LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Load Balancer > General > lslb 1.7 update - Invalid request filter directive / [ADMIN] authentication failed

Reply
 
Thread Tools Display Modes
  #1  
Old 01-20-2010, 02:44 AM
Clockwork Clockwork is offline
Senior Member
 
Join Date: May 2009
Posts: 74
Default lslb 1.7 update - Invalid request filter directive / [ADMIN] authentication failed

after the update I receive the following errors:

Code:
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "(alert|expression|eval|url)[[:space:]]*\("
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "(&\{.+\}|(&#[[0-9a-fA-F]]|\x5cx[0-9a-fA-F]){2})"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "((javascript|vbscript):|style[[:space:]]*=)"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "(fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->)"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "document\.(body|cookie|location|write)"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS_VALUES "jsessionid|phpsessid|onReadyStateChange|xmlHttp"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "<(applet|div|embed|iframe|img|meta|object|script|textarea)"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "on(Abort|Blur|Click|DblClick|DragDrop|Error|Focus|KeyUp|KeyDown|KeyPrerss|Load|Mouse(Down|Out|Over|Up)|Move|Reset|Resize|Select|Submit|Unload)"
2010-01-20 11:36:55.596	ERROR	Invalid request filter directive: ARGS "drop[[:space:]]+(database|table|column|procedure)"
2010-01-20 11:36:55.597	ERROR	Invalid request filter directive: ARGS "delete[[:space:]]+from|create[[:space:]]+table|update.+set.+=|insert[[:space:]]+into.+values"
2010-01-20 11:36:55.597	ERROR	Invalid request filter directive: ARGS "select.+from|bulk[[:space:]]+insert|union.+select|alter[[:space:]]+table"
2010-01-20 11:36:55.597	ERROR	Invalid request filter directive: ARGS "or.+1[[:space:]]*=[[:space:]]1|or 1=1--'|'.+--"
2010-01-20 11:36:55.597	ERROR	Invalid request filter directive: ARGS "into[[:space:]]+outfile|load[[:space:]]+data|/\*.+\*/"
It's also really bad that the clusters in the real-time stats aren't being shown anymore like in the 1.6 version.

Last edited by Clockwork; 01-20-2010 at 06:46 AM..
Reply With Quote
  #2  
Old 01-20-2010, 11:28 AM
Lauren Lauren is offline
LiteSpeed Staff
 
Join Date: Jul 2003
Location: New Jersey, USA
Posts: 99
Quote:
It's also really bad that the clusters in the real-time stats aren't being shown anymore like in the 1.6 version.
for real-time stats, it is new consolidated look with similar info as before. If you click "show" button on external application, are you able to see it?
Reply With Quote
  #3  
Old 01-21-2010, 11:14 AM
Clockwork Clockwork is offline
Senior Member
 
Join Date: May 2009
Posts: 74
yes, thanks
Reply With Quote
  #4  
Old 01-21-2010, 04:54 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
The request filter error bug has been addressed with an update of 1.7 release. please try "Force reinstall" from the web console to apply the latest build.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 06:33 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.