Can't access items, type and categories.

More
6 years 7 months ago #69562 by marc.light
ModSecurity was enabled. I disabled it and everything seems back to normal. It's a bit weird because I have other Joomla setup with FLEXIcontent with ModSecurity and I have no issues.

Please Log in or Create an account to join the conversation.

More
6 years 7 months ago - 6 years 7 months ago #69563 by ggppdk
Hello

mod_security is a set of customizable rules

are you using same rules everywhere ?

Also no need to guess
you can look at the logs to see which mod_security rule was triggered


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star...
Last edit: 6 years 7 months ago by ggppdk.

Please Log in or Create an account to join the conversation.

More
6 years 7 months ago #69564 by marc.light
I'll check that later. Thanks for your help!

Please Log in or Create an account to join the conversation.

More
6 years 7 months ago #69565 by ggppdk
In your
modsecurity.conf

you can add (change the path):

SecDebugLog /opt/modsecurity/var/log/debug.log
SecDebugLogLevel 3

www.feistyduck.com/library/modsecurity-h...ne/ch04-logging.html


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star...

Please Log in or Create an account to join the conversation.

More
6 years 6 months ago #69677 by marc.light
Here's the rule that blocks Joomla when FLEXIcontent is installed:

981257: Detects MySQL comment-/space-obfuscated injections and backtick termination
Request: GET /administrator/
Action Description: Access denied with redirection to mydomain.com/ using status 302 (phase 2).
Justification: Pattern match "(?i:(?:,.?)\da-f\"'][\"' )|(?:\Wselect.+\W ?from)|((?:select|create|rename|truncate|load|alter|delete|update|insert|desc)\s?\(\s ?space\s*?\())" at REQUEST_COOKIES:fc_columnchooser.

This is an important rule and I don't want to deactivate it. Is there anything that can be done ?

Thanks.

Please Log in or Create an account to join the conversation.

More
6 years 6 months ago #69681 by ggppdk
Hello

that is the our columns cookie being save into Joomla session (database)

maybe i will look at it some time during week


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star...

Please Log in or Create an account to join the conversation.

Moderators: vistamediajoomlacornerggppdk
Time to create page: 0.589 seconds
Save
Cookies user preferences
We use cookies to ensure you to get the best experience on our website. If you decline the use of cookies, this website may not function as expected.
Accept all
Decline all
Essential
These cookies are needed to make the website work correctly. You can not disable them.
Display
Accept
Analytics
Tools used to analyze the data to measure the effectiveness of a website and to understand how it works.
Google Analytics
Accept
Decline