Mod Security

A red message that stops the whole page from loading, a full page but a message that looks like it came from the server, a red box with red text that we made: all of these are bugs you can see, so report them here. kthxbai :)

Moderator: Dracones

Forum rules
Can you copy/paste the error message, or do a screen shot that shows what is wrong? If not maybe you've got a "you can sense it" bug.

Mod Security

Postby Yabs » Mon Jul 19, 2010 2:30 pm

Been seeing this problem a tad on evo forums, just had it confirmed by leeturner as happening on hostgator.

Mod sec kills contact form ( it also kills parts of admin as well ) because of ?param=htp:// ( normally ?redirect_to ) ... pretty damn sure the same problem exists in QP as well, although not installed mod sec so I can test.

This *could* be an easy fix. Basically remove http(s):// part of redirect_to and add an extra "is_secure" param flag so we know if (s) needs adding ;)

Anyway, would be nice if we didn't have this problem when we launch ... assuming I can get past my coding block with the evo converter :(

¥
I may have opened the door but you entered of your own free will

Image Techno Babble II
Image Tacky Pad 3
Yabs
Dracone
User avatar
 
Posts: 819
Joined: Sat Nov 21, 2009 9:59 am

Re: Mod Security

Postby Tblue » Mon Jul 19, 2010 3:32 pm

On IRC, I wrote:<Tblue> Real fix is fixing mod_security...
<Tblue> But yeah, I guess we have to add yet another stupid workaround for broken setups
Tblue
Dracone
User avatar
 
Posts: 289
Joined: Sat Nov 21, 2009 1:35 pm
Location: Berlin, Germany

Re: Mod Security

Postby Yabs » Mon Jul 19, 2010 3:37 pm

irc_continued wrote:<Tblue> Real fix is fixing mod_security...
<Tblue> But yeah, I guess we have to add yet another stupid workaround for broken setups
<yabs> I look forward to the day that we can rely on every server in the world running the fixes that you submit to mod_sec() ... until then we treat it a smidge like ie6 ;)


¥
I may have opened the door but you entered of your own free will

Image Techno Babble II
Image Tacky Pad 3
Yabs
Dracone
User avatar
 
Posts: 819
Joined: Sat Nov 21, 2009 9:59 am

Re: Mod Security

Postby EdB » Mon Jul 19, 2010 8:57 pm

Could we make up a param for what the leading bits should be? Like ?redirect_to=domain.tld/post_title&lb=foo where we then have a little legend of what the various lb bits might be? Or even drop the first three letters and use them as the lb part? As in htt or ftp? For a legend type of thing all I can think of is http:// and https:// and ftp:// but there are probably more. Might have to do the www. versions as well?
EdB
Dracone
User avatar
 
Posts: 1467
Joined: Sun Nov 22, 2009 7:20 am
Location: Maricopa Arizona

Re: Mod Security

Postby Yabs » Tue Jul 20, 2010 4:37 am

redirect_to should only ever be http:// or https:// so a flag for "add_s" should be enough, the rest of the url can be in redirect_to. I'm pretty sure that there's a few other admin areas/actions that spark of mod sec as well, but can't think of any off hand.

I'm not sure how easy/hard it'd be to implement the fix, but it'd be nice if we could for v0 although I wouldn't consider it a deal killer if it had to wait until v1 ;)

¥
I may have opened the door but you entered of your own free will

Image Techno Babble II
Image Tacky Pad 3
Yabs
Dracone
User avatar
 
Posts: 819
Joined: Sat Nov 21, 2009 9:59 am


Return to You can see the bug

Who is online

Users browsing this forum: No registered users and 1 guest