Zen Cart Logo
Forums / Upgrading to 1.5.x / Edit DEMO EZpage ID=14 causes server 403 error

Edit DEMO EZpage ID=14 causes server 403 error

Views: 2,827

Results 1 to 15 of 15
29 Jun 2016, 4:07 PM
#1
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Edit DEMO EZpage ID=14 causes server 403 error

Attempting to edit the Demo EZ page ID=14 causes a 403 error. I haven't found any other EZ page that causes a similar reaction.

Host is looking into server logs but first indication is that it is triggering a

mod_security rule but has not offered any other specifics yet.

Vanilla v155a install
Bugfixes applied
Demo data
No plugins or templates installed
php 5.5.32
mySQL 5.5.5-10.1.14-MariaDB
Server OS: Linux 3.10.0-327.10.1.el7.x86_64

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

29 Jun 2016, 4:36 PM
#2
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

I'm guessing that something in the demo EZ page data should be edited/corrected.

Mod_security rule

The description says "SQLmap attack detected"

Request: POST
/index.php?main_page=tell_a_friend&products_id=180&action=process

Action Description: Access denied with code 403 (phase 2).

Justification: Test
'ARGS|ARGS_NAMES|REQUEST_COOKIES|REQUEST_COOKIES_NAMES|XML:/|!ARGS:/body/|!ARGS:/content/|!ARGS:/description/|!ARGS:/message/|!ARGS:Post|!ARGS:desc|!ARGS:text|!ARGS:text_message|!REQUEST_COOKIES:/__utm/|!REQUEST_COOKIES:/pk_ref/|!ARGS:sql_query'
against '@rx
[[]"',().]{10}$|(?:union\s+all\s+select\s+(?:(?:null|\d+),?)+|order\s+by\s+\d{1,4}|(?:and|or)\s+\d{4}=\d{4}|waitfor\s+delay\s+'\d+:\d+:\d+'|(?:select|and|or)\s+(?:(?:pg
)?sleep(\d+)|\d+\s
=\s*(?:dbms_pipe.receive_message((?:chr(\d+)(?:\s*||\s*)?),\d+)|(select\s+\d+\s+from\s+pg_sleep(\d+)))))(?:\s(?:and|or)\s+(?(?:(\d{4})=\1|'(\w{4})'='\2|'%'=')|--\s*\w*|#)$|(select\s*(case\s+when\s*(\d+\s*=\s*\d+)\s+then\s+\d+\s+else\s+(?:0x[\0-9a-h]+|\d+)\s+end))|(?:(?:and|or)\s+(?'?(?:\w{1,4}|%)'?)?(?:=|<|>)(?'?\w{0,4}'?)?|order\s+by\s+\d+)(?:#|--\s*\w{0,4})?$'
is true.

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

29 Jun 2016, 7:10 PM
#3
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

Here is the public page
http://srevaewniahc(DOT).info/155a/index.php?main_page=page&id=14&chapter=10

I did notice that there is reference to 403 Forbidden in the viewsource screen but I don't think that would be from the server mod_security

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

29 Jun 2016, 7:13 PM
#4
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,843
Plugin Contributions:
17

Re: Edit DEMO EZpage ID=14 causes server 403 error

so... No CKEditor?
Can you provide the text you were going to change to?
As I said in the other post, simple editing did not throw an error for me BUT I have CKEditor installed.

Need a hand with Zen Cart? Hire the team at myZenCartZone.com for upgrades, repairs, and custom plugins.
Zen Cart Certified hosting at myZenCartHost.com

29 Jun 2016, 7:25 PM
#5
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

Nope. Just out of the box, vanilla, nothing added yet except the only known issues that are resolved in the bugfixes (according to DrByte).

No logfiles in the logs folder either

Host claims that they have temporarily disabled the mod_security rule that the page was triggering.

I just added random text to the title in an attempt to make it long enough to need to wrap.
I also just added random text to the end of the source.

Also, just opening the EZ page for editing and saving without touching a key causes the 403 forbidden

Either way, the next page presented after clicking Update is a blank white page with

 
**403**

Forbidden

Access to this resource on the server is denied!

Proudly powered by
LiteSpeed Web Server

Please be advised that LiteSpeed Technologies Inc. is not a web hosting company and, as such, has no control over content found on this site.


Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

29 Jun 2016, 7:29 PM
#6
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,843
Plugin Contributions:
17
29 Jun 2016, 7:36 PM
#7
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

I will ask but something on that one page is not playing nice because I have not found any other EZ page that has the issue.

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

29 Jun 2016, 8:14 PM
#8
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

Not the prettiest but removing this block of code from that Demo EZ page clears the 403 error.

Parts of this block of code are hidden from display on the EZ page.

Link Placement</span><br /><br /></span>While you have the option of adding Additional Links to the Header, Footer and Sidebox with EZ-Pages, you are not limited to these three Link locations. Links can be in one or more locations simply by enabling the Order for the Location(s) where the Link should appear..<br /><br />The Link Location Status for the Header, Footer and Sidebox is controlled simply by setting these to Yes or No for each setting. Then, set the Order in which the Link should appear for each location.<br /><br />This means that if you were to set Header to Yes 30 and Sidebox to Yes 50 then the link would appear in both the Header and Sidebox in the Order of your Links.<br /><br />The Order numbering method is up to you. Numbering using 10, 20, 30, etc. will allow you to sort the Links and add additional Links later.<br /><br />Note: a 0 value for the Order will disable the Link from displaying.<br /><br /><span style="font-weight: bold;"><span style="color: rgb(255, 0, 0);">Open in New Window and Secure Pages</span><br /></span><br />With EZ-Pages, each Link can take you to the same, main window for your shop; or, you can have the Link open a brand new New Window. In addition, there is an option for making the Link open as a Secure Page or a Non-Secure Page.<br /><br /><span style="font-weight: bold; color: rgb(255, 0, 0);">Chapter and TOC</span><br style="font-weight: bold; color: rgb(255, 0, 0);" /><br />The Chapter and TOC, or Table of Contents, are a unique method of building Multiple Links that interact together.<br /><br />While these Links still follow the rules of the Header, Footer and Sidebox placement, the difference is that only one of the Links, the Main Link, needs to be displayed anywhere on the site.<br /><br />If you had, for example, 5 related Links, you could add the first Link as the Main Link by setting its location to the Header, Footer or Sidebox and set its Order, as usual.<br /><br />Next, you need to assign a Chapter or Group number to the Link. This Chapter holds the related Links together.<br /><br />Then, set the TOC or Table of Contents setting. This is a secondary Sort Order for within the Chapter.<br /><br />Again, you can display any of the Links within a Chapter, as well as making any of these Links the Main Link. Whether the Links all show, or just one or more of the Links show, the Chapter is the key to grouping these Links together in the TOC or Previous/Next. <br /><br /><span style="font-weight: bold; font-style: italic;">NOTE: While all Links within a Chapter will display together, you can have the different Links display in the Header, Footer or Sidebox on their own. Or, you can have the additional Links only display when the Main Link or one of the Additional Links within the Chapter has been opened.</span><br style="font-weight: bold; font-style: italic;" /><br />The versitility of EZ-Pages will make adding new Links and Pages extreamly easy for the beginner as well as the advance user.<br /><br />NOTE: Browser-based HTML editors will sometimes add the opening and closing tags for the <html>, <head> and <body> to the file you are working on.<br /><br />These are already added to the pages via EZ-Pages.<br /><br /><span style="color: rgb(255, 0, 0); font-weight: bold;">Admin Only Display</span><br /><br />Sometimes, when working on EZ-Pages, you will want to be able to work on a Live Site and see the results of your work, but not allow the Customers to see this until you are done.<br /><br />There are 3 settings in the Configuration ... EZ-Pages Settings for the Header, Footer and Sidebox  Status:<br /><ul><li>OFF</li><li>ON</li><li>

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

29 Jun 2016, 9:29 PM
#9
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Edit DEMO EZpage ID=14 causes server 403 error

RixStix:

Host claims that they have temporarily disabled the mod_security rule that the page was triggering.
The all-important question is: WHICH rule?

I suspect they're overzealously blocking the encoded <html> or <head> tags in that content.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

29 Jun 2016, 9:43 PM
#10
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

DrByte:

The all-important question is: WHICH rule?
.

I thought what I pasted in post #2 was the rule. It is greek to me.

The easiest (for me) is to continue to remove code from the page until the 403 is no longer present.

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

30 Jun 2016, 12:10 AM
#11
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

Thank you DrByte for pointing me in the right direction.

DrByte:

The all-important question is: WHICH rule?

I suspect they're overzealously blocking the encoded <html> or <head> tags in that content.

You are correct. The culprit is the ```

<html> ```.

Not sure why all the other code appears when I use the "Reply with Quote" feature.

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

30 Jun 2016, 2:57 AM
#12
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Edit DEMO EZpage ID=14 causes server 403 error

RixStix:

I thought what I pasted in post #2 was the rule. It is greek to me.Ya, it probably is. But for the "html" tag to be treated as "SQLmop"seems odd. Nevertheless, at least it's unlikely that you'll be planning to keep all that demo text in your pages.

RixStix:

Not sure why all the other code appears when I use the "Reply with Quote" feature.
That's something on our end, which also peeks at the html and head stuff. But at least it's not throwing a 403 :)

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

30 Jun 2016, 3:25 AM
#13
rixstix avatar

rixstix

Totally Zenned

Join Date:
Aug 2009
Location:
North Idaho, USA
Posts:
2,015
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

Thanks again. You are right, the demo data will be removed when I get to the point ready to import my v154 database.

Host says the rule is disabled but no explanation of why I still receive it. It is probably best that I just drop the case before the fingerpointing or peeing contest begins.

Rick
RixStix (dot) com
aka: ChainWeavers (dot) com

8 May 2018, 11:10 PM
#14
rgilchrist avatar

rgilchrist

New Zenner

Join Date:
May 2018
Location:
Tennessee
Posts:
5
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

I am also having the 403 error.
I have 2 EZ-Pages that give me that error without changing anything and just clicking UPDATE.
Both of these pages have been fine since 1 week ago. No other changes have been made.
The server folks say, You can let them know it's triggering an Apache mod_security alert due to the "content="text/html;" in the meta tag.

I hope this doesn't turn into a finger pointing game!

8 May 2018, 11:50 PM
#15
rgilchrist avatar

rgilchrist

New Zenner

Join Date:
May 2018
Location:
Tennessee
Posts:
5
Plugin Contributions:
0

Re: Edit DEMO EZpage ID=14 causes server 403 error

In my EZ-Pages content I had <html> at the beginning and </html> at the end.
When I removed these the problem is fixed.
I no longer get the 403 error.
Why would this cause a problem?