Hi,
I have had PHPIDS installed for a while now to protect my previously hacked jobboard. It seems to work insomuchas I have not had any breaches since I installed it. However, however I have it set up, and I will not pretend that I understand how I do have it set up, seems to often trigger alerts and "cease and desist" messages to users trying to innocently register on the site. Here is an example of what I mean, this person was just filling in a covering letter for their resume at registration, yet it has been treated as an attack on the site. obviously this means that however I have it set up is incorrect. i would like to amend this as obviously it gives a bad user experience. I have made a couple of changes to what is pasted below to try to maintain the privacy of the person who submitted the registration details to my site.
The following attack has been detected by PHPIDS
IP: xxxx (deleted to preserve privacy)
Date: 2011-09-24T03:52:45-06:00
Impact: 4
Affected tags: xss csrf id rfe
Affected parameters: POST.app_letter=From%2C+%0D%0AVINOD.K.JOSEPH%0D%0A %0D%0ATo%2C%0D%0AThe+Principal%2C%0D%0AAl+XXXXX+Bi lingual+School%2C%0D%0ARiyadh%0D%0A%0D%0ADate%3A+% 0924th+Sep+2011%0D%0A%0D%0A%0D%0ADear+Sir%2C%0D%0A %0D%0A%0D%0A+Subject%3A+Application+for+the+post+o f+Mathematics+Teacher+%0D%0A%0D%0AWith+over+8+year s+of+hands-on%2C+successful+teaching+experience%2C+I+am+confi dent+in+my+ability+and+passion+to+become+a+positiv e+addition+to+your+school+community+as+a+High+Scho ol+Mathematics+Teacher.%0D%0A%0D%0AAs+you+will+see +in+the+enclosed+resume+I+have+earned+a+Master%92s +Degree+in+Mathematics%2C+as+well+as+gained+certif icate+in+Bachelor+of+Education.+I+have+had+the+opp ortunity+to+teach+students+who+functioned+below-%2C+on-%2C+and+above+grade+level.%0D%0A%0D%0AI+encourage+ learning+by+using+number+of+different+manipulative %2C+hands-on+activities+and+various+forms+of+technology.+By+ incorporating+class+discussions%2C+open-ended+questions+and+cooperative+learning+I+am+able +to+facilitate+a+highly+interactive+and+inquisitiv e+class+atmosphere.+In+addition+I+utilize+weekly+q uizzes+and+monthly+tests+to+track+student+progress %2C+locate+areas+of+weakness+and+prepare+students+ for+finals+exams.%0D%0A%0D%0ABeing+a+hard+working+ and+well-rounded+educator%2C+I+welcome+the+opportunity+to+m eet+with+you+to+discuss+how+my+extensive+experienc e%2C+collaborative+nature+and+innovative+class+roo m+skills+would+benefit+your+Mathematics+program.+T hank+you+for+your+time+consideration+and+I+look+fo rward+to+hearing+from+you+soon.%0D%0A%0D%0ASincere ly%2C%0D%0AXXXX.X.JXXXXXX%0D%0A,
Request URI: %2Fapply_iframe.php
Origin: XX.XXX.XX.X (deleted to preserve privacy)
Any tips gratefully recieved. Many thanks,
Simon


Zitieren

Lesezeichen