+ Reply to Thread
Results 1 to 12 of 12

Source of Securi nasty message

  1. #1
    Forum Expert
    Join Date
    01-23-2013
    Location
    USA
    MS-Off Ver
    Microsoft 365 aka Office 365
    Posts
    3,863

    Source of Securi nasty message

    Hopefully, this post will help the ExcelForum Tech Staff reduce the number of Securi messages. When I attempted to 'Go Advanced' when editing a Private Message, the line in red below was the cause of a Securi SQL injection was detected and blocked message.

    I know that line was the cause, because when I removed the line from the PM, the Securi message went away. When I put the line back in the PM, the Securi message returned

    Please Login or Register  to view this content.

    Excerpt from Securi message:
    Please Login or Register  to view this content.
    Lewis

  2. #2
    Forum Expert JBeaucaire's Avatar
    Join Date
    03-21-2004
    Location
    Bakersfield, CA
    MS-Off Ver
    2010, 2016, Office 365
    Posts
    33,492

    Re: Source of Securi nasty message

    Awesome info, I'll pass it on!
    _________________
    Microsoft MVP 2010 - Excel
    Visit: Jerry Beaucaire's Excel Files & Macros

    If you've been given good help, use the icon below to give reputation feedback, it is appreciated.
    Always put your code between code tags. [CODE] your code here [/CODE]

    ?None of us is as good as all of us? - Ray Kroc
    ?Actually, I *am* a rocket scientist.? - JB (little ones count!)

  3. #3
    Forum Expert Fotis1991's Avatar
    Join Date
    10-11-2011
    Location
    Athens(The homeland of the Democracy!). Greece
    MS-Off Ver
    Excel 1997!&2003 & 2007&2010
    Posts
    13,744

    Re: Source of Securi nasty message

    Nice one Lewis!!

    Perhaps the owner of the forum, has to hire you as technical advisor!!
    Regards

    Fotis.

    -This is my Greek whisper to Europe.

    --Remember, saying thanks only takes a second or two. Click the little star * below, to give some Rep if you think an answer deserves it.

    Advanced Excel Techniques: http://excelxor.com/

    --KISS(Keep it simple Stupid)

    --Bring them back.

    ---See about Acropolis of Athens.

    --Visit Greece.

  4. #4
    Forum Expert
    Join Date
    01-23-2013
    Location
    USA
    MS-Off Ver
    Microsoft 365 aka Office 365
    Posts
    3,863

    Re: Source of Securi nasty message

    Additional Information on a similar Sucuri nasty message. I was not able to save the nasty text, however the symptoms were as follows:

    Text sleep() generated the same nasty message as above.

    Removing the parentheses from the sleep as per below allowed the message to be accepted.

    When sending a PM today, the following PM went through OK:
    Hi,

    I'm glad it worked out for you. If you ever need to use a delay of less than one second, the API (Application Programmer's Interface) sleep function is available.

    ...
    Lewis

  5. #5
    Forum Expert snb's Avatar
    Join Date
    05-09-2010
    Location
    VBA
    MS-Off Ver
    Redhat
    Posts
    5,649

    Re: Source of Securi nasty message

    The same applies to

    Please Login or Register  to view this content.



  6. #6
    Forum Expert teylyn's Avatar
    Join Date
    10-28-2008
    Location
    New Zealand
    MS-Off Ver
    Excel 365 Insider Fast
    Posts
    11,372

    Re: Source of Securi nasty message

    These messages are just false positives from a filter that Sucuri uses to monitor for certain expressions that may appear in hacking attempts. It does not mean that the page/PM/post/comment is actually a problem. It has basically no value. It's the same principle that the forum software uses to replace certain words with *** because they are on a short list of words that are considered rude or otherwise unsuitable. Sometimes perfectly valid text gets replaced by ***, for example when you post a table that has a column for "gender" but you have labeled it with the other word instead. The filter does not evaluate the context. It just replaces the offending characters. The Sucuri warning about SQL injection is just as useful and just as (not) correct.

    I'd be very surprised if a VBulletin board would allow SQL injection via forum posts or PMs in the first place. It's a teeny bit more complicated than that.
    Last edited by teylyn; 06-11-2015 at 05:02 AM.

  7. #7
    Forum Expert
    Join Date
    01-23-2013
    Location
    USA
    MS-Off Ver
    Microsoft 365 aka Office 365
    Posts
    3,863

    Re: Source of Securi nasty message

    @teylyn,

    Thank you for your response.

    I understand that I caused a false positive and that was my speculation all along. My hope was that ExcelForum could add filter rules such as ignore anything that is NOT inside CODE TAGS, or that certain POSITIVE KEYWORDS could be ignored.

    Lewis

  8. #8
    Forum Guru AlKey's Avatar
    Join Date
    07-20-2009
    Location
    Lakeland, FL USA
    MS-Off Ver
    Microsoft Office 2010/ Office 365
    Posts
    8,903

    Re: Source of Securi nasty message

    I also had the same problem when I tried to post a formula that contained CHAR() function. The only workaround I could come up with is to insert some characters into the function name. After that I would go to Edit and remove those characters.
    If you like my answer please click on * Add Reputation
    Don't forget to mark threads as "Solved" if your problem has been resolved

    "Nothing is so firmly believed as what we least know."
    --Michel de Montaigne

  9. #9
    Valued Forum Contributor
    Join Date
    03-22-2013
    Location
    Australia,NSW, Wirrimbi
    MS-Off Ver
    Excel 2013
    Posts
    1,057

    Re: Source of Securi nasty message

    This code brought the same warning...
    Please Login or Register  to view this content.

  10. #10
    Forum Expert teylyn's Avatar
    Join Date
    10-28-2008
    Location
    New Zealand
    MS-Off Ver
    Excel 365 Insider Fast
    Posts
    11,372

    Re: Source of Securi nasty message

    Quote Originally Posted by LJMetzger View Post
    @teylyn,
    My hope was that ExcelForum could add filter rules such as ignore anything that is NOT inside CODE TAGS, or that certain POSITIVE KEYWORDS could be ignored.

    Lewis
    Yeah, well, there's always hope.

    Currently, my hope is that Excelforum will manage to display web standard image formats to web standard browsers. Apparently, half the population of this forum cannot see PNG images in posts.

    Assuming that PNG images in posts happen a lot more often than code keywords that trigger Securi blocks, and seeing that the issue of PNG images not showing for users with certain browsers has been reported about a year ago, I would not get my hopes up that your suggestion gets any traction.

    For the PNG problem, there are tried and tested solutions to the problem and people who know about forum software have posted them.

    Still, nothing has happened.

    As far as I can see, the "tech team" will try (! - with varying degrees of success) to keep the lights on, but on top of that, don't get your hopes up. Don't expect more than the basics, because this forum does not even manage to deliver the basics of a modern forum.

  11. #11
    Forum Expert
    Join Date
    01-23-2013
    Location
    USA
    MS-Off Ver
    Microsoft 365 aka Office 365
    Posts
    3,863

    Re: Source of Securi nasty message

    FYI,

    The Firewall would not let me put the following code in post #8 of the following thread today http://www.excelforum.com/excel-prog...ml#post4203888
    Please Login or Register  to view this content.
    Sucuri WebSite Firewall - CloudProxy - Access Denied
    ...
    Block details

    Your IP: 96.234.66.73
    URL: http://www.excelforum.com/editpost.p...postid=4203888
    Your Browser: Mozilla/5.0 (Windows NT 6.0; rv:38.0) Gecko/20100101 Firefox/38.0
    Block ID: SQLi17
    Block reason: SQL injection was detected and blocked.
    Time: Wed, 30 Sep 2015 09:44:38 -0400
    Server ID: cp448

    It is very interesting that when I add the line to the referenced thread, the Firewall blocks me, but the Firewall allows the same code in this thread.

    Additional information. When I surrounded the word 'Select' with BOLD and RED COLOR in the other thread, the Firewall finally allowed the code.

    Lewis
    Last edited by LJMetzger; 09-30-2015 at 09:59 AM.

  12. #12
    Forum Guru xladept's Avatar
    Join Date
    04-14-2012
    Location
    Pasadena, California
    MS-Off Ver
    Excel 2003,2010
    Posts
    12,378

    Re: Source of Securi nasty message

    Hey Lewis,

    It's Sucuri like in suck
    If I've helped you, please consider adding to my reputation - just click on the liitle star at the left.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~(Pride has no aftertaste.)

    You can't do one thing. XLAdept

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~aka Orrin

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Extracting city state zip out of nasty address field
    By silvertrace in forum Excel Formulas & Functions
    Replies: 5
    Last Post: 01-21-2015, 09:35 PM
  2. Nasty 400 when running web query macro
    By mwalker.web in forum Excel Programming / VBA / Macros
    Replies: 1
    Last Post: 09-29-2006, 03:11 PM
  3. [SOLVED] Nasty IF Statement
    By bodhisatvaofboogie in forum Excel Programming / VBA / Macros
    Replies: 3
    Last Post: 07-21-2006, 08:35 AM
  4. [SOLVED] nasty little excel autofilling ******
    By [email protected] in forum Excel General
    Replies: 1
    Last Post: 07-12-2006, 07:10 PM
  5. source location and error message 400
    By owl527 in forum Excel Programming / VBA / Macros
    Replies: 1
    Last Post: 10-14-2005, 12:03 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0 RC 1