PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : Typo3 Ext: PHPIDS, Error upon load



mcian
23.02.2010, 15:47
Right after installation in to typo 4.3.2 i get this error message:

++
PHPIDS

Total impact: 16
Affected tags: xss, csrf, id, rfe, lfi

Variable: COOKIE.__utmz | Value: 145453743.1265992084.18.3.utmccn=(referral)|utmcsr =transferserver.jansass.com|utmcct=/cgi-bin/xchng.pl|utmcmd=referral
Impact: 16 | Tags: xss, csrf, id, rfe, lfi
Description: Detects JavaScript location/document property access and window access obfuscation | Tags: xss, csrf | ID: 23
Description: Detects common XSS concatenation patterns 1/2 | Tags: xss, csrf, id, rfe | ID: 30
Description: Detects unknown attack vectors based on PHPIDS Centrifuge detection | Tags: xss, csrf, id, rfe, lfi | ID: 67

Centrifuge detection data
Threshold: ---
Ratio: ---
Converted: ((+++:

Reporting to File (Threshold: 1)

Dieing... (Threshold: 0)

You have been logged out cause of a possible hacking attemp.

Your data has been stored and reported.

If you think this is an error please contact the webmaster of this website.
+++

i have no idea where to start debudding. the site uses realURL, maybe thats the problem?

geralt
30.03.2010, 10:52
hello mcian,
maybe this post can help you:
http://forum.phpids.org/comments.php?DiscussionID=144&page=1#Item_0

.mario
01.04.2010, 18:36
@mcian - yep @geralt is right - that's what it is and should help.

Thanks!

qualle
01.09.2010, 15:08
Hi mcian,


Posted By: mcianReporting to File (Threshold: 1)

Dieing... (Threshold: 0)


it looks like you have set the threshold for exiting the page to 0.
Try to upgrade to the current versions 1.2.2 and reset the dieing threshold to it's default value of 75.

You can find the current version of PHPIDS for TYPO3 here: http://typo3.org/extensions/repository/view/px_phpids/current/

Regards,
qualle