Blob ([info]blob) wrote in [info]dyc_hosting,
@ 2006-01-03 12:56:00
Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Weird, weird problem
Katie -

I'm sure this is related to what [info]arkadina posted about last month, although I've only just seen her post about it! Not sure how I missed that. I've done a bit of research into it so I thought I'd post here.

A lot of visitors to both of my sites have been getting 403 forbidden errors when trying to post comments on my blogs, send messages via my feedback forms, and post questions in my Q&A. This has been happening since November time, which is when we had all the problems with the server. I have had this problem numerous times when trying to update my blog. It would appear that the server disallows/bans lots of words, and combinations of letters/spaces, from being submitted - one example of a letter combination is "sh t" (which features in in "wish that", "finish the", "posh things", etc.), and also "sh s" (in "wish she", "finish shopping", "posh socks", etc.) Plus other combinations, I'm sure, although finding them is a tricky matter - it involves dissecting each post and removing sentences, words or letters one by one, until you figure out exactly which combination of letters is causing the problem! It really does limit what can be posted. :( Long comments are generally lost more often than short comments, because, obviously, there's more chance of them containing forbidden words/combinations.

EDIT: Okay! After playing about a bit more, I've realised that it's actually "sh " (with a space after it) regardless of the letters that follow. So something like "I like fish." would not be a problem, but "I like fish and chips" would.

After researching this a bit, I realised that it's not a problem with my scripts (as it's happening on both of my sites) - it's an issue with the server. So it won't be affecting individual accounts; it'll be affecting everyone. I expect that anyone else on the server trying to use the POST command (used in WordPress, and other scripts that use forms) to send the combination "sh t" will get a 403 error. In fact, I just took a trip over to DamnYellowCap.net and Tinyblob.net and tried to post comments of "sh s" and "sh t", which resulted in 403 errors. So I thought I'd let you know what some people have suggested to tell your host if you're having the same problems.

These are the suggestions:

- Ask your host whether they're using mod_security, and if so, whether they have any (overly-simplistic) rules that look for certain terms. Give an example of a combination of letters that is banned; in this case "sh ".

- Ask your host to update Zend (although this appears to work in only about 50% of the cases).

I don't really understand the above suggestions, but maybe you could contact Surpass and ask about them? It really is getting a bit annoying, because there's a lot of discussion over at Rachael-Stirling.com (and will be more when I get the forum set up). At present, only about 40% of the messages are getting through, and people are losing some long comments. :( I advised them to keep a backup of their comments before posting, but it's not like they're able to post them anyway, so that isn't much use, LOL! I thought it was a problem on my end to start with, which is why I haven't posted here about it until now.

Help? :)



(Post a new comment)


[info]sopdetly
2006-01-03 02:57 pm UTC (link)
Well, right now I'm more concerned with the fact that when I tried to login to the server, it says I've got the wrong login info! :/

I pretty much copied/pasted your thing here to Surpass, we'll see what they can do, though if that password thing is an issue for them, too, I don't know where that will leave us...

(Reply to this) (Thread)


[info]arkadina
2006-01-03 03:33 pm UTC (link)
I'm not sure if this is related to your problem Katie, but I've been randomly told my login info is wrong lately as well, although obviously it's not so alarming. I just assumed it was my typing or computor.

Also, thanks for doing more research than I could Bonnie, I had no idea where to go to look for help. How bizarre.

(Reply to this) (Parent)(Thread)


[info]blob
2006-01-03 03:47 pm UTC (link)
I've also been having random login issues lately! Hmmm, definitely dodgy...

(Reply to this) (Parent)(Thread)


[info]splonk
2006-01-04 12:49 am UTC (link)
Ahhh, thanks for posting this. I had the biggest bitch of a time posting to a new installation of WordPress last night because I got 403 errors, but only when I posted certain things. Glad to know it wasn't just me!

(Reply to this) (Parent)


[info]feloriene
2006-01-17 11:18 am UTC (link)
I've just finally started some work on my sites again lately and I had a similar problem with 403 errors, but it was on the images/ folder on the-Spacemonkey.net - all the images on my site weren't showing and when I tried to access the directory, I kept getting error 403 forbidden msgs. I checked out FTP and the folder won't let me into it, the permissions are all set to 0 meaning I can't delete it or edit the contents. In the meantime I've changed the name of the folder to 'delete' and uploaded my images folder again so that the site's displaying normally again, but I think I may need help getting the damn folder off the server :s.

Any ideas?

(Reply to this)


Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…