Recent Topics

1 Jan 29, 2011 22:48    

My b2evolution Version:

Upgraded to version 4 and all seemed well.

Set up an additional blog and was going through the settings, all working fine until I made changes on the blog settings feature page.

site.org.uk/blogs/admin.php?ctrl=coll_settings&tab=features&blog=6

produces a 403 error. Nothing gets updated. It also happens on the existing blog. All other config screens are OK.

Does this page need access to a file or a resource that none of the other pages use?

It has happened so many times that the ISP locked me out. They have put in an 'allow' this address, but given they are dynamically assigned, It won't be long before I am locked out again!

2 Jan 30, 2011 23:13

It was mod_security doing the blocking, and after 3 attempt locking me out.
Anyway, the error given is below so you can see what b2evo was doing - maybe it can be patched fron the inside?;

[Sat Jan 29 23:02:48 2011] [error] [client 92.29.47.131] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (/node/add/story)" against "REQUEST_URI" required. [file "/usr/local/apache/conf/modsec_rules/10_asl_rules.conf"] [line "267"] [id "340160"] [rev "24"] [msg "Atomicorp.com - FREE UNSUPPORTED DELAYED FEED - WAF Rules: Generic SQL Injection protection"] [data "varchar"] [severity "CRITICAL"] [hostname "*********.org.uk"] [uri "/blogs/admin.php"] [unique_id "TUScmFOmqIsAAC1DUB0AAAAC"]
[Sat Jan 29 23:05:04 2011] [error] [client 92.29.47.131] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (/node/add/story)" against "REQUEST_URI" required. [file "/usr/local/apache/conf/modsec_rules/10_asl_rules.conf"] [line "267"] [id "340160"] [rev "24"] [msg "Atomicorp.com - FREE UNSUPPORTED DELAYED FEED - WAF Rules: Generic SQL Injection protection"] [data "varchar"] [severity "CRITICAL"] [hostname "************.org.uk"] [uri "/blogs/admin.php"] [unique_id "TUSdIFOmqIsAAC3gI6UAAAAE"]


Form is loading...