Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
NC Software Offline
Member
 
NC Software's Avatar
 
Posts: 512
Join Date: Dec 2005
Location: Sitting
Exclamation Hover ticket preview a potential security threat - 27-07-2007, 12:17 PM

When viewing the ticket list you can hover your mouse over the yellow ticket icon to preview the message. This hover preview is actually HTML and if your ticket content is HTML, it has the full capabilities of such. I had an issue the other day where a spam message had come in and in the process of moving the mouse to the checkbox to delete the message, the hover preview appeared and triggered a HTML new window to open the site the message was triggered to perform. I was confused at first as to what happened, how did this IE window get opened, then I realized someone carefully crafted this message such that when it's viewed in HTML it triggers as action!

You may want to rethink that yellow preview system to NOT be HTML as tickets themselves are NOT HTML, or at least that's the way it's set in my SS 3.10.02. Maybe this is a bug that the preview popup is not stripping HTML like tickets do?

Again, potential security threat in the ticket preview popup!


Neal Culiner
NC Software, Inc.
Visual Basic .NET Forums
3.30.02 STABLE
   
Reply With Quote
  (#2) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,120
Join Date: Jan 2006
Location: United Kingdom
27-07-2007, 12:33 PM

Hi Neal,

Have you got "Convert HTML" to the respective entities enabled, or have you selected no processing of HTML (under Ticket options in the admincp)? Please let me know what level of HTML processing you have selected for this option.

Thanks,


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
  (#3) Old
NC Software Offline
Member
 
NC Software's Avatar
 
Posts: 512
Join Date: Dec 2005
Location: Sitting
27-07-2007, 12:49 PM

Jamie,

Tell me EXACTLY where in the AdminCP and what setting you want me to check INSTEAD OF sending me on a wild goose chase without YOU referencing the admincp first. I don't see the setting you allude to in your post, so tell me what you want.

Do NOT tell me again OR PM ME again to post in the correct forum. This is a usability design flaw on your part. I am the customer, I do the best I can to post in the best forum based on what I read on your forum home page listing. I see a forum title "Comments, Questions, and Feedback" so that's where I posted this. If you want to move it, that's up to you, but do NOT counsel me again regarding posting in the wrong place! Understood?


Neal Culiner
NC Software, Inc.
Visual Basic .NET Forums
3.30.02 STABLE
   
Reply With Quote
  (#4) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,120
Join Date: Jan 2006
Location: United Kingdom
27-07-2007, 02:36 PM

It is found in the admincp under Settings -> Tickets you will see the option:

http://jamie.kayako.org/screenshots/...2627030759.png
http://jamie.kayako.org/screenshots/...2727030737.png

What do you have it set to?

===

With regards to me asking you to post in the correct forum - for the benefit of readers, this was not done in a rude way and was a request simply to look at the forum descriptions as guidance on where to post thing.

I have to move very few posts as a result of people posting in the incorrect place.

If you are not happy about the forum rules or my (or any other forum moderator) contacting you about forum related matters, then please do not use the forum. The community forum (as stated clearly - almost everywhere) is not a guaranteed support medium. The community here is largely made up of people happy to spare some time to help others users. If you wish to receive direct and dedicated support, please contact the support department.

Thanks,


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
  (#5) Old
NC Software Offline
Member
 
NC Software's Avatar
 
Posts: 512
Join Date: Dec 2005
Location: Sitting
27-07-2007, 02:50 PM

It is set to strip tags. However, my post is saying I don't think this is applying to the ticket preview as the ticket preview (mouse hover) shows full HTML.


Neal Culiner
NC Software, Inc.
Visual Basic .NET Forums
3.30.02 STABLE
   
Reply With Quote
  (#6) Old
craigbrass Offline
Senior Member
 
Posts: 5,391
Join Date: Jun 2005
Location: Cumbria, UK
27-07-2007, 02:56 PM

Can I just comment here.

Neal: Was there really such a need to be rude to Jamie? He was only trying to help you as all the people who are active on this forum do...


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger
   
Reply With Quote
  (#7) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,120
Join Date: Jan 2006
Location: United Kingdom
27-07-2007, 03:09 PM

Quote:
Originally Posted by NC Software View Post
It is set to strip tags. However, my post is saying I don't think this is applying to the ticket preview as the ticket preview (mouse hover) shows full HTML.
Hi Neal,

Can you send (in a PM) to me (wrapped in [.code] tags) the contents of the post that is causing this issue so I can do testing?

Also, was the post submitted by e-mail or by form?


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
  (#8) Old
eiden Offline
Member
 
Posts: 237
Join Date: Apr 2006
Location: Norway
27-07-2007, 04:08 PM

Quote:
Originally Posted by craigbrass View Post
Can I just comment here.

Neal: Was there really such a need to be rude to Jamie? He was only trying to help you as all the people who are active on this forum do...
I agree. No need to be rude.

Guess that some people suffer from A.H.S...
   
Reply With Quote
  (#9) Old
craigbrass Offline
Senior Member
 
Posts: 5,391
Join Date: Jun 2005
Location: Cumbria, UK
27-07-2007, 06:06 PM

Well I just get annoyed that people get annoyed at people who are just trying to help on this forum at times when there is no need to.


Craig Brass - Kayako Forum Squatter (Note: I am NOT a staff member)

Icon Headquarters - Its Elixir - Web2Messenger
   
Reply With Quote
  (#10) Old
NC Software Offline
Member
 
NC Software's Avatar
 
Posts: 512
Join Date: Dec 2005
Location: Sitting
27-07-2007, 08:18 PM

Jamie,

I don't have the e-mail, naturally I deleted it as it appeared to be a potential for a thread if just previewing it was causing IE windows to open. You should be able to see the issue clearly by sending yourself a HTML e-mail with images. You'll see that when you hover the mouse over the ticket icon you'll get a full HTML preview with images. I've seen that quite a bit, I don't think that's intended, the preview info should have its tags stripped as well, you may want to log this as a bug.


Neal Culiner
NC Software, Inc.
Visual Basic .NET Forums
3.30.02 STABLE
   
Reply With Quote
  (#11) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,120
Join Date: Jan 2006
Location: United Kingdom
27-07-2007, 08:22 PM

As you have confirmed it was sent via e-mail (in which case tags should be stripped), logged as a bug.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
  (#12) Old
tony300 Offline
New Member
 
Posts: 4
Join Date: Sep 2007
26-09-2007, 12:36 AM

Jamie, this bug has been flagged as "Not a bug / Deferred" http://bugs.kayako.com/index.php?cmd=view&id=212

The admin interface warns that allowing HTML is "not recommended as it can allow malicious code to be executed in staff users web browsers." Can you please find out why this is not considered important enough to fix? It seems to me that this should be a high priority bug.
   
Reply With Quote
  (#13) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,120
Join Date: Jan 2006
Location: United Kingdom
26-09-2007, 08:49 AM

Hi Tony,

It was changed to this status as we were unable to replicate it in 3.11.01. However, if you believe the problem still persists then let me know and I shall reopen the bug for further investigation.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
  (#14) Old
tony300 Offline
New Member
 
Posts: 4
Join Date: Sep 2007
26-09-2007, 08:59 AM

It definitely does happen on 3.11.01, but I have only seen it a few times. I'll let you know when I get another one. Thanks.
   
Reply With Quote
  (#15) Old
Jamie Edwards Online
Operations Manager
 
Jamie Edwards's Avatar
 
Posts: 5,120
Join Date: Jan 2006
Location: United Kingdom
26-09-2007, 09:02 AM

Hi Tony,

It would also help if you could detail your settings for things such as tag stripping and whether or not the ticket was submitted via e-mail or via the form on your support centre.


Jamie Edwards (jamie.edwards ]at[ kayako.com)
----------------------------------------------------------------
---
  • New to the forum? New user's guide here.
  • Submit bug reports here.
  • Submit support tickets via the members area.
  • Submit sales queries either via live chat or via e-mail.
  • There is no official ETA on Version 4.
   
Reply With Quote
Reply

Tags
hover, potential, preview, threat, ticket

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Ticket locking reply preview improvement jon Duplicate Requests 0 03-07-2007 03:32 PM
Tickets Ticket list -> UI -> Better placement of preview hover Southerncentralrain Feature Requests 0 26-05-2007 01:20 PM
New Build: 3.10.02 STABLE Ryan Lederman News and Announcements 0 05-03-2007 09:53 PM



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46