Elxis CMS Forum

Support => Security => Topic started by: Luca on December 02, 2022, 21:48:50

Title: SEC-DEFG-0018 PHP wrapper attack
Post by: Luca on December 02, 2022, 21:48:50
Hello, everybody!

I've searched the forum but didn't found anything about this Defender attack report:
SEC-DEFG-0018
Requested URI:    /components/com_content/plugins/gallery/includes/data:image/png;base64,(...etc...)
when browsing Sample Gallery

Thank you
Gianluca

Elxis 5.3 Rev 2452
PHP 8.1.2-1ubuntu2.9
Title: Re: SEC-DEFG-0018 PHP wrapper attack
Post by: datahell on December 04, 2022, 19:44:24
It seems that you have entered the image as blob (binary) data through the editor and Elxis Defender doesn't like it :-)
For the gallery, create a folder in media/images/, upload your images there, and then go to Gallery plugin and set it to load the images from that folder.
Title: Re: SEC-DEFG-0018 PHP wrapper attack
Post by: Luca on December 04, 2022, 19:52:32
Hey! @Datahell!
Nice to hear you again!
I will try to do as per your suggestion. The fact is that the installation is the one out of the box. Noticing that error while testing...
Luca
Title: Re: SEC-DEFG-0018 PHP wrapper attack
Post by: datahell on December 04, 2022, 21:32:01
Out of the box? Are you sure?
This: /components/com_content/plugins/gallery/includes/data:image/png;base64, doesn't look out of the box. However, I don't know, I haven't seen the site. If I could see it I would be able to tell you something for sure. Follow my recommendation in my previous reply and it will be fine. It doesn't look that important.
Title: Re: SEC-DEFG-0018 PHP wrapper attack
Post by: Luca on December 05, 2022, 20:26:29
Thank you very much for your kindness
Yes. I kept everything as it was and that is the essential part of the message from Defender reporting.
Anyway, as I will go further, I will observe your directions
I could give the address but, for now and until I will be ready for the release, the access to the server is restricted to only few countries
Thank you again!!!
My best
(As always, Great Work you did! I am eager about your Team. Thank you!)