Forum

Investigation Requi...
 
Notifications
Retirer tout

Investigation Required: "Hack Detected" Log Entry for Registered User

1 Posts
1 Utilisateurs
0 Reactions
734 Vu
(@chandrashekhar)
Posts: 275
Honorable Member
Début du sujet
 
[#9673]

Hi,Today, I encountered the following log entry indicating a "hack detected" event for a user who is registered in ProjeQtOr:
 

2024-12-18 10:48:28.927 ** ERROR ** [V11.4.2] [133] HACK ================================================================
2024-12-18 10:48:28.927 ** ERROR ** [V11.4.2] [133] Try to hack detected
2024-12-18 10:48:28.928 ** ERROR ** [V11.4.2] [133] Source Code = checkValidAccessForUser() Reject for Project - no access to screen 'Project'
2024-12-18 10:48:28.928 ** ERROR ** [V11.4.2] [133] QUERY_STRING = objectClass=Project&objectType=&objectClient=&budgetParent=&objectElementable=&comboDetail=true&showAllProjects=on
2024-12-18 10:48:28.929 ** ERROR ** [V11.4.2] [133] REMOTE_ADDR = 1xx.1xx.x.x
2024-12-18 10:48:28.929 ** ERROR ** [V11.4.2] [133] SCRIPT_FILENAME = C:/Apache24/htdocs/projeqtor/tool/jsonQuery.php
2024-12-18 10:48:28.929 ** ERROR ** [V11.4.2] [133] CONNECTED USER = #133 - pxxxxi.axxk@mxxxxxxxc.com
2024-12-18 10:48:28.930 ** ERROR ** [V11.4.2] [133] === Trace Stack for last error ===
2024-12-18 10:48:28.930 ** ERROR ** [V11.4.2] [133] => C:Apache24htdocsprojeqtortoolprojeqtor.php at line 1698 calling debugPrintTraceStack()
2024-12-18 10:48:28.930 ** ERROR ** [V11.4.2] [133] => C:Apache24htdocsprojeqtormodelSecurity.php at line 384 calling traceHack()
2024-12-18 10:48:28.930 ** ERROR ** [V11.4.2] [133] => C:Apache24htdocsprojeqtortooljsonQuery.php at line 45 calling Security:checkValidAccessForUser()
2024-12-18 10:48:28.931 ** ERROR ** [V11.4.2] [133] ===
2024-12-18 10:48:28.931 ** ERROR ** [V11.4.2] [133] REQUEST_URI = /projeqtor./tool/jsonQuery.php?objectClass=Project&objectType=&objectClient=&budgetParent=&objectElementable=&comboDetail=true&showAllProjects=on

Could you please investigate why this "hack detected" message is appearing for a legitimate user?

It seems the user attempted to access the 'Project' screen without the necessary permissions, which triggered the security alert.Your assistance in resolving this issue would be greatly appreciated.  


 
Posté : 18/12/2024 12:05 pm
Share:
Retour en haut