Recent Topics

1 Oct 10, 2011 01:16    

Not sure whether this is related to the above changes which I have made or something different.

However, on accessing Blog Settings>>Features and making a change to a setting the system response with:

Forbidden
You don't have permission to access /blog/admin.php on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

The other tabs in Blog Settings work!

This has happened on three sites I use B2Evo. Any ideas...

3 Oct 10, 2011 01:15

Sorry. That I do not understand. I have been running B2Evo for some 5 years on the current settings and all has worked fine until now. Why the need to change now?

If I add the condition to .htaccess I get an Internal server error.

4 Oct 10, 2011 01:31

mod_security analyzes URL path, getand post params and then blocks suspicious requests. Params and/or URL path change with every b2evolution release.

Add this to your .htaccess

SecFilterEngine Off

5 Oct 10, 2011 01:44

Tried that and get the Internal Server error.

6 Oct 10, 2011 01:46

Then you need to talk to server support. Are you on shared hosting? Also you may find some info in error logs

7 Oct 22, 2011 23:43

I'm having this same issue. Spoke with the host and they said than can't just disable all of mod_security but they might be able to white list an individual security setting within mod_security if I could figure out which one needs to be disabled. Can you provide more information so I can have them disable the right setting?

I also get this in System Status, is this related? :

Caching
Cache directory
OK - /home/operati1/public_html/cache/
Cache folder size
9.2 KB
General caching
Disabled
An unexpected error has occurred!

If this error persists, please report it to the administrator.

Go back to home page

Additional information about this error:

Requested Blog from T_blogs without ID!

8 Oct 22, 2011 23:57

My hoster fixed the problem. Here is the text of the response I got so I would expect your hoster would be similar:

Unfortunately we cannot disable mod_security flat out as it makes it significantly easier for your website to be hacked and thus our server to be compromised. If you are experienced specific issues please provide us with the steps to replicate it on your account (along with any login details needed to replicate it if its in a backend panel) and we can narrow it down to specific rules to disable.

I provided details and once they did their bit all works well - I do have a very helpful hoster. (Notwithstanding, I did change my log-ins etc once this was fixed)

9 Oct 23, 2011 00:19

Ok, so do you know what they ended up doing to resolve the issue?

11 Oct 23, 2011 01:50

That would be greatly appreciated! I now have 2 sites being held up by this...

12 Oct 23, 2011 03:22

Ethan5150
I have separately provided details direct to you.

13 Oct 23, 2011 03:24

Can anyone post it here? If there's an issue with stock mod_security rules we need to report it to the dev team

14 Oct 24, 2011 19:48

Ok, well they fixed my issue by whitelisting the appropriate security rule. However, I'm still getting the above error in the System Status page. Bug? What's causing this? Should I be concerned?

15 Oct 24, 2011 21:16

I'm still getting the above error in the System Status page. Bug? What's causing this? Should I be concerned?

It's just a UI bug, nothing to worry about. It seems to be fixed in CVS already


Form is loading...