0
Welcome Guest! Login
0 items Join Now

ROCKETTHEME IS CLOSING ON JUNE 30, 2025. As a thank-you to our community, enjoy 50% off all themes with the promo code THANKYOU before we shut down. Read our Farewell Blog Post for more details.

I have a Gantry Issue...not sure where to post...

    • Twiggliscious's Avatar
    • Twiggliscious
    • Elite Rocketeer
    • Posts: 568
    • Thanks: 0
    • Joomla KungFu!!!

    I have a Gantry Issue...not sure where to post...

    Posted 12 years 8 months ago
    • RT,

      I originally posted my issue on the template board for my template thinking it was a template specific issue:

      Pathway: Board index ‹ Joomla Templates ‹ Momentum

      http://www.rockettheme.com/forum/index.php?f=547&t=174954&rb_v=viewtopic&p=862206#p862206

      Basically, the customer I have, who operates in all 50 states, has many+ parked domains.

      When clicking the "Home" tab, the site will redirect to a parked url name on the server...rather than the original url name:

      ex: http://www.pinnacleautoappraisers.com will redirect to http://mobileautoappraiser.com/ or one of the other many urls that are parked...

      I installed several templates and ran them with no issues...they were not using Gantry...I rolled Gantry back to an early release of G3 and the problem went away...the updated G4 problem sprang back up...

      This got me to thinking about this issue (Unvalidated Redirects and Forwards):

      securitynoir.blogspot.com/2011/03/misdirection-3.html
      First, we reviewed the code for all uses of redirects or forwards (called a transfer in .NET). Next, for each use, we identified if the target URL was included in any parameter values. In some cases it was, but there was validation in place to ensure that the value was a valid site.

      Not giving up on the idea, we spidered the site to see if it generates any redirects (HTTP response codes 300-307, typically 302). We looked at the parameters supplied prior to the redirect to see if they appear to be a target URL or a piece of such a URL. That is where we found the bug. In one case we were able to change the target and observed that the redirect would allow us to redirect to any site of our choosing.

      See, web applications frequently redirect and forward users to other pages and websites, and use untrusted data to determine the destination pages. Now, without proper validation, attackers can redirect victims to phishing or malware sites, or use forwards to access unauthorized pages.

      My thinking is always how things can be exploited...obviously for some reason unknown to me...Gantry4 is causing "just the home button" to bounce to a different url parked on the server...

      Those are my two cents...and I'd really like some definitive answer on if my thinking is right...

      My client wants to represent himself in his many markets through specific urls...I don't want to redirect his site to his main url...and it's just odd to me that the "Home" button is behaving this way...

      I'm going to roll back to Gantry3 this weekend until I get a solid answer...it's an odd behavior...only other post I've seen was from 2010:

      The answer I keep seeing is the redirect...but that's just a band-aid for something I'm seeing that is a bit deeper...just the fact that this link:

      index.php?option=com_content&view=featured

      Is allowing the site to pull information for the server that's not specifically "attached" or "nested" with the joomla install itself...is odd behavior...My server people told me it's a rockettheme issue, rockettheme said joomla...but all my joomla tests didn't repeat the issue...Gantry seems to be the culprit...

      So.....I love Rockettheme...and this is me trying to bring attention to a small item...that I feel is bigger than it looks...

      Mike - :mrgreen:

    • Mike-

      "Nobody cares who your father was, only the father you'll be." – Mandalorian saying...
  • Re: I have a Gantry Issue...not sure where to post...

    Posted 12 years 8 months ago

Time to create page: 0.052 seconds