Recently when i went to make some modification on Modx Revolution, I found that I was getting 403 Forbidden message. The error logs soon indicated that this was due to ModSecurity (
http://www.modsecurity.org/) being installed. Since most of my MODX installations are on shared servers I do not have the ability to follow this Modx Document: Installation on a server running ModSecurity (
http://rtfm.modx.com/revolution/2.x/getting-started/installation/basic-installation/installation-on-a-server-running-modsecurity). After a lot of support tickets between the service provider a list of modSecurity rules were established as follows:
200004 950006 950007 950911 958003 958011 958013 958030 958049 973307 973314 973315 973320 973321 973348 981241 981249 950001 950901 958039 958051 959073 973300 973304 973306 973316 973330 973331 973333 973334 973335 973336 973344 981231 981240 981248 981319 950001 950901 959073 973300 973304 973332 973333 973335 981231 973305 959151 981250 981176
So my understanding of ModSecurity is minimal, but I understand the basics principles that it sets up rules to prevent malicious attacks on the server. When modx does a post, it is posting script tags and php code which looks like an attack. Are there any solutions now or in the future for modx not to false trigger these rules in ModSecurity.
Or will I have to continually submit a support ticket to apply these rules.
Thanks
Shawn