Results 1 to 10 of 10
  1. #1
    Join Date
    Jun 2004
    Posts
    130
    Plugin Contributions
    0

    Default Page Editor and Mod Security issues

    I was getting an Internal Server 500 Error when I tried to edit pages using the Define Pages Editor. I narrowed it down to not being able to use the word "From", as strange as that sounds.

    I then looked in my server logs and found it was triggering a mod_security error with the word From.

    The odd thing is, I have several clients on the machine using Zen, and this is the only one that has this problem.

    Can anyone tell me how to fix it?

    Thanks!

  2. #2
    Join Date
    Jun 2004
    Posts
    130
    Plugin Contributions
    0

    Default Re: Page Editor and Mod Security issues

    Forgot to mention that I did try the htaccess entry in the other thread to no avail.

  3. #3
    Join Date
    Jan 2004
    Posts
    66,419
    Blog Entries
    7
    Plugin Contributions
    277

    Default Re: Page Editor and Mod Security issues

    Quote Originally Posted by Scarlet View Post
    Forgot to mention that I did try the htaccess entry in the other thread to no avail.
    Which specific other thread?


    You may need to ask your hosting company whether they will even allow you to override the mod_security 'protections' for specific sections of your website.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Jun 2004
    Posts
    130
    Plugin Contributions
    0

    Default Re: Page Editor and Mod Security issues

    Hi:

    I tried the htaccess entries you posted. I wound up having to whitelist the domain, which is odd because I have about 10 other zen carts on the machine that don't have the problem and aren't whitelisted. (I am the host).

    It's working now, regardless :)

  5. #5
    Join Date
    Jan 2004
    Posts
    66,419
    Blog Entries
    7
    Plugin Contributions
    277

    Default Re: Page Editor and Mod Security issues

    Be careful whitelisting the entire domain ... because that basically removes all mod_security protection on the storefront side too ... which is where most rogue visitors first come in contact with your site.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    Jun 2004
    Posts
    130
    Plugin Contributions
    0

    Default Re: Page Editor and Mod Security issues

    I was told that the whitelist file on the server can only do the entire domain. htaccess doesn't work. Do you know of another way?

  7. #7
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: Page Editor and Mod Security issues

    There is more here than meets the eye. Mod Security Rules usually return something other than a 500 msg. as that msg. is generally used for script and .htaccess "errors".

    500 Internal Server Error
    The server encountered an unexpected condition that prevented it from fulfilling the request.

    Most common mistakes:
    - script not uploaded in ASCII
    - server permission set incorrectly
    - syntax error within the script itself
    - server missing required script module(s)


    You should check with your Hoster to see why the word "From" trips a mod_sec rule.

    As another workaround, you could try editing the define page on your computer and then uploading it. Also, which define page are you trying to edit?

  8. #8
    Join Date
    Jun 2004
    Posts
    130
    Plugin Contributions
    0

    Default Re: Page Editor and Mod Security issues

    [Tue Apr 21 18:41:05 2009] [error] [client 71.236.111.245] ModSecurity: Access
    denied with code 500 (phase 2). Pattern match
    "((select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|d escribe)[[:space:]]+[A-Z|a-z|0-9|\\*|
    |\\,]+[[:space:]]+(from|into|table|database|index|view)[[:space:]]+[A-Z|a-z|0-9|\\*|
    |\\,]|UNION SELECT.*\\'.*\\'.*,[0-9].*INTO.*FROM)" at
    REQUEST_BODY. [file "/usr/local/apache/conf/modsec2.user.conf"]
    [line "345"] [id "300013"] [rev "1"] [msg
    "Generic SQL injection protection"] [severity "CRITICAL"]
    [hostname "www.uniqueflyingobjects.com"] [uri
    "/admin/define_pages_editor.php"] [unique_id
    "Se5LgUPhjPIAAHn7UzIAAAAV"]

  9. #9
    Join Date
    Jun 2004
    Posts
    130
    Plugin Contributions
    0

    Default Re: Page Editor and Mod Security issues

    It's on any of the pages - I need the client to be able to easily edit his pages and he doesn't know how to ftp or upload - that was a big reason we migrated from Miva to Zen - easier for him to maintain.

  10. #10
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: Page Editor and Mod Security issues

    I see no reason for such a wonky mod_sec rule as they currently have but then again, it's their Server, their rules.

    Quote Originally Posted by Scarlet View Post
    I need the client to be able to easily edit his pages
    Unless your Hoster is willing to have better defined mod_sec Rules, your Client will not be able to do what you want.

 

 

Similar Threads

  1. EZ-page and Define Pages Editor
    By hara in forum General Questions
    Replies: 1
    Last Post: 14 Aug 2015, 04:48 PM
  2. define page 2 and page 3 editor: Images and changing name
    By QTPasha in forum General Questions
    Replies: 2
    Last Post: 12 Nov 2009, 12:41 PM
  3. File Editor Mod.
    By empirefi in forum Customization from the Admin
    Replies: 1
    Last Post: 28 Sep 2006, 02:56 AM
  4. Looking for copy products mod and wysiwyg product editor
    By Helvis in forum General Questions
    Replies: 0
    Last Post: 12 May 2006, 09:04 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR