Simple Membership Plugin › Forums › Simple Membership Plugin › Editing sites created by Membership Plugin throws out JSON error
- This topic has 15 replies, 3 voices, and was last updated 3 years, 9 months ago by
admin.
-
AuthorPosts
-
December 19, 2022 at 10:01 pm #24936
toddehb
ParticipantThis is from the logs. Maybe somebody here will understand how to interpret this:
[Mon Dec 19 19:20:50.871830 2022] [:error] [pid 198258] [client XXX:52849] [client XXX] ModSecurity: Warning. Pattern match “\\\\b(?:if(?:/i)?(?: not)?(?: exist\\\\b| defined\\\\b| errorlevel\\\\b| cmdextversion\\\\b|(?: |\\\\().*(?:\\\\bgeq\\\\b|\\\\bequ\\\\b|\\\\bneq\\\\b|\\\\bleq\\\\b|\\\\bgtr\\\\b|\\\\blss\\\\b|==))|for(?:/[dflr].*)? %+[^ ]+ in\\\\(.*\\\\)\\\\s?do)” at ARGS:content. [file “/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf”] [line “412”] [id “932140”] [msg “Remote Command Execution: Windows FOR/IF Command Found”] [data “Matched Data: if you end up changing the url of this page then make sure to update the url value in the settings menu of the plugin.</p> <p style=border-top:1px solid #ccc padding-top:10px margin-top:10px ></p> free membership you get unlimited access to free membership content price: free! link the following image to go to the registration page if you want your visitors to be able to create a free membership account <img title=join now src=https://www.XXX.ne…”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “lang [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6Crgs5o4VMPWxNSlINc-gAAAAQ”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
[Mon Dec 19 19:20:50.872782 2022] [:error] [pid 198258] [client XXX:52849] [client XXX] ModSecurity: Warning. detected XSS using libinjection. [file “/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf”] [line “55”] [id “941100”] [msg “XSS Attack Detected via libinjection”] [data “Matched Data: XSS data found within ARGS:content: <p style=\\x22color:red;font-weight:bold;\\x22>This page and the content has been automatically generated for you to give you a basic idea of how a \\x22Join Us\\x22 page should look like. You can customize this page however you like it by editing this page from your WordPress page editor.</p>\\x0a<p style=\\x22font-weight:bold;\\x22>If you end up changing the URL of this page then make sure to update the URL value in the settings menu of the plugin.</p>\\x0a<p s…”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “language-multi”] [tag “platform-multi”] [tag “attack-xss”] [tag “paranoia-level/1”] [tag “OWASP_CRS”] [tag “capec/1000/152/242”] [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6Crgs5o4VMPWxNSlINc-gAAAAQ”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
[Mon Dec 19 19:21:48.055447 2022] [:error] [pid 198263] [client XXX:52876] [client XXX] ModSecurity: Warning. Pattern match “(?i:(?:;\\\\s*?(?:(?:(?:trunc|cre|upd)at|renam)e|(?:inser|selec)t|de(?:lete|sc)|alter|load)\\\\b\\\\s*?[\\\\[(]?\\\\w{2,}|create\\\\s+function\\\\s+.+\\\\s+returns))” at ARGS:content. [file “/usr/share/modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf”] [line “404”] [id “942350”] [msg “Detects MySQL UDF injection and other data/structure manipulation attempts”] [data “Matched Data: ; Insert Payment found within ARGS:content: <p style=\\x22color:red;font-weight:bold;\\x22>This page and the content has been automatically generated for you to give you a basic idea of how a \\x22Join Us\\x22 page should look like. You can customize this page however you like it by editing this page from your WordPress page editor.</p>\\x0a<p style=\\x22font-weight:bold;\\x22>If you end up changing the URL of this page then make sure to update the URL value in the settings menu of the plugin.</p>…”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “language-multi”] [tag “platform-multi” [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6CrvLpw7DeoGiaPDNHu3wAAAAg”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
[Mon Dec 19 19:21:48.055876 2022] [:error] [pid 198263] [client XXX:52876] [client XXX] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file “/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf”] [line “93”] [id “949110”] [msg “Inbound Anomaly Score Exceeded (Total Score: 20)”] [severity “CRITICAL”] [ver “OWASP_CRS/3.3.2”] [tag “application-multi”] [tag “language-multi”] [tag “platform-multi”] [tag “attack-generic”] [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6CrvLpw7DeoGiaPDNHu3wAAAAg”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=edit
[Mon Dec 19 19:21:48.056072 2022] [:error] [pid 198263] [client XXX:52876] [client XXX] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file “/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf”] [line “91”] [id “980130”] [msg “Inbound Anomaly Score Exceeded (Total Inbound Score: 20 – SQLI=5,XSS=10,RFI=0,LFI=0,RCE=5,PHPI=0,HTTP=0,SESS=0): individual paranoia level scores: 20, 0, 0, 0”] [ver “OWASP_CRS/3.3.2”] [tag “event-correlation”] [hostname “www.XXX.net”] [uri “/index.php”] [unique_id “Y6CrvLpw7DeoGiaPDNHu3wAAAAg”], referer: https://www.XXX.net/wp-admin/post.php?post=258&action=editDecember 19, 2022 at 10:04 pm #24939admin
KeymasterThe mod security rule on this server seems to be giving a false positive for that action. You might be able to configure/customize the rule to remove this false positive. The hosting provider will probably be able to adjust/tweak the mod security configuration. The following file might have some additional insight into why the false positive is triggering:
usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf -
AuthorPosts
- You must be logged in to reply to this topic.