Forum Discussion

Hoekstra_VFZ's avatar
5 years ago

Security risk? Our search bar is being tested periodically for vulnerabilities

Hi All,

Not sure if this is in the right board, however here I think most tech sevvy members will see this post here fasted.

In our Community Analytics board we see that on weekends our search functionalities on both our Communities (community.ziggo.nl and community.vodafone.nl) are being tested by some kind of robot (scan for fulnerabilities?) with search terms containing "1".

Do you guys experience the same thing on your Communities? 

If yes, is this a security risk Khoros needs to fix in your opinion?

3 Replies

  • We saw something similar in October of last year.

    16,433 searches for the letter e and a significant number of searches for the number 20. And who is Larry Freeman?

    The rest of the unusual SQL-related searches were fewer in quantity.

    I thought searches were rate-limited, but perhaps I'm wrong about that.

     
     
     

     

  • We have the same thing w/ searches containing "1" & then some code:

    These all happened within the last 30 days.

    These searches don't cause any mal effects - the code doesn't actually end up running on the site. So I wouldn't call it a security risk - but I also don't know a ton about this topic.

  • FYI, we've also raised this question to Khoros directly and have received a comforting response:

    "We can confidently confirm that the mentioned query, although looks like SQL, is actually a Khoros(Lithium) specific language - LiQL which is well protected against most of common attacks like SQL injections.

    You can share a couple of articles to anyone who would want to understand the same with below links:
    1. https://community.khoros.com/t5/Community-FAQ-s-from-Support/Is-LiQL-vulnerable-to-SQL-injection-attacks/ta-p/281334

    2. https://community.khoros.com/t5/Developer-Discussion/LiQL-injection-attacks-and-quotes-in-Rest-API-2-0/m-p/231920"