Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Encoding periods (.) as . #1253

Open
AnthonyVO opened this issue Jan 17, 2018 · 7 comments
Open

Encoding periods (.) as . #1253

AnthonyVO opened this issue Jan 17, 2018 · 7 comments

Comments

@AnthonyVO
Copy link

My host Namecheap is now rejecting strings like "web.config" in post requests. I suspect they are trying to avoid hacking attempts that go after specific system files. This makes it annoying to write documentation using GetSimple.

One suggestion I have is to encode the period as .

Thanks again for a great and simple CMS.

@AnthonyVO
Copy link
Author

Noticed that my last post was auto corrected. The subject line is still correct.
I would like to suggest that perdiods (.) be encoded as "& period;" <= ignore the space

@tablatronix
Copy link
Member

Strings where, what payloads? Post?

@tablatronix
Copy link
Member

This seems awefully lame, are they using a mod sec rule? Is this in any post or content with html and code

@AnthonyVO
Copy link
Author

AnthonyVO commented Jan 17, 2018

It is a ModSecurity rule. I agree it is lame. I got their hosting to disable the rule and gave them some politely worded feedback.

The problem is that when ModSecurity kicks in it gives you no clue what the problem is with the result that it makes the Web Application look bad. All I get is a "Oops! Page not found!" which is totally not helpful.

They have disabled the rule so I can't do further testing.

Namecheap is pretty large and other Hosts might try the same thing so I leave it as a suggestion so that you could get ahead of this.

Thanks for being there and being responsive.

@tablatronix
Copy link
Member

Did you happen to get the rule id from your host error log

@AnthonyVO
Copy link
Author

The Rule Id is 210580.

@tablatronix
Copy link
Member

#1252

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants