LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > Popular web applications > Word Press > 403 Forbidden - New post

Reply
 
Thread Tools Display Modes
  #1  
Old 09-18-2011, 02:30 PM
tininho tininho is offline
Member
 
Join Date: May 2011
Posts: 17
Default 403 Forbidden - New post

While trying to make new post with Wordpress I get the 403 Forbidden error, log shows this:

2011-09-19 00:27:09.324 NOTICE [82.181.193.116:57055-0#XXXX] mod_security rule triggered!
[Mon Sep 19 00:27:09 2011] [error] [client 82.181.193.116] ModSecurity: Access denied with code 403, [Rule: 'ARGS' '(fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->)']
[Msg: XSS attack]
2011-09-19 00:27:09.324 NOTICE [82.181.193.116:57055-0#XXXX] Content len: 1181, Request line: 'POST /wp-admin/post.php HTTP/1.1'

How can I tell the server that this is not an XSS attack?
Reply With Quote
  #2  
Old 11-26-2011, 04:14 PM
ikiji ikiji is offline
New Member
 
Join Date: Oct 2011
Posts: 7
I'm getting the same with an install of WHMCS

Using version 4.1.8
Reply With Quote
  #3  
Old 11-28-2011, 11:29 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,337
Quote:
...
[Mon Sep 19 00:27:09 2011] [error] [client 82.181.193.116] ModSecurity: Access denied with code 403, [Rule: 'ARGS' '(fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->)']
[Msg: XSS attack]
2011-09-19 00:27:09.324 NOTICE [82.181.193.116:57055-0#XXXX] Content len: 1181, Request line: 'POST /wp-admin/post.php HTTP/1.1'
...
This indicates that page (/wp-admin/post.php) that does the post contains value of "fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->" (any). You may verify by looking that source of the page (not php code itself). If that's the case, you can disable the rule.
Reply With Quote
  #4  
Old 01-24-2012, 04:44 AM
htduhoc2012 htduhoc2012 is offline
New Member
 
Join Date: Jan 2012
Posts: 1
Quote:
Originally Posted by webizen View Post
This indicates that page (/wp-admin/post.php) that does the post contains value of "fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->" (any). You may verify by looking that source of the page (not php code itself). If that's the case, you can disable the rule.
I am not still repair it. Anyone esle can have another opinion about this?
__________________
du hoc Canada
du hoc Anh
Reply With Quote
  #5  
Old 01-24-2012, 05:39 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,226
what's your lsws version ?
Reply With Quote
  #6  
Old 04-24-2012, 05:09 AM
adhp123 adhp123 is offline
New Member
 
Join Date: Apr 2012
Posts: 5
Quote:
Originally Posted by NiteWave View Post
what's your lsws version ?
it's almost the same but
Reply With Quote
  #7  
Old 05-03-2013, 03:41 AM
chaterbox chaterbox is offline
New Member
 
Join Date: May 2013
Posts: 2
Did you recover from this? If yes can you share the steps you did to overcome?
__________________
Bluebird Travel.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:30 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.