Orca Forum - Unicode Topic not allowed!

Dear Friends,

When I tried to submit Unicode topic in Orca forum its not submitting and getting an error as follow. Any idea how to solve this issue?

Impact: 12 | Tags: xss, csrf
Description: finds html breaking injections including whitespace attacks | Tags: xss, csrf | ID: 1
Description: finds attribute breaking injections including whitespace attacks | Tags: xss, csrf | ID: 2
Description: Detects obfuscated script tags and XML wrapped HTML | Tags: xss | ID: 33

REMOTE_ADDR: *.*.*.*
HTTP_X_FORWARDED_FOR:
HTTP_CLIENT_IP:
SCRIPT_FILENAME: /home/myaccount/public_html/mysite.com/modules/boonex/forum/index.php
QUERY_STRING: orca_integration=groups
REQUEST_URI: /forum/groups/
QUERY_STRING: orca_integration=groups
SCRIPT_NAME: /modules/boonex/forum/index.

php
PHP_SELF: /modules/boonex/forum/index.php

Thanks in advance......
Quote · 18 Dec 2009

Any help friends?

Quote · 18 Dec 2009

For now try going into Admin

Advanced Settings -> Other.

Increase values for ...........

Total security impact threshold to send report:

And

Total security impact threshold to send report and block aggressor:


Increase a little at a time until the problem goes away.



I think boonex is still working on those stupid filters.

https://www.deanbassett.com
Quote · 18 Dec 2009

mgmsites follow what deano said, it seems 17 is a good number to allow most legitimate users to use unicode and copy/paste text

Quote · 18 Dec 2009

Thank you Friends :-)

Quote · 18 Dec 2009

deano, AlexT,

im just wondering what these impact points actually reflect. Is there documentation on what the settings should be and what the differences are between the two levels of settings. what is the upper and lower range on these settings. one other thing i would like to inquire about is:

was this stuff even tested before you released it? because it seems to me that if you guys had tested making any of these changes that would make the site through this attack error, you would have seen that your initial impact settings were not going to work, and made adjustments so that there would not have been this influx of posts regarding the impact results.

Regards,

DosDawg

When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support
Quote · 18 Dec 2009
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.