HTML Logo by World Wide Web Consortium (www.w3.org). Click to learn more about our commitment to accessibility and standards.

Moving forward with Composr

ocPortal has been relaunched as Composr CMS, which is now in beta. ocPortal 9 will be superseded by Composr 10.

Head over to compo.sr for our new site, and to our migration roadmap. Existing ocPortal member accounts have been mirrored.


forbidden 404 error

Login / Search

 [ Join | More ]
 Add topic 
Posted
Rating:
#95096 (In Topic #18933)
Avatar

Well-settled

After editing side_panel blocks

After I edit (change positions of blocks in side panels)  then scoll down and click the save button I get the folling in my browser:


Forbidden

You don't have permission to access /dir/adminzone/index.php on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

This happens both when logged in as admin and user with admin permissions. Got to be simple fix... What am I doing incorrectly?

~larryg1957
Back to the top
 
Posted
Rating:
#95097
Avatar

modsecurity


Become a fan of ocPortal on Facebook or add me as a friend. Add me on on Twitter.
Was I helpful?
  • If not, please let us know how we can do better (please try and propose any bigger ideas in such a way that they are fundable and scalable).
  • If so, please let others know about ocPortal whenever you see the opportunity.
  • If my reply is too Vulcan or expressed too much in business-strategy terms, and not particularly personal, I apologise. As a company & project maintainer, time is very limited to me, so usually when I write a reply I try and make it generic advice to all readers. I'm also naturally a joined-up thinker, so I always express my thoughts in combined business and technical terms. I recognise not everyone likes that, don't let my Vulcan-thinking stop you enjoying ocPortal on fun personal projects.
  • If my response can inspire a community tutorial, that's a great way of giving back to the project as a user.
Back to the top
 
Posted
Rating:
#95098
Avatar

Well-settled

Hi Chris,
So are there any files/directories I can check permissions to see if they are trigger the modsecurity excepts?

I just found a previous post looks like a big hasle to try and resolve.

I have used the edit this page and updated my main_panel no errors.

But when editing with zone edit and then save I get the error….

~Thx. for any pointers
Back to the top
 
Posted
Rating:
#95100
Avatar

Community saint

larryg1957 said

Hi Chris,
So are there any files/directories I can check permissions to see if they are trigger the modsecurity excepts?
No. It has nothing to do with your file/directory security, its your hosts firewall.

larryg1957 said

I just found a previous post looks like a big hasle to try and resolve.
It shouldn't be a big hassle as the bulk of the hard work has already been done to identify the rules that need to be whitelisted. Just tell your host to whitelist all the rules listed Configuring mod_security - ocPortal.com .

larryg1957 said

I have used the edit this page and updated my main_panel no errors.

But when editing with zone edit and then save I get the error….
The errors are largely triggered by the content, so that's not unusual.

Do you have a Samsung Galaxy S / Galaxy S II ? If so, why not check out my ScreenFree FM Radio .
Back to the top
 
Posted
Rating:
#95104
Avatar

Well-settled

@temp1024, @chris

Thanks very much for your time….  It's all fixed(at least it save and loads without errors).  

It's really nice to have docs like you have devolped on here and to whom ever tested and found all those rules….. my hat is off to ya!!!

~larryg1957
Back to the top
 
Posted
Rating:
#95106
Avatar

Community saint

larryg1957 said

  • 1. It's all fixed(at least it save and loads without errors).
  • 2. It's really nice to have docs like you have devolped on here and to whom ever tested and found all those rules….. my hat is off to ya!!!
1. Congrats!

2. I remember the massive amount of work that was done on this by temp1024, and it was uploaded to the Community Docs for all our use. I have the distinct impression that it is not a totally 'completed work', as more 'mod_sec' rules keep jumping up to bite us in the bum!

I know I have it bookmarked, but haven't needed to use it twice. My hosts saw the light almost immediately …!!

Concur your 'kudos' to Chris and temp.

 :thumbs:

Take my advice. I'm not using it!

View my working ocPortal site (version 9.x.x) at Anglo-Indian Portal
Back to the top
 
Posted
Rating:
#95108
Avatar

Community saint

Fletch said

I have the distinct impression that it is not a totally 'completed work', as more 'mod_sec' rules keep jumping up to bite us in the bum!
Correct. mod_sec is a moving target so it can never be considered complete :( .

For example, there are potential issues with using the openID addon (see http://ocportal.com/forum/topicview/findpost/93460.htm), but it has not been confirmed so we have not added it to the docs.

Do you have a Samsung Galaxy S / Galaxy S II ? If so, why not check out my ScreenFree FM Radio .
Back to the top
 
There are too many online users to list.
Control functions:

Quick reply   Contract

Your name:
Your message: