Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


timmmay

20857 posts

Uber Geek
+1 received by user: 5349

Trusted
Lifetime subscriber

#214787 28-May-2017 16:37
Send private message

I've posted 3-4 times today. I've gotten a catchpa at least twice. I'm connected directly to the net, no proxy or VPN.

 

Not really a problem, just odd.


Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41024

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1790702 28-May-2017 16:54
Send private message

Cloudflare being over protective today.




Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 




networkn
Networkn
32862 posts

Uber Geek
+1 received by user: 15453

ID Verified
Trusted
Lifetime subscriber

  #1791088 29-May-2017 13:46
Send private message

I have had this for the first time in my MANY visits to GZ over the years from various devices. This is from my office computer, which GZ will know well :) 

 

 


Geektastic
18009 posts

Uber Geek
+1 received by user: 8465

Trusted
Lifetime subscriber

  #1791305 29-May-2017 18:25
Send private message

networkn:

 

I have had this for the first time in my MANY visits to GZ over the years from various devices. This is from my office computer, which GZ will know well :) 

 

 

 

 

 

 

+1








michaelmurfy
meow
13579 posts

Uber Geek
+1 received by user: 10910

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1791306 29-May-2017 18:25
Send private message

I must say I've got this a few times over the last couple of days. @freitasm did you check what rule is triggering this?





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


Behodar
11089 posts

Uber Geek
+1 received by user: 6069

Trusted
Lifetime subscriber

  #1791309 29-May-2017 18:30
Send private message

I made a post 25 minutes ago with no issues, then another just now from the same static IP address and got the prompt. It really threw me because it takes over the entire window.


freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41024

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1791344 29-May-2017 19:39
Send private message

No, I don't know which rule is triggering this. I didn't change the sensitivity level and checked this. I will look at one of your IP addresses now - if you posted from a different IP from the previous two posts when it happened let me know.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


HP

 
 
 
 

Shop now for HP laptops and other devices (affiliate link).
freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41024

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1791347 29-May-2017 19:45
Send private message

@Geektastic, your post here triggered a SQL Injection alert:

 

60024            OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION-ARGS:MESSAGE="></
950901 OWASP_CRS/WEB_ATTACK/SQL_INJECTION-ARGS:MESSAGE=p>Yep
981257 DETECTS MYSQL COMMENT-/SPACE-OBFUSCATED INJECTIONS AND BACKTICK TERMINATION-OWASP_CRS/WEB_ATTACK/SQLI-2000000408_146=, and it still annoys me&nbsp;<img src="https://cdn.tinymce.com/4/plugins/emoticons/img/smiley-tongue-out.gif" alt=
981245 DETECTS BASIC SQL AUTHENTICATION BYPASS ATTEMPTS 2/3-OWASP_CRS/WEB_ATTACK/SQLI-2000000408_146="></p> 1
981247B            DETECTS CONCATENATED BASIC SQL INJECTION AND SQLLFI ATTEMPTS-OWASP_CRS/WEB_ATTACK/SQLI-2000000409_167=190840 insert
960024            OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION-ARGS:MESSAGE

 

@Behodar: One of your posts triggered a SQL Injection alert:

 

960024            OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION-ARGS:MESSAGE=> <
981231 OWASP_CRS/WEB_ATTACK/SQL_INJECTION-ARGS:MESSAGE= #1
950901 OWASP_CRS/WEB_ATTACK/SQL_INJECTION-ARGS:MESSAGE=p>It
981245 DETECTS BASIC SQL AUTHENTICATION BYPASS ATTEMPTS 2/3-OWASP_CRS/WEB_ATTACK/SQLI-2000000408_146="><br>T
981246 DETECTS BASIC SQL AUTHENTICATION BYPASS ATTEMPTS 3/3-OWASP_CRS/WEB_ATTACK/SQLI-2000000408_146=or how it stands up to baggage handlers but all 3 of the fabrics you see there look like the day I got them and they have all done at least 4x
981247B            DETECTS CONCATENATED BASIC SQL INJECTION AND SQLLFI ATTEMPTS-OWASP_CRS/WEB_ATTACK/SQLI-2000000409_167=179 214792 1 insert
960024            OWASP_CRS/WEB_ATTACK/COMMAND_INJECTION-ARGS:MESSAGE

 

I will have to look at what changed in the rules to trigger this.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Behodar
11089 posts

Uber Geek
+1 received by user: 6069

Trusted
Lifetime subscriber

  #1791348 29-May-2017 19:46
Send private message

Bizarre. I certainly didn't post anything resembling SQL!

Geektastic
18009 posts

Uber Geek
+1 received by user: 8465

Trusted
Lifetime subscriber

  #1791350 29-May-2017 19:47
Send private message

That's all very far above my pay grade!





freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41024

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1791353 29-May-2017 19:49
Send private message

Ok, I've made a change in the rules. Let's see how it goes.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Geektastic
18009 posts

Uber Geek
+1 received by user: 8465

Trusted
Lifetime subscriber

  #1791355 29-May-2017 19:54
Send private message

Behodar: Bizarre. I certainly didn't post anything resembling SQL!

 

 

 

I don't even know what it is, so you're one up on me! surprised






 
 
 

Stream your favourite shows now on Apple TV (affiliate link).
freitasm
BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41024

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1791356 29-May-2017 19:57
Send private message

Just rest knowing we're here to protect you, citizen.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Geektastic
18009 posts

Uber Geek
+1 received by user: 8465

Trusted
Lifetime subscriber

  #1791361 29-May-2017 20:07
Send private message

freitasm:

 

Just rest knowing we're here to protect you, citizen.

 

 

 

 

Thanks. I will. 

 

 

 

Just as long as no one thinks I did whatever that was deliberately!






timmmay

20857 posts

Uber Geek
+1 received by user: 5349

Trusted
Lifetime subscriber

  #1791363 29-May-2017 20:12
Send private message

drop table users;


timmmay

20857 posts

Uber Geek
+1 received by user: 5349

Trusted
Lifetime subscriber

  #1791364 29-May-2017 20:13
Send private message

delete from posts where id > 1;


 1 | 2
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.