icon Get the most out of Surmunity, read our tips here! Need an interesting blog to read? You've got to read the Surpass Blog! | Welcome! Please register to access all of our features.

» Surpass Web Hosting Forums » Discussions » Coding and Programming » Apache mod_securtiy conflicts with $_POST variables?

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread
Old January 27th, 2007, 6:27 PM   #1 (permalink)
Registered User
Fresh Surpasser
 
Joined in Nov 2006
29 posts
Gave thanks: 0
Thanked 1 Time in 1 Post
Apache mod_securtiy conflicts with $_POST variables?

If you have a $_POST variable containing the word "curl", I get 403 errors.

People on my forum are trying to post on my forum with the word curl in their post, and it's 403'ing for them. I researched it and apparently its Apache's mod_security module blocking(?) the expression "curl *".

Can this be fixed through cPanel? If not, can someone at Surpass fix this?
tuffy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 27th, 2007, 6:33 PM   #2 (permalink)
Yabadabadoo
Super #1
 
Geoff's Avatar
 
Joined in Nov 2004
Lives in B.C., Canada
Hosted on Dedicated
1,013 posts
Gave thanks: 7
Thanked 28 times
lol its implemented in order to stop people from taking advantage of holes in any scripts you might be running, which would allow them access to curl, and other misc utilities/features, and so on

I personally recommend you leave it on, it only makes your site more secure, but if you really wish to turn it off, create an .htaccess file in your forums root folder with the following in it:

SecFilterEngine Off

and that should turn off mod_security for that directory.
__________________
Geoff Ellis - Surpass Dedicated Server Customer
www.adepttechs.net
Geoff is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 27th, 2007, 6:56 PM   #3 (permalink)
Registered User
Fresh Surpasser
 
Joined in Nov 2006
29 posts
Gave thanks: 0
Thanked 1 Time in 1 Post
Well I find it pretty retarded that I can't have people posting sentences like "I curl 50lb dumbells" on my bodybuilding forum

Thank you for that solution.
tuffy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 27th, 2007, 7:00 PM   #4 (permalink)
Yabadabadoo
Super #1
 
Geoff's Avatar
 
Joined in Nov 2004
Lives in B.C., Canada
Hosted on Dedicated
1,013 posts
Gave thanks: 7
Thanked 28 times
perhaps, but im sure when phpBB or whatever gets another major vulnerability and you find "Pwnd by 1337h4cker" accross your home page or forums, which might have been stopped rather easily by mod_security, youll find that pretty retarded too
__________________
Geoff Ellis - Surpass Dedicated Server Customer
www.adepttechs.net
Geoff is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 27th, 2007, 7:02 PM   #5 (permalink)
Skittles
Super #1
 
DewKnight's Avatar
 
Joined in Aug 2004
Lives in a space ship
Hosted on dedi
6,826 posts
Gave thanks: 103
Thanked 199 times
I believe that it's just a small error that needs to be fixed as far as the word curl being blocked. File a ticket with support, and they should be able to fix the problem
__________________
Mountain Dew Knight
People should not be afraid of their governments. Governments should be afraid of their people.
DewKnight is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old January 27th, 2007, 9:17 PM   #6 (permalink)
Surpass Fan
Excelling Contributor
 
cowboy's Avatar
 
Joined in Nov 2005
Lives in Colorado
Hosted on DEDI
937 posts
Gave thanks: 2
Thanked 95 times
Quote:
Originally Posted by tuffy View Post
If you have a $_POST variable containing the word "curl", I get 403 errors.

People on my forum are trying to post on my forum with the word curl in their post, and it's 403'ing for them. I researched it and apparently its Apache's mod_security module blocking(?) the expression "curl *".

Can this be fixed through cPanel? If not, can someone at Surpass fix this?
On sites which use banned words as normal conversation, write a small javascript code to activate on submit which searches for these words and appends them with a nonstandard character, like a double dagger in the second position (c‡url). Then a preg_replace statement to remove it after submission and at the same time check for patterns used with cURL commands and intercept them yourself.
__________________
Where would you be if you were at the highest court in the land (US)?
cowboy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On