• Forum
  • Doc
  • Screenshots
  • Download
  • Donate
  • Contributors
  • Contact
  • Follow @phpfreechat
  • DEMO
  • Board index ‹ Version 1.x branch ‹ General Support (v1.x)
  • Change font size
  • FAQ
  • Register
  • Login

Chat messages with certain string getting dropped

Moderators: OldWolf, re*s.t.a.r.s.*2

Post a reply
8 posts • Page 1 of 1

Postby xss » Thu Feb 09, 2012 3:42 am

Hello all,

today, with a fresh install of PFC, I noticed a really strange behavior:

Almost all chat messages that somehow contain the string 'rm' at the end of a word, like in the word 'term' or 'harm', and some other text after that in the same line, get dropped. Possibly also others.

You can try it out yourself here, try with something like 'no harm done' or 'long term relationship'. ;)

This is the original index.php, nothing changed.

I can't reproduce the issue, though. I copied the whole folder as it is to another server, and there the issue does not happen (at least not with this string, didn't test for much more), and neither it happens with the demos here on this site.

What could be the problem here? It seems to be server related, but I cannot really imagine what and why...

Volunteers? :)
xss


EDIT: Added the parts in italics to make the issue clearer and reproducible...
Last edited by xss on Thu Feb 09, 2012 3:52 pm, edited 1 time in total.
xss
New member
 
Posts: 5
Joined: Thu Feb 09, 2012 3:12 am
Top

Postby re*s.t.a.r.s.*2 » Thu Feb 09, 2012 4:23 am

Hi,
went there, seems to work fine.

regards.
Free Singles Chat Rooms No Registration Required
Text and Chat Singles no need to register or app required
Sala De Bate Papo Online Grátis E Sem Cadastro
re*s.t.a.r.s.*2
Support Team
 
Posts: 612
Joined: Wed Sep 24, 2008 4:04 pm
Location: los angeles CA
  • Website
Top

Postby xss » Thu Feb 09, 2012 12:52 pm

For anyone who simply tried typing 'harm': Try 'harm done' or anything else after the 'rm'. With a quote character or another letter (as in 'harms') right after the 'rm' it seems to work. With a space not.

Thank you for trying. :)
xss
New member
 
Posts: 5
Joined: Thu Feb 09, 2012 3:12 am
Top

Postby charlesbrown678 » Thu Feb 09, 2012 1:20 pm

I have not tried yet but i think it will definitely an interesting thing :)
charlesbrown678
New member
 
Posts: 6
Joined: Tue Jan 31, 2012 12:30 pm
  • Website
Top

Postby xss » Sun Feb 12, 2012 12:25 am

So what, the issue still persists. Anyone still interested in this?

charlesbrown678 wrote:I have not tried yet but i think it will definitely an interesting thing :)

As interesting as this is, from a programmer's point of view; for chatting this is actually quite disruptive, when lines with random content get dropped...

It seems to be somewhat server related, too:
- I copied the whole PFC folder as is (downloaded from my original host, uploaded somewhere else) to two other hosts, but could not reproduce this (exact) issue on any of those other servers (haven't tested with real chatting, so it may be that other strings get dropped now...).
- But I also copied (re-uploaded) the whole folder to another directory within my web space (so, same server), that is even the root for another one of my domains, and there the '*rm *' issue appears to be the exact same.

Please, anyone with a bit of insight? A piece of advice? Any ideas? Where could I look for any hints?

xss
xss
New member
 
Posts: 5
Joined: Thu Feb 09, 2012 3:12 am
Top

Postby re*s.t.a.r.s.*2 » Sun Feb 12, 2012 2:39 am

Hi,

Xss, I have gone there again and made a test after your properly described how to duplicate the issue.
I've receiver a 403 forbidden in firebug, and I think I seen this issue before, there is something called mod_security that is currently running in some server, try to talk to your admin IT and tell him to white-list your chat url or to turn this feature off in your account...

that's as much i can tell you..

kind regards.
Free Singles Chat Rooms No Registration Required
Text and Chat Singles no need to register or app required
Sala De Bate Papo Online Grátis E Sem Cadastro
re*s.t.a.r.s.*2
Support Team
 
Posts: 612
Joined: Wed Sep 24, 2008 4:04 pm
Location: los angeles CA
  • Website
Top

Postby xss » Sun Feb 12, 2012 5:10 pm

Hello re*s.t.a.r.s.*2,

thank you for testing again and for your reply. :)

It never occurred to me to look at the firebug console. I'll look into the mod_security thing, that's at least a point to start. Though, I still don't really understand how/why a normal string of a word in a chat could cause such trouble.

Kind regards,
xss
xss
New member
 
Posts: 5
Joined: Thu Feb 09, 2012 3:12 am
Top

Postby xss » Sun Feb 12, 2012 11:31 pm

Hello,

by now I know a bit more. Indeed mod_security is somehow the cause as it checks any post in the chat for forbidden words (well, strings of words, actually) that could be used in server-side shell commands, such as „rm “, „kill “, „perl “, „links “, „php “, „echo “ and many more.

I contacted the server admin; I hope they know a way... :/

Thanks again for the hint, re*s.t.a.r.s.*2, muchas gracias, y que tengas una buena noche. :)

Kind regards/saludos,
xss
xss
New member
 
Posts: 5
Joined: Thu Feb 09, 2012 3:12 am
Top


Post a reply
8 posts • Page 1 of 1

Return to General Support (v1.x)

Who is online

Users browsing this forum: No registered users and 14 guests

  • Board index
  • The team • Delete all board cookies • All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
cron
Sign in
Wrong credentials
Sign up I forgot my password
.
jeu-gratuit.net | more partners
Fork me on GitHub