Ubuntu 20.04.5 LTS
wurde 3.1.8 installiert, alles geht bis auf der Zugriff zu Userverwaltung wie auch
FAQ Beitrag erstellen
https://faq.xxx.at/admin/?action=user
https://faq.xxx.at/admin/?action=editentry
"Forbidden
You don't have permission to access this resource.
Apache Server at faq.barth-company.at Port 443"
im Protokoll scheint auf
Code: Select all
403 GET /admin/?action=user HTTP/1.0
[client xx.xx.xx.xx] ModSecurity: Access denied with code 403 (phase 4). Match of "rx \\\\ssrc=\\\\x22https:\\\\/\\\\/www\\\\.googletagmanager\\\\.com\\\\/ns\\\\.html\\\\?id=GTM|\\\\ssrc=\\\\x22https:\\\\/\\\\/w\\\\.soundcloud\\\\.com\\\\/player\\\\/\\\\?url=" against "TX:0" required. [file "/etc/apache2/modsecurity.d/rules/comodo_free/19_Outgoing_FilterInFrame.conf"] [line "14"] [id "214540"] [rev "5"] [msg "COMODO WAF: Possibly malicious iframe tag in output||faq.xx.at|F|3"] [data "Matched Data: <iframe id=\\x22keepPMFSessionAlive\\x22 src=\\x22session.keepalive.php?lang=de\\x22 width=\\x220\\x22 height=\\x220\\x22\\x0a style=\\x22display: none found within TX:0: <iframe id=\\x22keepPMFSessionAlive\\x22 src=\\x22session.keepalive.php?lang=de\\x22 width=\\x220\\x22 height=\\x220\\x22\\x0a style=\\x22display: none"] [severity "ERROR"] [tag "CWAF"] [tag "FilterInFrame"] [hostname "faq.xx.at"] [uri "/admin/index.php"] [unique_id "Y3VC61sUI-7v1ZuRc@P3VwAAAAE"], referer: https://faq.barth-company.at/admin/?action=system
[client xx.xx.xx.xx] ModSecurity: Warning. Operator GE matched 4 at TX:outgoing_points. [file "/etc/apache2/modsecurity.d/rules/comodo_free/20_Outgoing_FiltersEnd.conf"] [line "38"] [id "214940"] [rev "2"] [msg "COMODO WAF: Outbound Points Exceeded| Total Points: 4|faq.xx.at|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "FiltersEnd"] [hostname "faq.xx.at"] [uri "/admin/index.php"] [unique_id "Y3VC61sUI-7v1ZuRc@P3VwAAAAE"], referer: https://faq.xx.at/admin/?action=system
404 GET /admin/requestProvider.js.map HTTP/1.0
404 GET /favicon.ico HTTP/1.0
Irgendwelche Ideen was das Problem sein könnte?
Apache Module in Plesk, Php ist 7.4.33 und auch 8.1.12 probiert worden.
Folgende PHP Extensions sind laut PhpmyFAQ ersichtlich (Systeminfo):
Core, date, libxml, openssl, pcre, zlib, bz2, calendar, ctype, hash, filter, ftp, gettext, gmp, json, iconv, SPL, Reflection, session, standard, mbstring, SimpleXML, sockets, tokenizer, xml, cgi-fcgi, mysqlnd, bcmath, curl, dba, dom, enchant, fileinfo, gd, imagick, imap, intl, ldap, exif, mysqli, odbc, PDO, pdo_mysql, PDO_ODBC, pdo_pgsql, pdo_sqlite, pgsql, Phar, posix, pspell, redis, soap, sodium, sqlite3, sysvmsg, sysvsem, sysvshm, tidy, xmlreader, xmlwriter, xsl, zip, Zend OPcache
Database Server mysqli
Database Server Version 10.3.34-MariaDB-0ubuntu0.20.04.1
Database Client Version mysqlnd 8.1.12
PHP Version 8.1.12
Web server Interface FPM-FCGI
phpMyFAQ Version 3.1.8
phpMyFAQ API Version 2.1