<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en" xmlns="http://www.w3.org/2005/Atom"><title>Recent changes to bugs</title><link href="https://sourceforge.net/p/secureideas/bugs/" rel="alternate"/><link href="https://sourceforge.net/p/secureideas/bugs/feed.atom" rel="self"/><id>https://sourceforge.net/p/secureideas/bugs/</id><updated>2013-05-03T19:23:27Z</updated><subtitle>Recent changes to bugs</subtitle><entry><title>Issue BASE autentication with Oracle 11g</title><link href="https://sourceforge.net/p/secureideas/bugs/247/" rel="alternate"/><published>2013-05-03T19:23:27Z</published><updated>2013-05-03T19:23:27Z</updated><author><name>Paulo Matos</name><uri>https://sourceforge.net/u/pauloeduardodf/</uri></author><id>https://sourceforge.net0d93fa73c6281e76c3d048b9083bcf7fee6d83b7</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;First I want congrat you for your excepcional work with BASE.&lt;br /&gt;
Second I am deploying Base with Oracle 11g and I am with issue in autentication.&lt;br /&gt;
All function works fine, but autentication don´t work.&lt;br /&gt;
Base can create the user and password but when I enable autentication don´t work.&lt;br /&gt;
Application returns as "user don´t exist or password was wrong".&lt;br /&gt;
If you could help me, I will stay very thankful.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Issue BASE autentication with Oracle</title><link href="https://sourceforge.net/p/secureideas/bugs/246/" rel="alternate"/><published>2013-05-03T15:55:29Z</published><updated>2013-05-03T15:55:29Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net159a36c3eef3d8c25f323f3c58b66df8afe54e0a</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;First I want congrat you for your excepcional work with BASE.&lt;br /&gt;
Second I am deploying  Base with Oracle 11g and I am with issue in autentication.&lt;br /&gt;
All function works fine, but autentication don´t work.&lt;br /&gt;
Base can create the user and password but when I enable autentication don´t work.&lt;br /&gt;
Application returns as "user don´t exist or password was wrong".&lt;br /&gt;
If you could help me, I will stay very thankful.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>PHP Remote Inclusion Vulnerability</title><link href="https://sourceforge.net/p/secureideas/bugs/245/" rel="alternate"/><published>2013-04-26T17:10:18Z</published><updated>2013-04-26T17:10:18Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net3af4ca8a0bf44ed534a312e362562a4aff01a341</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;we ran some tests on one of our installations and found an remote inclusion vulnerability as already published on:&lt;br /&gt;
&lt;a href="http://xforce.iss.net/xforce/xfdb/73200" rel="nofollow"&gt;http://xforce.iss.net/xforce/xfdb/73200&lt;/a&gt;&lt;br /&gt;
and&lt;br /&gt;
&lt;a href="http://packetstormsecurity.com/files/109663/BASE-1.4.5-Remote-File-Inclusion-Shell-Creation.html" rel="nofollow"&gt;http://packetstormsecurity.com/files/109663/BASE-1.4.5-Remote-File-Inclusion-Shell-Creation.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Do you plan on fixing these issues?&lt;/p&gt;
&lt;p&gt;Kind regards.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>2995737 patch</title><link href="https://sourceforge.net/p/secureideas/bugs/244/" rel="alternate"/><published>2011-03-25T16:03:07Z</published><updated>2011-03-25T16:03:07Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net33f21041484d4dfdce0694ecf09af96d32f5e532</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Fix Sensor.name sort in base_sensor_stat.php&lt;/p&gt;
&lt;p&gt;Props to abenson&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>error in DB connection settings</title><link href="https://sourceforge.net/p/secureideas/bugs/243/" rel="alternate"/><published>2011-03-09T13:06:47Z</published><updated>2011-03-09T13:06:47Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net2eed2751cce4a4afeb5c6d69749c175f3f5822a0</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;BASE doesn't show any data until in base_conf.php will be set $alert_host='0.0.0.0' and $archive_host='localhost'. In other variations of this parameters (both set to localhost, or to 0.0.0.0) BASE didn't work.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Bug in Base 1.4.5</title><link href="https://sourceforge.net/p/secureideas/bugs/242/" rel="alternate"/><published>2010-09-24T22:51:31Z</published><updated>2010-09-24T22:51:31Z</updated><author><name>Gilbert Standen</name><uri>https://sourceforge.net/u/gilstanden/</uri></author><id>https://sourceforge.net0368d0e47a092db595f2860ab213a24b7e99c462</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Hi not sure if this is the way to submit a bug.  I am using BASE and ADODB with Oracle as a backend DB.  When I tried to use Base 1.4.5 I found that the lower part of the main BASE page (base_main.php) threw an Oracle error for the lower part of the screen (which remains blank).  The error was "Database ERROR: Database ERROR: ORA-00907 missing parenthesis".  When I ripped out Base 1.4.5 and went back to 1.4.3 the error was not occurring.  Thanks.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>XSS</title><link href="https://sourceforge.net/p/secureideas/bugs/241/" rel="alternate"/><published>2010-08-11T07:24:07Z</published><updated>2010-08-11T07:24:07Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net909221d985756938c23752d2cfad36175c693381</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Base has a XSS bug in search field.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Sagan SID's show up as Emerging Thread SIDS.</title><link href="https://sourceforge.net/p/secureideas/bugs/240/" rel="alternate"/><published>2010-07-22T14:40:38Z</published><updated>2010-07-22T14:40:38Z</updated><author><name>Da Beave</name><uri>https://sourceforge.net/u/dabeave/</uri></author><id>https://sourceforge.net125247ef988783629bacadcb9fc31a7fe2921bd3</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Sagan is a real time log analysis tool that can store and correlate IDS/IPS information with log information.  For more information,  please see &lt;a href="http://sagan.softwink.com." rel="nofollow"&gt;http://sagan.softwink.com.&lt;/a&gt;   Sagan uses the Snort MySQL and PostgreSQL to store events and for correlation.  When Sagan stores events,  reference URLs show Sagan alerts as "EmThreat",  which is incorrect.   Sagan rule set SID's start at 500000.  It's likely that BASE simply considers EmThreat rules any thing over 200000 (?).   There's a screen shot of this issue at: &lt;a href="http://sagan.softwink.com/screenshots.html" rel="nofollow"&gt;http://sagan.softwink.com/screenshots.html&lt;/a&gt; (about middle of the page).   Let me know if you need any more information.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Sorting order</title><link href="https://sourceforge.net/p/secureideas/bugs/239/" rel="alternate"/><published>2010-05-03T06:09:46Z</published><updated>2010-05-03T06:09:46Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.net02642bcdbd9be198a80890a9665625964c3aa9c4</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;base 1.4.5&lt;/p&gt;
&lt;p&gt;base_stat_sensor.php:                         " ORDER BY sensor.name ASC",&lt;br /&gt;
base_stat_sensor.php:                         " ORDER BY sensor.name DESC");&lt;/p&gt;
&lt;p&gt;Unknown column 'sensor.name' in 'order clause'&lt;/p&gt;
&lt;p&gt;$qro-&amp;gt;AddTitle(_SIPLTOTALEVENTS,&lt;br /&gt;
"occur_a", " ",&lt;br /&gt;
" ORDER BY event_cnt ASC",&lt;br /&gt;
"occur_d", " ",&lt;br /&gt;
" ORDER BY event_cnt DESC"); &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;"missing" -&amp;gt; " ORDER BY event_cnt ASC", and  " ORDER BY event_cnt DESC");&lt;/p&gt;
&lt;p&gt;Order by unique event not work correctly&lt;br /&gt;
$qro-&amp;gt;AddTitle(_SIPLUNIEVENTS,&lt;br /&gt;
"occur_a", "", " ORDER BY sig_cnt ASC",&lt;br /&gt;
"occur_d", "", " ORDER BY sig_cnt DESC");&lt;/p&gt;
&lt;p&gt;$sql = "SELECT DISTINCT acid_event.sid, count(acid_event.cid) as event_cnt,".&lt;br /&gt;
" count(distinct(acid_event.signature)) as sig_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_src)) as saddr_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_dst)) as daddr_cnt, ".&lt;br /&gt;
"min(timestamp) as first_timestamp, max(timestamp) as last_timestamp".&lt;br /&gt;
$sort_sql[0].$from.$where." GROUP BY acid_event.sid ".$sort_sql[1];&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>Sorting order</title><link href="https://sourceforge.net/p/secureideas/bugs/238/" rel="alternate"/><published>2010-05-03T04:32:13Z</published><updated>2010-05-03T04:32:13Z</updated><author><name>Anonymous</name><uri>https://sourceforge.net/u/userid-None/</uri></author><id>https://sourceforge.netd857ecdfcdcbbbdfe20804ecd612b27742071cf2</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;base 1.4.5&lt;/p&gt;
&lt;p&gt;base_stat_sensor.php:                         " ORDER BY sensor.name ASC",&lt;br /&gt;
base_stat_sensor.php:                         " ORDER BY sensor.name DESC");&lt;/p&gt;
&lt;p&gt;Unknown column 'sensor.name' in 'order clause'&lt;/p&gt;
&lt;p&gt;$qro-&amp;gt;AddTitle(_SIPLTOTALEVENTS,&lt;br /&gt;
"occur_a", " ",&lt;br /&gt;
" ORDER BY event_cnt ASC",&lt;br /&gt;
"occur_d", " ",&lt;br /&gt;
" ORDER BY event_cnt DESC"); &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;"missing" -&amp;gt; " ORDER BY event_cnt ASC", and  " ORDER BY event_cnt DESC");&lt;/p&gt;
&lt;p&gt;Order by unique event not work correctly&lt;br /&gt;
$qro-&amp;gt;AddTitle(_SIPLUNIEVENTS,&lt;br /&gt;
"occur_a", "", " ORDER BY sig_cnt ASC",&lt;br /&gt;
"occur_d", "", " ORDER BY sig_cnt DESC");&lt;/p&gt;
&lt;p&gt;$sql = "SELECT DISTINCT acid_event.sid, count(acid_event.cid) as event_cnt,".&lt;br /&gt;
" count(distinct(acid_event.signature)) as sig_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_src)) as saddr_cnt, ".&lt;br /&gt;
" count(distinct(acid_event.ip_dst)) as daddr_cnt, ".&lt;br /&gt;
"min(timestamp) as first_timestamp, max(timestamp) as last_timestamp".&lt;br /&gt;
$sort_sql[0].$from.$where." GROUP BY acid_event.sid ".$sort_sql[1];&lt;/p&gt;&lt;/div&gt;</summary></entry></feed>