ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

"Scan Attacks" Produce 200 Responses with "Invalid GET Data - Array" error instead of 404/403 Error

January 22, 2012 6:54am

Subscribe [3]
  • #1 / Jan 22, 2012 6:54am

    Favio

    4 posts

    Hello,

    when I try to access a site with the following URL:

    <a href="http://host/phorum/plugin/replace/plugin.php?PHORUM">http://host/phorum/plugin/replace/plugin.php?PHORUM</a>

      it produces a 404 error which is expected.


    However, when trying to access this URL:

    <a href="http://host/phorum/plugin/replace/plugin.php?PHORUM&#91settings_dir&#93=../../../../../../../proc/self/environ">http://host/phorum/plugin/replace/plugin.php?PHORUM[settings_dir]=../../../../../../../proc/self/environ</a>

    which is typical when being hit by someone scanning the website for vulnerabilities, I instead get this error: Invalid GET Data - Array

    Is there a way EE can return a 404 or 403 response, instead of a 200 response? 

    Thanks!

  • #2 / Jan 23, 2012 12:49pm

    Robin Sowell

    13255 posts

    Hi Favio,

    Not currently, but you make a good point.  I’ve added this into our internal tracker as a desired feature- because it is and it’s one that should be a quick addition for the dev team.  Currently, however, there isn’t a good way to do it natively.

  • #3 / Apr 13, 2012 1:33pm

    kayaker392

    11 posts

    Any update on status here?

  • #4 / Apr 13, 2012 3:05pm

    Robin Sowell

    13255 posts

    Thanks for the reminder to double check, Kayaker392.  As per this Bug Report we added 503 headers in a number of spots for the upcoming 2.5 release.  I just checked and made sure they’re in for the ‘Disallowed GET’ exit in EE_Input as well.

    Which is to say- it’s still an issue in 2.4, but should be good in upcoming 2.5.

  • #5 / Apr 13, 2012 3:37pm

    kayaker392

    11 posts

    Great, thanks!!

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases