Hy,
ich habe den Shop eines Kunden auf einen neuen Server mit den neusten Sicherheitsfunktionen umgezogen.
Nun scheint ModSecurity die Vorschau der eMail-Vorlagen nicht mehr zu mögen und sperrt.
Die Frage ist nun, da dies ja eine False/Positive Meldung ist, an wen richtet man das Fehlverhalten? Bei Shopware, Atomicorp oder Plesk?
[Mon Jan 16 16:02:54.957722 2017] [:error] [pid 13334] [client 212.***.***.***] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)?(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^<samlp|^>> ?$)" against "ARGS:value" required. [file "/etc/apache2/modsecurity.d/rules/tortix/modsec/50_plesk_basic_asl_rules.conf"] [line "308"] [id "350147"] [rev "143"] [msg "Protected by Atomicorp.com Basic Non-Realtime WAF Rules: Potentially Untrusted Web Content Detected"] [data ""] [severity "CRITICAL"] [hostname "www.*****.de"] [uri "/backend/mail/verifySmarty"] [unique_id "W*****n*****MAADQWwrw*****"]
[Mon Jan 16 16:03:07.370223 2017] [:error] [pid 13334] [client 212.***.***.***] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)?(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^<samlp|^>> ?$)" against "ARGS:value" required. [file "/etc/apache2/modsecurity.d/rules/tortix/modsec/50_plesk_basic_asl_rules.conf"] [line "308"] [id "350147"] [rev "143"] [msg "Protected by Atomicorp.com Basic Non-Realtime WAF Rules: Potentially Untrusted Web Content Detected"] [data ""] [severity "CRITICAL"] [hostname "www.*****.de"] [uri "/backend/mail/verifySmarty"] [unique_id "W*****d2*****ADQWwr4A*****"]
[Mon Jan 16 16:03:17.217145 2017] [:error] [pid 24384] [client 212.***.***.***] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)?(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^<samlp|^>> ?$)" against "ARGS:value" required. [file "/etc/apache2/modsecurity.d/rules/tortix/modsec/50_plesk_basic_asl_rules.conf"] [line "308"] [id "350147"] [rev "143"] [msg "Protected by Atomicorp.com Basic Non-Realtime WAF Rules: Potentially Untrusted Web Content Detected"] [data ""] [severity "CRITICAL"] [hostname "www.*****.de"] [uri "/backend/mail/verifySmarty"] [unique_id "W*****d2*****AF9*****iE*****"]