Menu

Topic-icon Consistent firewall issue

  • helsinkisisu
  • helsinkisisu's Avatar Topic Author
  • Offline
  • Fresh Boarder
  • Fresh Boarder
More
4 weeks 1 day ago - 4 weeks 1 day ago #7990 by helsinkisisu
Consistent firewall issue was created by helsinkisisu
On one site I have a problem where visits are being blocked under HTTP/com_contact. Frequently these visits are genuine and legitimate.

In every instance the description says: "Integers (0x format) :[REQUEST:4fb0df10920f547a852c54ed0a217e12]"

Two examples of listed text in the box show:
Mozilla/5.0 (Linux; Android 9; LLD-L31 Build/HONORLLD-L31; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/83.0.4103.106 Mobile Safari/537.36 Instagram 146.0.0.27.125 Android (28/9; 480dpi; 1080x2032; HUAWEI/HONOR; LLD-L31; HWLLD-H; hi6250; en_GB; 221134032)
Mozilla/5.0 (iPhone; CPU iPhone OS 13_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Instagram 146.0.0.21.122 (iPhone10,4; iOS 13_5_1; fi_FI; fi-FI; scale=2.00; 750x1334; 220223664)

Thereare quite a few of these being logged, all different IPs, but always HTTP | com_contact | Integers (0x format) :[REQUEST:4fb0df10920f547a852c54ed0a217e12]

I would be grateful for advice on how these can be better verified as they are resulting in missed potential customers.
Last edit: 4 weeks 1 day ago by helsinkisisu.

Please Log in or Create an account to join the conversation.

More
4 weeks 1 day ago #7991 by Jose
Replied by Jose on topic Consistent firewall issue
Hi helsinkisisu,

The "0x integers" and also the "line comments" filters into Filter exceptions -> SQL Injection tab are too sensitive and can cause many false positives. To avoid issues with them I recommend to enable the 'Easy config' feature from main panel of Securitycheck Pro. You can also disable them adding a * into them or, as in your case, disable them for the specific component affected (com_content) in your case.

Regards,
Jose
The following user(s) said Thank You: helsinkisisu

Please Log in or Create an account to join the conversation.

  • helsinkisisu
  • helsinkisisu's Avatar Topic Author
  • Offline
  • Fresh Boarder
  • Fresh Boarder
More
4 weeks 1 day ago #7992 by helsinkisisu
Replied by helsinkisisu on topic Consistent firewall issue
Thanks for the quick reply (as usual), Jose. I will try your suggestions and let you know.

Please Log in or Create an account to join the conversation.

More
4 weeks 1 day ago #7993 by Jose
Replied by Jose on topic Consistent firewall issue
You're welcome! :)

Regards,
Jose

Please Log in or Create an account to join the conversation.

  • helsinkisisu
  • helsinkisisu's Avatar Topic Author
  • Offline
  • Fresh Boarder
  • Fresh Boarder
More
1 week 4 days ago #8077 by helsinkisisu
Replied by helsinkisisu on topic Consistent firewall issue
There have been no false positive over the past two weeks, so I'm happy it's sorted. Thanks!

Please Log in or Create an account to join the conversation.

More
1 week 4 days ago #8078 by Jose
Replied by Jose on topic Consistent firewall issue
You're welcome!

Regards,
Jose

Please Log in or Create an account to join the conversation.

Time to create page: 0.131 seconds
Powered by Kunena Forum

Login or Sign In