View Issue Details

IDProjectCategoryView StatusLast Update
0001811Composrsecurityloggingpublic2015-03-01 05:38
ReporterPatrick SchmalstigAssigned To 
SeverityMinor-bug 
Status resolvedResolutionfixed 
Product Version 
Fixed in Version 
Summary0001811: "Suspected hack attempt" when clicking admin link to view contact us message
DescriptionI was flagged for a suspicious hack attempt when attempting to view a contact us message in the admin queue.

Additional Informationsee screenshots. This seems very familiar as the GET ID is actually a description of a forum topic I posted in the Forum home (most outside layer, not inside any forum groups)

4 screenshots are inside included zip file of stack trace
TagsNo tags attached.
Time estimation (hours)
Sponsorship open

Activities

Patrick Schmalstig

2015-03-01 05:38

administrator  

Untitled4.zip (1,873,827 bytes)

Chris Graham

2015-03-01 10:45

administrator   ~0002581

Automated response: Long "contact us" subject lines cause a false-positive hack attack error

When clicking the notification link, a hack-attack error is shown.

Chris Graham

2015-03-01 10:45

administrator   ~0002582

Fixed in git commit d483bfb (https://github.com/chrisgraham/Composr/commit/d483bfb - link will become active once code pushed to github)

A hotfix (a TAR of files to upload) have been uploaded to this issue. These files are made to the latest intra-version state (i.e. may roll in earlier fixes too if made to the same files) - so only upload files newer than what you have already. Always take backups of files you are replacing or keep a copy of the manual installer for your version, and only apply fixes you need. These hotfixes are not necessarily reliable or well supported. Not sure how to extract TAR files to your Windows computer? Try 7-zip (http://www.7-zip.org/).

hotfix-1811, 2015-03-01 11am.tar (10,240 bytes)

Issue History

Date Modified Username Field Change