WPIntell

Source evidence

Users getting blocked by ModSecurity

Simple Notices · support · 2012-11-01T15:28:00+00:00

complaintsentiment
highseverity
1.0relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

2 / 27 rows with source links

7.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

25 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
RichmondJim unresolved
Users are getting locked out of the server by ModSecurity for cPanel. Checking the log, I find error messages like: “Cross-site Scripting (XSS) Attack. Matched signature <.cookie>”] [severity “CRITICAL”] [hostname “**redacted**”] [uri “/wp-content/plugins/simple-notices/js/jquery.cookie.js”] Any chance you can update the plugin so that it does not generate files with the word “cookie” in the file name? http://wordpress.org/extend/plugins/simple-notices/ The word “cookie” in the file name is causing the error message? jquery.cookie.js is a very common JS library used in hundreds of plugins / themes. Thanks for the speedy reply. It would appear that the block is caused by the word “cookie”. After seeing about a dozen of these blocks over the last 24 hours, I Googled the error message and found that one user had rewritten the plug-in and associated files to use “.wookie” instead of .cookie and the problem resolved. Since you say that the jquery.cookie.js is a common library, I’ll forward this first to our server engineer and see what he says. I’ll post an update when I hear back from him. Thanks again! It seems really weird that the server would block it based on the file name, especially one so common as “cookie”. Let me know what they say!

Comments

3 shown
Pippin Williamson 2012-11-01T15:43:00+00:00

The word “cookie” in the file name is causing the error message? jquery.cookie.js is a very common JS library used in hundreds of plugins / themes.

RichmondJim 2012-11-01T16:03:00+00:00

Thanks for the speedy reply. It would appear that the block is caused by the word “cookie”. After seeing about a dozen of these blocks over the last 24 hours, I Googled the error message and found that one user had rewritten the plug-in and associated files to use “.wookie” instead of .cookie and the problem resolved. Since you say that the jquery.cookie.js is a common library, I’ll forward this first to our server engineer and see what he says. I’ll post an update when I hear back from him. Thanks again!

Pippin Williamson 2012-11-02T00:47:00+00:00

It seems really weird that the server would block it based on the file name, especially one so common as “cookie”. Let me know what they say!