View Issue Details

IDProjectCategoryView StatusLast Update
1811Composrsecurityloggingpublic2015-03-01 05:38
ReporterPDStig Assigned ToGuest  
PrioritynormalSeverityminor 
Status resolvedResolutionfixed 
Summary1811: "Suspected hack attempt" when clicking admin link to view contact us message
DescriptionI was flagged for a suspicious hack attempt when attempting to view a contact us message in the admin queue.

Additional Informationsee screenshots. This seems very familiar as the GET ID is actually a description of a forum topic I posted in the Forum home (most outside layer, not inside any forum groups)

4 screenshots are inside included zip file of stack trace
TagsNo tags attached.
Attach Tags
Attached Files
Untitled4.zip (1,873,827 bytes)
Time estimation (hours)
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Activities

Chris Graham

2015-03-01 10:45

administrator   ~2581

Automated response: Long "contact us" subject lines cause a false-positive hack attack error

When clicking the notification link, a hack-attack error is shown.

Chris Graham

2015-03-01 10:45

administrator   ~2582

Fixed in git commit d483bfb (https://github.com/chrisgraham/Composr/commit/d483bfb - link will become active once code pushed to github)

A hotfix (a TAR of files to upload) have been uploaded to this issue. These files are made to the latest intra-version state (i.e. may roll in earlier fixes too if made to the same files) - so only upload files newer than what you have already. Always take backups of files you are replacing or keep a copy of the manual installer for your version, and only apply fixes you need. These hotfixes are not necessarily reliable or well supported. Not sure how to extract TAR files to your Windows computer? Try 7-zip (http://www.7-zip.org/).

Issue History

Date Modified Username Field Change