Announcement

Collapse
No announcement yet.

Comment regarding recent change to thread title rules

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Comment regarding recent change to thread title rules

    I wanted to post on the actual thread, but it's locked to me...

    Re. the change to title requirements, i.e. no characters other than letters and numbers; It does make have a descriptive post title of any length difficult to make readable. I'm a big proponent of highly descriptive thread titles.

    However, I agree that safety of the forum is paramount. My only request would be is if another solution presents itself, I would prefer the ability to add punctuation in titles. Thanks for listening...

    Please Read Me

    #2
    Yes, Kubuntuforum Announcements is restricted to Administrators.

    I do understand your position, and should a better solution be presented, I'm always open to listen. That said, I believe that "the issue" should follow the "question" and not the other way round. So a Title should be the question or a statement and not the problem at hand; that can be provided in the body of the post.

    Punctuation characters and where they are placed (in a Title) are what can trigger an SQL Injection presence. Concider what happens in a Konsole when you mistype and say, hit Enter after typing a [ in error.
    Windows no longer obstructs my view.
    Using Kubuntu Linux since March 23, 2007.
    "It is a capital mistake to theorize before one has data." - Sherlock Holmes

    Comment


      #3
      Does the site use prepared sql statements?

      Comment


        #4
        Originally posted by whatthefunk View Post
        Does the site use prepared sql statements?
        Can you elaborate?
        Windows no longer obstructs my view.
        Using Kubuntu Linux since March 23, 2007.
        "It is a capital mistake to theorize before one has data." - Sherlock Holmes

        Comment


          #5
          If you use prepared sql statements and parameterize the queries, sql injection is pretty much impossible.

          https://www.owasp.org/index.php/SQL_...zed_Queries.29

          Comment


            #6
            Thank you.

            Our issue wasn't "real" SQL attacks, rather how ZB Block interpreted search queries based on Post/Thread Title content that contained non-alphanumeric characters in combination and/or position that take the form of an SQL. ZB Block protects us from SQL Injection attacks, but it can (and does) identify what it believes are SQL attacks that aren't (false positives).

            I have responded to members who were stopped by ZB Block when searching KFN, either logged in or externally via browser searches, when the Title searched for contained what ZB Block interpreted as SQL code (because of the presence of non-alphanumeric characters, both in type/combination and/or positioning). As an Administrator, I have also experienced this issue when trying to move/merge Posts/Threads, again, when their Titles were triggering ZB Block.

            There is no perfect solution. But, this solution is manageable; IMO. That members won't be able to create a Post/Thread Title that contains an error/code string isn't a deal breaker. As stated earlier, the error/code in its entirety can always be included within the body of the post. I am not aware of any incident where code cited within the body of a post has created any issue with ZB Block.

            To be clear(er), it isn't the existence of these characters in the Post/Thread Title itself; ZB Block doesn't care what is posted when a member is logged in; but what is contained in a search string. But if a search is based on a real Title, ZB Block checks the query against it's rules.

            In the case of internal management of Posts/Threads by Moderators/Administrators; merging Posts/Threads say; the underlying execution of the action is via SQL; that's how vBulletin works. So again, if Post/Thread Titles contain characters that match ZB Block SQL Injection rules, ZB Block is triggered.
            Last edited by Snowhog; Dec 23, 2016, 05:42 PM.
            Windows no longer obstructs my view.
            Using Kubuntu Linux since March 23, 2007.
            "It is a capital mistake to theorize before one has data." - Sherlock Holmes

            Comment


              #7
              Thanks for the clarification

              Comment


                #8
                I do hope I explained myself well enough.

                If this MOD results in to many complaints I can always disable it.
                Windows no longer obstructs my view.
                Using Kubuntu Linux since March 23, 2007.
                "It is a capital mistake to theorize before one has data." - Sherlock Holmes

                Comment


                  #9
                  I'd go with Joe Friday, "Just the facts, Ma'am."
                  https://en.wikipedia.org/wiki/Joe_Friday
                  (There's always more to the story, there always is,
                  http://www.snopes.com/radiotv/tv/dragnet.asp ,
                  But it's the idea that counts: Just give me the facts.)
                  An intellectual says a simple thing in a hard way. An artist says a hard thing in a simple way. Charles Bukowski

                  Comment

                  Working...
                  X