to have log about attack on server. With redirect : no way to log Why 0% user affected ? | |
| 
 Ah yes, OK. We clearly need more log possibility. | |
| 2 times out of millions and millions of requests....? Not sure it's an application responsibility either. :d | |
| Date Modified | Username | Field | Change | 
|---|---|---|---|
| 2019-03-14 18:07 | DenisChenu | New Issue | |
| 2019-03-14 18:07 | DenisChenu | Assigned To | => LouisGac | 
| 2019-03-14 18:07 | DenisChenu | Status | new => feedback | 
| 2019-03-14 18:07 | DenisChenu | Note Added: 50991 | |
| 2019-03-14 18:07 | DenisChenu | Assigned To | LouisGac => | 
| 2019-03-18 15:45 | DenisChenu | Note Added: 51032 | |
| 2019-03-18 15:45 | DenisChenu | Status | feedback => new | 
| 2019-03-18 15:45 | DenisChenu | Relationship added | related to 13652 | 
| 2019-03-18 15:48 | DenisChenu | Note Edited: 51032 | |
| 2019-04-05 09:21 | Mazi | Issue Monitored: Mazi | |
| 2023-02-08 16:07 | ollehar | Story point estimate | => 5 | 
| 2023-02-08 16:07 | ollehar | Users affected % | => 0 | 
| 2023-02-08 16:08 | ollehar | Story point estimate | 5 => 40 | 
| 2023-02-08 16:08 | ollehar | Note Added: 73742 | |
| 2023-02-08 16:08 | ollehar | Bug heat | 254 => 256 | 
| 2023-02-08 16:09 | DenisChenu | Note Added: 73743 | |
| 2023-02-08 16:11 | DenisChenu | Note Added: 73744 | |
| 2023-02-08 16:11 | ollehar | Note Added: 73745 | 



