Hello,
I'm getting this error messages every night at 1:00 AM:
2025-09-03 01:00:03.408 ===== TRACE ===== Logfile->purge() : Technical trace to keep current log file
2025-09-03 01:00:04.006 ** ERROR ** [V12.2.2] HACK ================================================================
2025-09-03 01:00:04.006 ** ERROR ** [V12.2.2] Try to hack detected
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] Source Code = checkDisplayMenuForUser() Reject for menu 'Admin'
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] QUERY_STRING = csrfToken=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&directAccessIndex=
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] REMOTE_ADDR = XX.XX.XX.XX
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] SCRIPT_FILENAME = /var/www/projeqtor/tool/cronRelaunch.php
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] CONNECTED USER = # -
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] Last connection =
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] Last access =
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] Disconnection =
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] === Trace Stack for last error ===
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/tool/projeqtor.php at line 1734 calling debugPrintTraceStack()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/model/Security.php at line 460 calling traceHack()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/tool/adminFunctionalities.php at line 28 calling Security:checkDisplayMenuForUser()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/tool/cronExecutionStandard.php at line 359 calling require_once()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/model/Cron.php at line 610 calling cronRunConsistencyCheck()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/model/Cron.php at line 449 calling Cron:run()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] => /var/www/projeqtor/tool/cronRelaunch.php at line 30 calling Cron:relaunch()
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] ===
2025-09-03 01:00:04.007 ** ERROR ** [V12.2.2] REQUEST_URI = /tool/cronRelaunch.php?csrfToken=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&directAccessIndex=
2025-09-03 01:00:04.524 ** ERROR ** [V12.2.2] CRON abnormally stopped
2025-09-03 01:00:04.524 ** ERROR ** [V12.2.2] === Trace Stack for last error ===
2025-09-03 01:00:04.524 ** ERROR ** [V12.2.2] => /var/www/projeqtor/model/Cron.php at line 324 calling debugPrintTraceStack()
2025-09-03 01:00:04.525 ** ERROR ** [V12.2.2] => /var/www/projeqtor/tool/cronRelaunch.php at line 28 calling Cron:abort()
2025-09-03 01:00:04.525 ** ERROR ** [V12.2.2] => calling cronAbort()
2025-09-03 01:00:04.525 ** ERROR ** [V12.2.2] ===
The "Try to hack" is a false positive. I've checked and there is no traffic between the server and the REMOTET_ADDR or any other IP address.The REMOTE_ADDR is the IP of the last disconnected user (either by automatic or manual disconnection). I'm certain this user is disconnected, their computer is off, and DHCP has not assigned the address to another device.
The problem started a long time ago (a year or so?) and I can't say which version it began on.
Any advice on where to look to solve this problem would be greatly appreciated.
Thank you in advance for your help.
Best regards,
Lionel
Hi,
This is not a false positive, it is a right positive, due to constraint you may have changed.
On configuration, user Admin is created with id #1.
This is the user we use to run the Cron.
So :
- you must not delete with id #1
- user with id #1 must have Administrator profile
- user with id #1 must have acces to screen "Administration" (this is by default given by profile Administrator)
Hi,
Thanks for your quick response.
I've checked the configuration based on your feedback. The only change I made was renaming the user from "Admin" to "Admin_XXXX" but keeping the ID #1.
The user with ID #1 was never deleted. It still has the "Administrator" profile and access to the "Administration" screen.
Since your last message, I've even changed the user's name back to "Admin", but the "Try to hack" error persists and the cron job still stops abnormally.
Thank you again for your help.
Lionel
EDIT : something I forgot to mention: the first user to log in at the start of the day is automatically logged out, even if he logged out correctly the previous day. The next login attempt is then successful.
The log out of first user is probably due to Cron restart that fails.
The cron is designed to restart automatically if it is stopped unexpectedly.
Can you please check that the admin user (id #1) has access to menu "Administration" ?
Thanks for additional info.
I added ticket for further analysis as I cannot reproduce such behavior on default config.
Hello,
I performed some additional tests: Since the detection of "Try to Hack" and the cron stop consistently occur at a fixed time (01:00), I rescheduled in the administration menu the various timings of the "Consistency Check" and "Maintenance of Data" items.It appears that both the "Try to Hack" event and the cron stop are triggered according to the schedule of the "automatic search." Furthermore, if the "automatic search" is disabled, the "Try to Hack" detection and the abnormal cron stop no longer occur.
Best regards,
Lionel
What do you mean as "automatic search"
I guess this is an already foxed issue on V12.3.3.
Try and migrate to latest stable version (we'll very soon deploye V12.4.1 as stable release)
Hi,
Version is V12.4.0 but the problem is still present when "automatic search" is enabled.
Have a good day,
Lionel
Reviewing your first post and trace loggued, it is clearly an issue with admin rights for user #1
I'll add a workaround to avoid issue when tratment is "Cronned"
Hello,
The problem has disappeared since installing version V12.4.2. Surely something to do with the fix for bug "#11114 Le cron peut s’arrêter lorsque le contrôle de cohérence est planifié"
Thank you.

