 |
Your forum announcement here! |
|
 |

04-06-2007, 20:17
|
 |
Member
|
|
Join Date: Apr 2007
Location: Bristol
Posts: 51
|
|
Apache security & phpBB Forum Hosting
After installing RC1 I've had a couple of small problems and, apparently, this is apache mod_security setup filtering all attempts to submit HTML tags.
Apparenty I should ask my host to remove the filter or reduce the strictness.
Is this something I can request in here?
Thanks
Frazer
|

04-06-2007, 20:19
|
 |
Moderator
|
|
Join Date: May 2007
Location: Newport, Wales
Posts: 855
|
|
Quote:
Originally Posted by Frazer
After installing RC1 I've had a couple of small problems and, apparently, this is apache mod_security setup filtering all attempts to submit HTML tags.
Apparenty I should ask my host to remove the filter or reduce the strictness.
Is this something I can request in here?
Thanks
Frazer
|
It's good to see your using phpBB  .
eUKHost should be able to resolve this issue for you, although if you have a shared hosting account, they might not. P.S I suggest you don't use phpBB3 RC's for a live environment
__________________
Thomas Williams
Founder of TWR Web Design
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

04-06-2007, 20:21
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
I doubt eUKhost will do this on a shared account as Thomas said as it will compromise server security. So maybe even if your not on a shared account you shouldn't do this anyway! 
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

04-06-2007, 20:29
|
 |
Moderator
|
|
Join Date: May 2007
Location: Manchester, United Kingdom
Posts: 1,325
|
|
Is there not one server which they can put shared hosting people on if they need certain security things activated? I seem to remember reading about it when there was all the problems with the new security measures.
__________________
Jonathan Crass
Joint Partner in Checker Design
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Save Jodrell Bank: To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
eUKhost Forum Moderator
|

04-06-2007, 20:34
|
 |
Moderator
|
|
Join Date: May 2007
Location: Newport, Wales
Posts: 855
|
|
Not to my knowledge. Anyway, I'm running mod_Security on my Dedicated Server and phpBB RC1 is working fine.
__________________
Thomas Williams
Founder of TWR Web Design
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

04-06-2007, 20:35
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
Quote:
Originally Posted by jc8654
Is there not one server which they can put shared hosting people on if they need certain security things activated? I seem to remember reading about it when there was all the problems with the new security measures.
|
Quote:
Originally Posted by Thomas
Not to my knowledge. Anyway, I'm running mod_Security on my Dedicated Server and phpBB RC1 is working fine.
|
jc is right. There is a server reserved for customers with unsecure code on shared plans.
You could ask for a transfer to it if that is the problem.
A brownie point for jc  .
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

04-06-2007, 22:33
|
 |
Moderator
|
|
Join Date: May 2007
Location: Manchester, United Kingdom
Posts: 1,325
|
|
Huzzzzaaaahhh for me! Lol.
__________________
Jonathan Crass
Joint Partner in Checker Design
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Save Jodrell Bank: To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
eUKhost Forum Moderator
|

04-06-2007, 22:41
|
 |
Chief Marketing Officer
|
|
Join Date: Sep 2005
Posts: 4,409
|
|
Quote:
Originally Posted by Frazer
After installing RC1 I've had a couple of small problems and, apparently, this is apache mod_security setup filtering all attempts to submit HTML tags.
Apparenty I should ask my host to remove the filter or reduce the strictness.
Is this something I can request in here?
Thanks
Frazer
|
disable mod_security from your .htaccess file. I've explained this procedure in other posts as well so take a look and see if that helps. other option would be to contact our CTO and give him necessary information to look into the rules. open ticket for him with subject "Attn : Nick J" and he will see if mod_security is blocking some genuine code.
Your feedback is the best thing that helps us to differentiate between good code and bad code.
__________________
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________
Great Opportunity :: Join our To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. for FREE and earn 20% commission on each referral.
|

05-06-2007, 13:31
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
Glad to see it is getting all sorted.
Maybe as this is such a common problem it is worth stickying a new topic with the information in about mod_security? Then people might have an automatic solution to their problem? 
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

05-06-2007, 20:45
|
 |
Chief Marketing Officer
|
|
Join Date: Sep 2005
Posts: 4,409
|
|
Quote:
Originally Posted by DPS Computing
Glad to see it is getting all sorted.
Maybe as this is such a common problem it is worth stickying a new topic with the information in about mod_security? Then people might have an automatic solution to their problem? 
|
nope. reason we have mod_security on our servers is to keep website hostings secure. If everyone starts disabling mod_security then one day we will again go through multiple website hostings injection attack. last time I managed to get their domain removed from Registry so they are quite now but we cannot underestimate them. They will come back someday to test our security settings.
__________________
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________
Great Opportunity :: Join our To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. for FREE and earn 20% commission on each referral.
|

05-06-2007, 21:05
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
Quote:
Originally Posted by eukhost.com
nope. reason we have mod_security on our servers is to keep website hostings secure. If everyone starts disabling mod_security then one day we will again go through multiple website hostings injection attack. last time I managed to get their domain removed from Registry so they are quite now but we cannot underestimate them. They will come back someday to test our security settings.
|
I suppose your right about that.
Are all accounts that disable mod_security moved to the unsecure server to keep the other servers secure then? - or does it just affect their own account or could gaining access to one unsecure account be used to attack another secure account on the same server?  .
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

05-06-2007, 21:18
|
 |
Member
|
|
Join Date: Apr 2007
Location: Bristol
Posts: 51
|
|
OK thanks for all the replies. I've done the mod_security change and it's all working, and Nick J has a new ticket with some details.
Presumably every webhost is going to get this trouble with phpBB 3? I guess this is a simplistic analysis but if so why doesn't phpBB make the necessary information available for webhosts to update their security rules?
p.s. Thomas thanks for the warning - I'm just using it to test and compare with another messageboard 
Last edited by Frazer; 05-06-2007 at 21:20.
|

05-06-2007, 21:21
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
Quote:
Originally Posted by Frazer
OK thanks for all the replies. I've done the mod_security change and it's all working, and Nick J has a new ticket with some details.
Presumably every webhost is going to get this trouble with phpBB 3? I guess this is a simplistic analysis but if so why doesn't phpBB make the necessary information available for webhosts to update their security rules?
|
eUKhost arn't upateing their security rules as doing the mod_security thing you have done makes your website hosting vulnerable - so if they did it server wide it would make everyones account on every server insecure which would not be good!
I prefer to know my account is secure!  Plus phpBB3 is only at RC (release candidate) stage isn't it? - they might iron out their security problems with the first proper release  .
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

05-06-2007, 21:30
|
 |
Member
|
|
Join Date: Apr 2007
Location: Bristol
Posts: 51
|
|
Hi David congrats on topping 1,000 posts!
I get the impression that by looking into the new code they can let phpBB's 'good code' through their mod_security's rules. Or something. Then I can switch back on mod_security in my .htaccess file.
If this interpretation is correct  then every webhost has its own mod_security rules, and all of these need to be updated.
We there's the theory anyway 
|

05-06-2007, 22:18
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
Quote:
Originally Posted by Frazer
Hi David congrats on topping 1,000 posts!
I get the impression that by looking into the new code they can let phpBB's 'good code' through their mod_security's rules. Or something. Then I can switch back on mod_security in my .htaccess file.
If this interpretation is correct then every webhost has its own mod_security rules, and all of these need to be updated.
We there's the theory anyway 
|
Thanks for the congrats!  . Much appreciated!
Maybe, I'm not sure whether it is possible to modify the security rules in that manner and keep it safe - I will have to leave it to someone from eUKhost to answer that one for you, but hopefully  .
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

06-06-2007, 22:15
|
 |
Chief Marketing Officer
|
|
Join Date: Sep 2005
Posts: 4,409
|
|
There are only 3 people with us who have expertise in mod_security so the best option to have something modified in mod_security is to open a ticket and have one of our senior person to look into it. best option would be to open it with subject "Attn :: Nick J"
__________________
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________
Great Opportunity :: Join our To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. for FREE and earn 20% commission on each referral.
|

07-06-2007, 13:14
|
 |
Premium Member
|
|
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,890
|
|
Quote:
Originally Posted by eukhost.com
There are only 3 people with us who have expertise in mod_security so the best option to have something modified in mod_security is to open a ticket and have one of our senior person to look into it. best option would be to open it with subject "Attn :: Nick J"
|
Sounds like a plan - so phpBB3 might be able to be integrated after all! 
__________________
David Smith
DPS Computing
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
NEW LAUNCH! To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
|

07-06-2007, 18:21
|
 |
Member
|
|
Join Date: Apr 2007
Location: Bristol
Posts: 51
|
|
Mark, below is the answer I got from Nick.
Re: Attn : Nick J
Hello,
We have checked and found that mod_security is off now for your website hosting. Hope that you are not facing re-direct problem now.
We have enabled mod_security, so that no one can hack the server through php script. If anyone is facing the problem, due to mod_security enabled then he has to make mod_security off.
Kindly revert to us in case of any query or problem, we will be glad to assist you.
Regards,
Jeet N,
Support Department.
|

07-06-2007, 20:00
|
 |
Chief Marketing Officer
|
|
Join Date: Sep 2005
Posts: 4,409
|
|
thats not replied by Nick. let me know the ticket number. I am not sure why Jeet touched it as it was suppose to be handled by Nick only.
__________________
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. || To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________
Great Opportunity :: Join our To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. for FREE and earn 20% commission on each referral.
|

07-06-2007, 20:32
|
|
| |