Did you restart Apache after disabling mod_security?
If you didn't then it wouldn't have updated.
Vger
Did you restart Apache after disabling mod_security?
If you didn't then it wouldn't have updated.
Vger
Yes - my version of CMC restarts Apache automatically when you change the setting.
What is your server running (versions)?
Vger
CENTOS 5.5 x86_64 standard, and the most recent version of ZenCart - it was a clean install this past fall. I was using osCommerce before that and did not experience this problem (I still prefer ZenCart, mind you - just saying).
Apache/2.2.16 (Unix)
Default PHP Version (.php files) 5
PHP 5 Handler suphp
PHP 4 Handler none
Apache suEXEC on
Last edited by aloeroot; 8 Dec 2010 at 09:38 PM. Reason: Adding apache version etc
Why are you running both SuExec and SuPHP?
You would normally run one or the other but not both, or you may run one of them and then "harden" with SuHosin.
Vger
SuEXEC is for cgi scripts, and SuPHP for php, so it does make sense to run both of them. You might be thinking of suPHPexec, which we're not using.
...and so the next question has to be:
Are you running PHP as a CGI or as an Apache module?
Vger
As an Apache module.
Just as a suggestion - why not try running PHP as a CGI, just using SuExec, and (if you still need to) disabling mod_security.
Running PHP as a CGI is far more secure than running it as an Apache module, and if you feel you need more security then you could always harden it with SuHosin. Though Suhosin did create problems with Who's Online in earlier versions of Zen Cart and you will probably have to disable session encryption in SuHosin to prevent those problems.
Other than suggesting that I really cannot see why you are having this problem if, as you say, you disabled mod_security and the problem persisted.
Vger
Hi
I am coming across the same issue i.e. get a 406 error from my IIS when my payment gateway is returning a longish URL. I believe the security settings on IIS change the MIME type so my browser says that there was an error in payment processing.
Any pointers to what are the settings I can ask my host to change in the IIS configuration?
the URL I am getting from my payment gateway is:
http://zencartroot/index.php?main_page=checkout_process&DR=$OP+dgG1+lqFQBe7E4kZcEkKEDKivrv9juvLUPmh NU2L7BzFg1aJTYfhIjEHCotqxDGsu0zXxmQgWO0UQp6kNh/kVsxEnaZ94X1YHt5r7D++ma9vcUhNiDA41LdMyIWaaWbfHRTbfxoLx0c9jCMlOWMLpBCz9UxooeJs6z5 8VRmjsN2U4oQVOqPL9bQKje/o9/n36vso6Q8ZeyQUEmj6xnekSkYKomjfmhsxMmVoXx6Q+dLWnQiOPwrgnDX2KtoPWr+GurtWTmZvj5AzcV hWO7aITspvT
Thanks!
Last edited by MartinKneeshaw; 10 Feb 2011 at 05:52 AM.
Bookmarks