Post by procheck » Sat Oct 19, 2024 9:54 am

Hi,
My firewall log blocked the following:
GET /index.php - Leading quote - [GET:route = %27]

Does anyone know what this does?

Thanks

New member

Posts

Joined
Tue Jul 23, 2013 9:42 am

Post by Cue4cheap » Sat Oct 19, 2024 11:32 pm

Not really an Opencart thing but since you asked. %27 is URL encoded single quote '
Some scammers / hacks will try and pass a quote, single or double, with sql injection or other things, trying to get into your cart backend or just mess up your site "for fun". Your firewall also should have provided where they were trying this and at least part of the code they were trying to send.
Mike

cue4cheap not cheap quality


Expert Member

Posts

Joined
Fri Sep 20, 2013 4:45 am

Post by procheck » Sun Oct 20, 2024 9:04 pm

I understand it's not directly related to Opencart but I didn't know if they were trying to hack something specific to Opencart.
Thanks for your reply.

New member

Posts

Joined
Tue Jul 23, 2013 9:42 am

Post by khnaz35 » Mon Oct 21, 2024 9:46 pm

Recommended Actions:
Review Logs: Check your web server logs for similar patterns and other blocked attempts. This could indicate an ongoing reconnaissance or attack.
Sanitize Inputs: Ensure that your web application is sanitizing and validating inputs properly to prevent injection vulnerabilities.
Update Software: Make sure your web server and any web applications are up to date with the latest security patches.
Firewall Rules: Verify that your firewall rules are correctly set up to block suspicious activity like this.

Got an urgent question that’s keeping you up at night? There might just be a magical inbox ready to help: khnaz35@gmail.com
Enjoy nature ;) :) :-*


User avatar
Active Member
Online

Posts

Joined
Mon Aug 27, 2018 11:30 pm
Location - Malaysia
Who is online

Users browsing this forum: Semrush [Bot] and 9 guests