• Welcome to PHPVIBE Forums. Please log in.

[ Video Sharing CMS v4 ] ModSecurity

Started by Wnux,

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

WnuxTopic starter

after activating " ModSecurity " on the server, not those connect to site administration , here is the error message in WHCMS

CRITICAL   302   
981245: Detects basic SQL authentication bypass attempts 2/3  Plus

-------------------------
Request:   GET /
Action Description:   Access denied with redirection to http://mysite.com/ using status 302 (phase 2).
Justification:   Pattern match "(?i:(?:union\\s*?(?:all|distinct|[(!@]*?)?\\s*?[([]*?\\s*?select\\s+)|(?:\\w+\\s+like\\s+[\"'`])|(?:like\\s*?[\"'`]\\%)|(?:[\"'`]\\s*?like\\W*?[\"'`\\d])|(?:[\"'`]\\s*?(?:n?and|x?x?or|div|like|between|and|not |\\|\\||\\&\\&)\\s+[\\s\\w]+=\\s*?\\w+\\s*? ..." at REQUEST_COOKIES:...

----------------------------

SecRule REQUEST_COOKIES|!REQUEST_COOKIES:/__utm/|REQUEST_COOKIES_NAMES|ARGS_NAMES|ARGS|XML:/* "(?i:(?:union\s*?(?:all|distinct|[(!@]*?)?\s*?[([]*?\s*?select\s+)|(?:\w+\s+like\s+[\"'`])|(?:like\s*?[\"'`]\%)|(?:[\"'`]\s*?like\W*?[\"'`\d])|(?:[\"'`]\s*?(?:n?and|x?x?or|div|like|between|and|not |\|\||\&\&)\s+[\s\w]+=\s*?\w+\s*?having\s+)|(?:[\"'`]\s*?\*\s*?\w+\W+[\"'`])|(?:[\"'`]\s*?[^?\w\s=.,;)(]+\s*?[(@\"'`]*?\s*?\w+\W+\w)|(?:select\s+?[\[\]()\s\w\.,\"'`-]+from\s+)|(?:find_in_set\s*?\())" "phase:request, rev:'2', ver:'OWASP_CRS/3.0.0', maturity:'9', accuracy:'8', capture, t:none,t:urlDecodeUni, block, msg:'Detects basic SQL authentication bypass attempts 2/3', id:'981245', tag:'OWASP_CRS/WEB_ATTACK/SQL_INJECTION', logdata:'Matched Data: %{TX.0} found within %{MATCHED_VAR_NAME}: %{MATCHED_VAR}', severity:'CRITICAL', setvar:'tx.msg=%{rule.msg}', setvar:tx.sql_injection_score=+%{tx.critical_anomaly_score}, setvar:tx.anomaly_score=+%{tx.critical_anomaly_score}, setvar:'tx.%{rule.id}-OWASP_CRS/WEB_ATTACK/SQLI-%{matched_var_name}=%{tx.0}'"



Thank you
  •  

PHPVibe A.

Hi! It's clearly stated in the Requirements that PHPVibe doesn't work with modsecurity on.

WnuxTopic starter

Quote from: Alexander on
Hi! It's clearly stated in the Requirements that PHPVibe doesn't work with modsecurity on.
okay, thanks
  •  

PHPVibe A.

Quote from: Wnux on
okay, thanks

At least if you want user security on cookies, else I can tell how to cut code.
But, you need to know that it will trigger it on every link input (example share video) since modsecurity doesn't allow links in inputs.

 

Similar topics (7)

Important Announcement: PHPVibe Video Sharing CMS End of Life

Started by Marius P.


Replies: 1
Views: 46336

The problem of video viewing PHPVibe 5.0

Started by Nayn


Replies: 25
Views: 74790

embed video does not work on v5

Started by neospider69


Replies: 6
Views: 56690

when slecting to unpublish music mp3 - next page says unpublished video ?

Started by spirog


Replies: 2
Views: 5105

insite ads issue when selecting above/below video player location

Started by georgepanaitescu


Replies: 3
Views: 26734

Video that I've uploaded needs to have that value in admin to upload

Started by spirog


Replies: 4
Views: 9903

video,playlist,images, etc. (frontend) select all deselect all reselect all

Started by spirog


Replies: 3
Views: 9552