UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Shared Hosting

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-06-2007, 20:17
Frazer's Avatar
Member
 
Join Date: Apr 2007
Location: Bristol
Posts: 51
Default Apache security & phpBB Forum Hosting

After installing RC1 I've had a couple of small problems and, apparently, this is apache mod_security setup filtering all attempts to submit HTML tags.

Apparenty I should ask my host to remove the filter or reduce the strictness.

Is this something I can request in here?

Thanks
Frazer
Reply With Quote
  #2 (permalink)  
Old 04-06-2007, 20:19
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 855
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Quote:
Originally Posted by Frazer View Post
After installing RC1 I've had a couple of small problems and, apparently, this is apache mod_security setup filtering all attempts to submit HTML tags.

Apparenty I should ask my host to remove the filter or reduce the strictness.

Is this something I can request in here?

Thanks
Frazer
It's good to see your using phpBB .

eUKHost should be able to resolve this issue for you, although if you have a shared hosting account, they might not. P.S I suggest you don't use phpBB3 RC's for a live environment
__________________
Thomas Williams
Founder of TWR Web Design

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #3 (permalink)  
Old 04-06-2007, 20:21
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

I doubt eUKhost will do this on a shared account as Thomas said as it will compromise server security. So maybe even if your not on a shared account you shouldn't do this anyway!
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #4 (permalink)  
Old 04-06-2007, 20:29
jc8654's Avatar
Moderator
 
Join Date: May 2007
Location: Manchester, United Kingdom
Posts: 1,325
Send a message via MSN to jc8654
Default

Is there not one server which they can put shared hosting people on if they need certain security things activated? I seem to remember reading about it when there was all the problems with the new security measures.
__________________
Jonathan Crass
Joint Partner in Checker Design


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


Save Jodrell Bank:
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


eUKhost Forum Moderator
Reply With Quote
  #5 (permalink)  
Old 04-06-2007, 20:34
WelshTom's Avatar
Moderator
 
Join Date: May 2007
Location: Newport, Wales
Posts: 855
Send a message via AIM to WelshTom Send a message via MSN to WelshTom Send a message via Yahoo to WelshTom
Default

Not to my knowledge. Anyway, I'm running mod_Security on my Dedicated Server and phpBB RC1 is working fine.
__________________
Thomas Williams
Founder of TWR Web Design

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #6 (permalink)  
Old 04-06-2007, 20:35
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by jc8654 View Post
Is there not one server which they can put shared hosting people on if they need certain security things activated? I seem to remember reading about it when there was all the problems with the new security measures.
Quote:
Originally Posted by Thomas View Post
Not to my knowledge. Anyway, I'm running mod_Security on my Dedicated Server and phpBB RC1 is working fine.
jc is right. There is a server reserved for customers with unsecure code on shared plans.

You could ask for a transfer to it if that is the problem.

A brownie point for jc .
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #7 (permalink)  
Old 04-06-2007, 22:33
jc8654's Avatar
Moderator
 
Join Date: May 2007
Location: Manchester, United Kingdom
Posts: 1,325
Send a message via MSN to jc8654
Default

Huzzzzaaaahhh for me! Lol.
__________________
Jonathan Crass
Joint Partner in Checker Design


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


Save Jodrell Bank:
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


eUKhost Forum Moderator
Reply With Quote
  #8 (permalink)  
Old 04-06-2007, 22:41
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,409
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by Frazer View Post
After installing RC1 I've had a couple of small problems and, apparently, this is apache mod_security setup filtering all attempts to submit HTML tags.

Apparenty I should ask my host to remove the filter or reduce the strictness.

Is this something I can request in here?

Thanks
Frazer
disable mod_security from your .htaccess file. I've explained this procedure in other posts as well so take a look and see if that helps. other option would be to contact our CTO and give him necessary information to look into the rules. open ticket for him with subject "Attn : Nick J" and he will see if mod_security is blocking some genuine code.

Your feedback is the best thing that helps us to differentiate between good code and bad code.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #9 (permalink)  
Old 05-06-2007, 13:31
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Glad to see it is getting all sorted.

Maybe as this is such a common problem it is worth stickying a new topic with the information in about mod_security? Then people might have an automatic solution to their problem?
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #10 (permalink)  
Old 05-06-2007, 20:45
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,409
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Quote:
Originally Posted by DPS Computing View Post
Glad to see it is getting all sorted.

Maybe as this is such a common problem it is worth stickying a new topic with the information in about mod_security? Then people might have an automatic solution to their problem?
nope. reason we have mod_security on our servers is to keep website hostings secure. If everyone starts disabling mod_security then one day we will again go through multiple website hostings injection attack. last time I managed to get their domain removed from Registry so they are quite now but we cannot underestimate them. They will come back someday to test our security settings.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #11 (permalink)  
Old 05-06-2007, 21:05
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by eukhost.com View Post
nope. reason we have mod_security on our servers is to keep website hostings secure. If everyone starts disabling mod_security then one day we will again go through multiple website hostings injection attack. last time I managed to get their domain removed from Registry so they are quite now but we cannot underestimate them. They will come back someday to test our security settings.
I suppose your right about that.

Are all accounts that disable mod_security moved to the unsecure server to keep the other servers secure then? - or does it just affect their own account or could gaining access to one unsecure account be used to attack another secure account on the same server? .
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #12 (permalink)  
Old 05-06-2007, 21:18
Frazer's Avatar
Member
 
Join Date: Apr 2007
Location: Bristol
Posts: 51
Default

OK thanks for all the replies. I've done the mod_security change and it's all working, and Nick J has a new ticket with some details.

Presumably every webhost is going to get this trouble with phpBB 3? I guess this is a simplistic analysis but if so why doesn't phpBB make the necessary information available for webhosts to update their security rules?

p.s. Thomas thanks for the warning - I'm just using it to test and compare with another messageboard

Last edited by Frazer; 05-06-2007 at 21:20.
Reply With Quote
  #13 (permalink)  
Old 05-06-2007, 21:21
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by Frazer View Post
OK thanks for all the replies. I've done the mod_security change and it's all working, and Nick J has a new ticket with some details.

Presumably every webhost is going to get this trouble with phpBB 3? I guess this is a simplistic analysis but if so why doesn't phpBB make the necessary information available for webhosts to update their security rules?
eUKhost arn't upateing their security rules as doing the mod_security thing you have done makes your website hosting vulnerable - so if they did it server wide it would make everyones account on every server insecure which would not be good!

I prefer to know my account is secure! Plus phpBB3 is only at RC (release candidate) stage isn't it? - they might iron out their security problems with the first proper release .
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #14 (permalink)  
Old 05-06-2007, 21:30
Frazer's Avatar
Member
 
Join Date: Apr 2007
Location: Bristol
Posts: 51
Default

Hi David congrats on topping 1,000 posts!

I get the impression that by looking into the new code they can let phpBB's 'good code' through their mod_security's rules. Or something. Then I can switch back on mod_security in my .htaccess file.

If this interpretation is correct then every webhost has its own mod_security rules, and all of these need to be updated.

We there's the theory anyway
Reply With Quote
  #15 (permalink)  
Old 05-06-2007, 22:18
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by Frazer View Post
Hi David congrats on topping 1,000 posts!

I get the impression that by looking into the new code they can let phpBB's 'good code' through their mod_security's rules. Or something. Then I can switch back on mod_security in my .htaccess file.

If this interpretation is correct then every webhost has its own mod_security rules, and all of these need to be updated.

We there's the theory anyway
Thanks for the congrats! . Much appreciated!

Maybe, I'm not sure whether it is possible to modify the security rules in that manner and keep it safe - I will have to leave it to someone from eUKhost to answer that one for you, but hopefully .
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #16 (permalink)  
Old 06-06-2007, 22:15
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,409
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

There are only 3 people with us who have expertise in mod_security so the best option to have something modified in mod_security is to open a ticket and have one of our senior person to look into it. best option would be to open it with subject "Attn :: Nick J"
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #17 (permalink)  
Old 07-06-2007, 13:14
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

Quote:
Originally Posted by eukhost.com View Post
There are only 3 people with us who have expertise in mod_security so the best option to have something modified in mod_security is to open a ticket and have one of our senior person to look into it. best option would be to open it with subject "Attn :: Nick J"
Sounds like a plan - so phpBB3 might be able to be integrated after all!
__________________
David Smith
DPS Computing

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
- New site / new polls / new stories! With many more to follow!
NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

NEW LAUNCH!
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Reply With Quote
  #18 (permalink)  
Old 07-06-2007, 18:21
Frazer's Avatar
Member
 
Join Date: Apr 2007
Location: Bristol
Posts: 51
Default

Mark, below is the answer I got from Nick.

Re: Attn : Nick J
Hello,

We have checked and found that mod_security is off now for your website hosting. Hope that you are not facing re-direct problem now.

We have enabled mod_security, so that no one can hack the server through php script. If anyone is facing the problem, due to mod_security enabled then he has to make mod_security off.

Kindly revert to us in case of any query or problem, we will be glad to assist you.


Regards,
Jeet N,
Support Department.
Reply With Quote
  #19 (permalink)  
Old 07-06-2007, 20:00
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,409
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

thats not replied by Nick. let me know the ticket number. I am not sure why Jeet touched it as it was suppose to be handled by Nick only.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
||
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
for FREE and earn 20% commission on each referral.
Reply With Quote
  #20 (permalink)  
Old 07-06-2007, 20:32
Frazer's Avatar