Phpbb3 Mod security BB codes problem
by Thinker
Link: http://www.modsecurity.org
Once again modsecurity does messes it up.
This time with phpbb custom codes such as these: http://www.modphpbb3.com/viewforum.php?f=17
At the moment with mod_security 2.5.9 and phpbb 3.0.5 all BB custom codes posted on that page are able to be installed (loaded).
All, execept the google video code: http://www.modphpbb3.com/viewtopic.php?f=17&t=314
This one also fails: http://www.phpbb.com/community/viewtopic.php?f=46&t=579376&start=2100
The output of this problem is shown as:
Method Not Implemented
POST to /forum/adm/index.php not supported.
Solution:
Unload your mod security to confirm that the problem is caused by it.
Do not simply reload apache; restart it.
The configuration file here modsecurity regex rule is:
/etc/apache2/modules.d/mod_security/40_generic_attacks.conf
40_generic_attacks.conf
Rule ID: "950006"
Regex:
ModSecurity: Access denied with code 501 (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}?\\+.{0,3}x))|[\\;\\|\\`]\\W*? ..." at ARGS:bbcode_tpl. [file "/etc/apache2/modules.d/mod_security/40_generic_attacks.conf"] [line "133"] [id "950006"] [msg "System Command Injection"] [data ";\\x22 id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "
note: there are other bb google video codes that also fail for the same reason
note: as i pubished this; mod security also blocked me again
07/11/09 03:54:38 pm,