IDS False Positive

Discussion in 'General' started by Stefan Schumacher, Apr 11, 2022.

  1. Hi,
    When I open one of my two productive instances of ISPConfig with Chrome on Debian I get the following error message:
    "Possible attack detected. This action has been logged."
    and I can't login. It works with Firefox and I had a look at /usr/local/interface/temp/ids.log via ssh.
    This is the output. Obviously there is some strange Cookie in Chrome and it triggers the IDS.
    I am very reluctant to simply delete all cookies because this will force me to confirm Privacy Settings on all Websites I visit for at least two weeks. Is there a way to either a) find out the cookies name or origin and delete it manually or b) disable the IDS?

    Yours sincerely
    Stefan

    any:/index.php:GET.WE_LANGUAGE
    any:/login/index.php:GET.WE_LANGUAGE
    any:/index.php:GET.WE_LANGUAGE
    any:/login/index.php:GET.WE_LANGUAGE
    any:/login/index.php:COOKIE.logged_out_marketing_header_id
    any:/index.php:COOKIE.logged_out_marketing_header_id
    any:/index.php:COOKIE.logged_out_marketing_header_id
    any:/index.php:pOST.class_module_classLoader_resources_context_parent_pipeline_first_pattern
    any:/index.php:COOKIE.logged_out_marketing_header_id
    any:/index.php:COOKIE.logged_out_marketing_header_id
    any:/index.php:COOKIE.logged_out_marketing_header_id
    any:/index.php:COOKIE.logged_out_marketing_header_id
     
  2. ahrasis

    ahrasis Well-Known Member HowtoForge Supporter

    I'd normally simply refresh the browser or use other browser and I don't even checked the logs. ;)
     
  3. till

    till Super Moderator Staff Member ISPConfig Developer

    Sure, your web browser should provide options for that.
     

Share This Page