Elxis CMS Forum

Support => Security => Topic started by: yiannisK on May 28, 2009, 01:20:45

Title: Defender and UNION SELECT filter
Post by: yiannisK on May 28, 2009, 01:20:45
It happens this strange thing...
i enabled the defender with different filters in www.pkn.gr (http://www.pkn.gr) without problems. (v2009)

The problems occurred when i wanted to add the UNION SELECT filter with this result!!

Quote
Forbidden
You don't have permission to access /administrator/index2.php on this server.
Apache Server at www.pkn.gr Port 80

Is this something with my server?!  :-\
As i know there is nothing changed to mod_security file of the Apache since previous Elxis installations (2008.1)
Title: Re: Defender and UNION SELECT filter
Post by: ks-net on May 28, 2009, 03:27:23
Quote
i enabled the defender with different filters in www.pkn.gr without problems. (v2009)

The problems occurred when i wanted to add the UNION SELECT filter with this result!!

1st disable defender then apply new filter .... nothing strange

Ps... if you are locked out now:
http://wiki.elxis.org/wiki/Troubleshooting#Elxis_Defender_locked_me_outside_Administrator
Title: Re: Defender and UNION SELECT filter
Post by: yiannisK on May 28, 2009, 11:50:16
Hi Kostas, i know that i have to disable 1st the defender and then apply the filter.
The strange is that the defender is disabled when me block!!  ::)
Title: Re: Defender and UNION SELECT filter
Post by: datahell on May 28, 2009, 13:32:48
Forbidden
You don't have permission to access /administrator/index2.php on this server.
Apache Server at www.pkn.gr Port 80

This is a message from Apache and not from Elxis defender.
At the end of your .htaccess file Elxis has some security related rewrite conditions. Comment them if you wish.
Title: Re: Defender and UNION SELECT filter
Post by: yiannisK on May 28, 2009, 15:30:53
ok thanks