We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 39548
    • 10 Posts
    Recently when i went to make some modification on Modx Revolution, I found that I was getting 403 Forbidden message. The error logs soon indicated that this was due to ModSecurity (http://www.modsecurity.org/) being installed. Since most of my MODX installations are on shared servers I do not have the ability to follow this Modx Document: Installation on a server running ModSecurity (http://rtfm.modx.com/revolution/2.x/getting-started/installation/basic-installation/installation-on-a-server-running-modsecurity). After a lot of support tickets between the service provider a list of modSecurity rules were established as follows:

    200004 950006 950007 950911 958003 958011 958013 958030 958049 973307 973314 973315 973320 973321 973348 981241 981249 950001 950901 958039 958051 959073 973300 973304 973306 973316 973330 973331 973333 973334 973335 973336 973344 981231 981240 981248 981319 950001 950901 959073 973300 973304 973332 973333 973335 981231 973305 959151 981250 981176

    So my understanding of ModSecurity is minimal, but I understand the basics principles that it sets up rules to prevent malicious attacks on the server. When modx does a post, it is posting script tags and php code which looks like an attack. Are there any solutions now or in the future for modx not to false trigger these rules in ModSecurity.
    Or will I have to continually submit a support ticket to apply these rules.
    Thanks
    Shawn




      • 3749
      • 24,544 Posts
      I don't think there's anything that MODX (or any other CMS) can do about this. If you want to use script tags in your code and your host's implementation of mod_security disallows writing script tags to the database, only the host can solve the problem.

      You might find this list useful: http://bobsguides.com/modx-friendly-hosts.html. I've never heard of a problem with script tags on any of them.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Actually, there was one once with SkyToaster, but it got fixed almost immediately. A really on-the-ball hosting provider can customize or even disable on a directory basis, thus allow script tags in the Manager directory but not the root directory.

        http://serverfault.com/questions/57210/disable-modsecurity-for-a-specific-directory
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 25803 ☆ A M B ☆
          • 721 Posts
          Whenever we've run into this issue we just get the host to "white list" the site(s).
            • 39548
            • 10 Posts
            The one thing that modx could improve on this situation is to give an indication , error message in the CMS to indicate that there was a 403, instead of just appearing like it saved the chunk or snippet. I believe on the resource when it gets a 403 message it goes into its infinite loop like it is trying to save the resource which is the only indication..
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              That would be a little tricky, since not all servers return a 403. I've dealt with some that returned a 404, some a 500 and some that just didn't return anything at all.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org