| Author |
Message |
dstg_ll
-=* NSFW *=-


Joined: 14 Jun 2002 Age: 31 Posts: 13903
Location: Black Pearl
|
Posted:
Fri Dec 01, 2006 9:01 pm Post subject: Problem with posting ? |
|
I'm getting a 403 Forbidden Error when i try to post something... will this work in here ?
EDIT: Well, it's working here, let's see in General Convo now...
EDIT #2: Yup, i only get that error in General Conversations in the Metallica thread. Here's the complete error.
Quote:Forbidden
You don't have permission to access /posting.php on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache/1.3.34 Server at www.littleblackdog.com Port 80 |
_________________ http://www.flickr.com/photos/dstg
Guy #1: Then You Post Those Fatties!
Guy #2: No can do. The forum limits attachments to 1600 x 1600.
|
|
|
|
|
sully_51
Moderator


Joined: 19 Jul 2003 Age: 24 Posts: 2072
Location: Kansas, USA
|
Posted:
Fri Dec 01, 2006 9:10 pm Post subject: |
|
Metallica thread works for me.. |
_________________ Sully
Trying to find my way around a dark life, always breaking the important things...
I only get angry at stupid people, and they have to be with themselves 24/7 so they already got theirs. - quijbe
RIP Kidneyman - 4/29/05
|
|
|
|
|
dstg_ll
-=* NSFW *=-


Joined: 14 Jun 2002 Age: 31 Posts: 13903
Location: Black Pearl
|
Posted:
Fri Dec 01, 2006 9:15 pm Post subject: |
|
Heh, found the problem.
Type this
together(as in, CD followed by 3 periods, no space).. and click on Preview. You will get the error. |
_________________ http://www.flickr.com/photos/dstg
Guy #1: Then You Post Those Fatties!
Guy #2: No can do. The forum limits attachments to 1600 x 1600.
|
|
|
|
|
pdk68
Butt Sniffer

Joined: 09 Nov 2000 Posts: 1883
|
Posted:
Fri Dec 01, 2006 9:17 pm Post subject: |
|
Looks like a bug in in the code.
As a side note should the "Site Feedback" forum not be made members only so if someone does find a bug and post it here it is not robotable?
Just a thought. |
|
|
|
|
|
|
fathertyme
Site Admin


Joined: 30 Jun 2001 Posts: 6183
Location: The American Colonies
|
Posted:
Fri Dec 01, 2006 9:58 pm Post subject: |
|
ok.. thats really funky! |
_________________ LWD web-cams: http://lwdcam.codecoma.com/?lwdcam
----
---
[9:08pm][09/16/2005]«+ flip » college...what is that
[9:08pm][09/16/2005]«+ Aff » apparently a place where you find rum
---
I used to live in my own little world, but they didn't like me there either.
You see dead people? I'm a software engineer, I don't see anybody!
---
My Amazon Wishlist
|
|
|
|
|
pdk68
Butt Sniffer

Joined: 09 Nov 2000 Posts: 1883
|
Posted:
Fri Dec 01, 2006 10:46 pm Post subject: |
|
Well it doesn't work with cd\
I guess that's something. |
|
|
|
|
|
|
EdisonRex
Lead Dog


Joined: 06 May 2002 Posts: 10049
Location: Not Moscow
|
Posted:
Sat Dec 02, 2006 1:39 am Post subject: |
|
There are all sorts of those sort of disallowed phrases in phpBB, as far as I can tell. I found out a bunch of others but I can't type them here. |
_________________ Garret: It's so retro.
EGM: What does retro mean to you?
Parker: Like, old and outdated.
|
|
|
|
|
Extreme
Big Dog


Joined: 17 Jun 2001 Age: 28 Posts: 4382
Location: Palm Bay, Florida USA
|
Posted:
Sat Dec 02, 2006 9:01 am Post subject: |
|
EdisonRex wrote:There are all sorts of those sort of disallowed phrases in phpBB, as far as I can tell. I found out a bunch of others but I can't type them here. 
But it actually looks like that the command is being ran. Otherwise wouldnt a PHP-BB error be generated and not a web server error document? |
_________________ I ♥ my IT guy, do you?
|
|
|
|
|
EdisonRex
Lead Dog


Joined: 06 May 2002 Posts: 10049
Location: Not Moscow
|
Posted:
Sat Dec 02, 2006 9:12 am Post subject: |
|
well, try typing a valid command or filename as the only item in the post. |
_________________ Garret: It's so retro.
EGM: What does retro mean to you?
Parker: Like, old and outdated.
|
|
|
|
|
Extreme
Big Dog


Joined: 17 Jun 2001 Age: 28 Posts: 4382
Location: Palm Bay, Florida USA
|
Posted:
Sat Dec 02, 2006 11:40 am Post subject: |
|
[edited multiple times]I tested with a few commands and filenames and they posted just fine. The original item did cause the same issue[/edit] |
_________________ I ♥ my IT guy, do you?
|
|
|
|
|
Extreme
Big Dog


Joined: 17 Jun 2001 Age: 28 Posts: 4382
Location: Palm Bay, Florida USA
|
Posted:
Sat Dec 02, 2006 11:46 am Post subject: |
|
I also find it odd that http://littleblackdog.com/posting.php is in the address bar, but it generates a 404 error.
When I access the same url directly it displays the normal site with the error message, No Posting Method Specified
What do the log files say regarding the error?
Quote:
Forbidden
You don't have permission to access /posting.php on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache/1.3.34 Server at www.littleblackdog.com Port 80 |
_________________ I ♥ my IT guy, do you?
|
|
|
|
|
EdisonRex
Lead Dog


Joined: 06 May 2002 Posts: 10049
Location: Not Moscow
|
Posted:
Sat Dec 02, 2006 12:22 pm Post subject: |
|
The log said the exact same thing. |
_________________ Garret: It's so retro.
EGM: What does retro mean to you?
Parker: Like, old and outdated.
|
|
|
|
|
Extreme
Big Dog


Joined: 17 Jun 2001 Age: 28 Posts: 4382
Location: Palm Bay, Florida USA
|
Posted:
Sat Dec 02, 2006 3:24 pm Post subject: |
|
OK, did some research and found out the issue.
Apparently its at the host level, and them or the site choosing to use mod_security. When this is in use it prevents known server commands from being used. One way to bypass it is to modify your . htaccess file with the following:
Quote:SecFilterEngine Off
SecFilterScanPOST Off
But you may want to check with your webhost first if you choose to bypass this security.
I was wondering why a PHP-BB error wasnt being generated....know I know why =D |
_________________ I ♥ my IT guy, do you?
|
|
|
|
|
pdk68
Butt Sniffer

Joined: 09 Nov 2000 Posts: 1883
|
Posted:
Sat Dec 02, 2006 10:36 pm Post subject: |
|
Sounds like a flaw in PHPBB, it shouldn't allow a system command to be executed from a post. |
|
|
|
|
|
|
Extreme
Big Dog


Joined: 17 Jun 2001 Age: 28 Posts: 4382
Location: Palm Bay, Florida USA
|
Posted:
Sun Dec 03, 2006 8:40 am Post subject: |
|
pdk68 wrote:Sounds like a flaw in PHPBB, it shouldn't allow a system command to be executed from a post.
Not really, its the mod_security processing anything submitted via post. And its not being executed, its just restricting that text from being used in the event of a security hole or etc.
PHP-BB cant filter it out since its done right at post time and wouldnt be able to process it...unless there was some javascript that ran client side. |
_________________ I ♥ my IT guy, do you?
|
|
|
|
|
|
|