Everytime while browsing my site, after fes 5-10 mins my server blocks the Ip. As i checked and found out that this was because mod_security. Its on all new versions.
What is the solution for this.
check problem details below. This look like a valid arrgument.
This was due to mod security >>
Access denied with code 406 (phase 2). Pattern match "(?:\b(?:(?:type\b\W*?\b(?:text\b\W*?\b(?:j(?:ava)?|ecma|vb)|application\b\W*?\bx-(?:java|vb))script|c(?:opyparentfolder|reatetextrange)|get(?:special|parent)folder|iframe\b.{0,100}?\bsrc)\b|on(?:(?:mo(?:use(?:o(?:ver|ut)|down|move|up)|ve)|key(?:press|d ..." at REQUEST_FILENAME. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "120"] [id "950004"] [msg "Cross-site Scripting (XSS) Attack"] [data ".cookie"] [severity "CRITICAL"] [tag "WEB_ATTACK/XSS"]
Problem file >> /includes/js/jquery.cookie.js HTTP/1.1
Vlad replies --- The file that is getting blocked is "includes/js/jquery.cookie.js". Add it to the ignore list of "mod_security". Contact your hosting provider for details as it's not part of our software.
But How to disable the ONLY 1 file for a website via Mod Security. Please assist as this is a big issues. what server config do we need for this for Mod_security. as i have simple default settings. View Comments & Reply...
If we keep the MOD Security ON then The Client need will randomely get IP Block issue. when i login & logout and perform this action couple of time the mod_security blocks my IP and my site is not accessed by me.
As there are some false alert also some time due to some pattern match, like it block if URL have % char. passed.
This is the issue im facing since i have updated to new version 2.5.6.
Does anyone have idea about this, or facing this find in newer version. View Comments & Reply...





Latest Comments
Status Mod - To Keep them Coming Back
1 day ago
Status Mod - To Keep them Coming Back
1 day ago
Edit to Picture-Zoom
1 day ago