#{茶男與藍牌}
Inproper UTF8 encoding lead to forbidden in apache by ModSecurity2
Today a very interesting issue raised…
Scenario:
- Copy text from Word document
- Paste text to input text field in browser
- Submit the form
- Response from apache is the following:
Bad Request
Your browser sent a request that this server could not understand.
Reason:
UTF8 text from word document conflicts with ModSecurity2′s rule – 950801
Solution:
Add the following line into proper place in httpd.conf
SecRuleRemoveById 950801
Reference:
http://en.wikipedia.org/wiki/Percent_encoding#Binary_data
http://osdir.com/ml/apache.mod-security.user/2007-05/msg00179.html
-
Articles
- October 2012
- May 2012
- April 2012
- March 2012
- February 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
-
Meta



