{"id":1032833,"date":"2015-11-30T13:52:41","date_gmt":"2015-11-30T21:52:41","guid":{"rendered":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/"},"modified":"2016-02-18T08:33:02","modified_gmt":"2016-02-18T16:33:02","slug":"events-calendar-triggering-false-positives-with-config-server-security-in-cpanel","status":"closed","type":"topic","link":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/","title":{"rendered":"Events calendar triggering false positives with Config Server security in cpanel"},"content":{"rendered":"<p>Our website is running on a cpanel server which uses ConfigServer Security &amp; Firewall &#8211; csf v8.08<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"fgS2f0hk9X\"><p><a href=\"https:\/\/spiritual-frontiers.com\/\">Home<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"&#8220;Home&#8221; &#8212; SFF\" src=\"https:\/\/spiritual-frontiers.com\/?embed=true#?secret=GFtM4ermQI#?secret=fgS2f0hk9X\" data-secret=\"fgS2f0hk9X\" width=\"580\" height=\"327\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>Some (or maybe all) people who click on a link that will open an event, experience a 403 error. At some point, CSF thinks that a SQL injection attack is happening and blacklists that person&#8217;s IP. Here are some of the error log entries including warnings, and then a 403 block. If I whitelist that IP, all is well.<\/p>\n<p>I wonder if you have seen this kind of thing before?<\/p>\n<p>[Mon Nov 30 15:45:29 2015] [error] [client 199.90.240.71] ModSecurity: Warning. Pattern match &#8220;(?i:(\\\\\\\\!\\\\\\\\=|\\\\\\\\&amp;\\\\\\\\&amp;|\\\\\\\\|\\\\\\\\||&gt;&gt;|&lt;&lt;|&gt;=|&lt;=|&lt;&gt;|&lt;=&gt;|xor|rlike|regexp|isnull)|(?:not\\\\\\\\s+between\\\\\\\\s+0\\\\\\\\s+and)|(?:is\\\\\\\\s+null)|(like\\\\\\\\s+null)|(?:(?:^|\\\\\\\\W)in[+\\\\\\\\s]*\\\\\\\\([\\\\\\\\s\\\\\\\\d\\\\&#8221;]+[^()]*\\\\\\\\))|(?:xor|&lt;&gt;|rlike(?:\\\\\\\\s+binary)?)|(?:regexp\\\\\\\\s+binary))&#8221; at REQUEST_COOKIES:pdb-wp_session. [file &#8220;\/usr\/local\/apache\/conf\/crs\/activated_rules\/modsecurity_crs_41_sql_injection_attacks.conf&#8221;] [line &#8220;70&#8221;] [id &#8220;981319&#8221;] [rev &#8220;2&#8221;] [msg &#8220;SQL Injection Attack: SQL Operator Detected&#8221;] [data &#8220;Matched Data: || found within REQUEST_COOKIES:pdb-wp_session: 3e1e9c77fb8917b10c50c58b53937e1f||1448918124||1448917764&#8221;] [severity &#8220;CRITICAL&#8221;] [ver &#8220;OWASP_CRS\/2.2.8&#8221;] [maturity &#8220;9&#8221;] [accuracy &#8220;8&#8221;] [tag &#8220;OWASP_CRS\/WEB_ATTACK\/SQL_INJECTION&#8221;] [tag &#8220;WASCTC\/WASC-19&#8221;] [tag &#8220;OWASP_TOP_10\/A1&#8221;] [tag &#8220;OWASP_AppSensor\/CIE1&#8221;] [tag &#8220;PCI\/6.5.2&#8221;] [hostname &#8220;spiritual-frontiers.com&#8221;] [uri &#8220;\/&#8221;] [unique_id &#8220;Vly1aRcdPxMAABBwDBwAAAFL&#8221;]<\/p>\n<p>[Mon Nov 30 15:45:29 2015] [error] [client 199.90.240.71] ModSecurity: Warning. Pattern match &#8220;([\\\\\\\\~\\\\\\\\!\\\\\\\\@\\\\\\\\#\\\\\\\\$\\\\\\\\%\\\\\\\\^\\\\\\\\&amp;\\\\\\\\*\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\+\\\\\\\\=\\\\\\\\{\\\\\\\\}\\\\\\\\[\\\\\\\\]\\\\\\\\|\\\\\\\\:\\\\\\\\;\\\\&#8221;\\\\\\\\&#8217;\\\\\\\\\\\\xc2\\\\xb4\\\\\\\\\\\\xe2\\\\x80\\\\x99\\\\\\\\\\\\xe2\\\\x80\\\\x98\\\\\\\\`\\\\\\\\&lt;\\\\\\\\&gt;].*?){4,}&#8221; at ARGS:tribe_events. [file &#8220;\/usr\/local\/apache\/conf\/crs\/activated_rules\/modsecurity_crs_41_sql_injection_attacks.conf&#8221;] [line &#8220;159&#8221;] [id &#8220;981173&#8221;] [rev &#8220;2&#8221;] [msg &#8220;Restricted SQL Character Anomaly Detection Alert &#8211; Total # of special characters exceeded&#8221;] [data &#8220;Matched Data: &#8211; found within ARGS:tribe_events: astrological-forecast-for-2016-phillip-young-january-7-2016&#8221;] [ver &#8220;OWASP_CRS\/2.2.8&#8221;] [maturity &#8220;9&#8221;] [accuracy &#8220;8&#8221;] [tag &#8220;OWASP_CRS\/WEB_ATTACK\/SQL_INJECTION&#8221;] [hostname &#8220;spiritual-frontiers.com&#8221;] [uri &#8220;\/&#8221;] [unique_id &#8220;Vly1aRcdPxMAABBwDBwAAAFL&#8221;]<\/p>\n<p>[Mon Nov 30 15:45:29 2015] [error] [client 199.90.240.71] ModSecurity: Access denied with code 403 (phase 2). Pattern match &#8220;(.*)&#8221; at TX:981319-OWASP_CRS\/WEB_ATTACK\/SQL_INJECTION-REQUEST_COOKIES:pdb-wp_session. [file &#8220;\/usr\/local\/apache\/conf\/crs\/activated_rules\/modsecurity_crs_49_inbound_blocking.conf&#8221;] [line &#8220;26&#8221;] [id &#8220;981176&#8221;] [msg &#8220;Inbound Anomaly Score Exceeded (Total Score: 5, SQLi=3, XSS=0): Last Matched Message: Restricted SQL Character Anomaly Detection Alert &#8211; Total # of special characters exceeded&#8221;] [data &#8220;Last Matched Data: ||&#8221;] [hostname &#8220;spiritual-frontiers.com&#8221;] [uri &#8220;\/&#8221;] [unique_id &#8220;Vly1aRcdPxMAABBwDBwAAAFL&#8221;]<\/p>\n","protected":false},"template":"","class_list":["post-1032833","topic","type-topic","status-closed","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Events calendar triggering false positives with Config Server security in cpanel -<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Events calendar triggering false positives with Config Server security in cpanel -\" \/>\n<meta property=\"og:description\" content=\"Our website is running on a cpanel server which uses ConfigServer Security &amp; Firewall &#8211; csf v8.08 Home Some (or maybe all) people who click on a link that will open an event, experience a 403 error. At some point, CSF thinks that a SQL injection attack is happening and blacklists that person&#8217;s IP. Here [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/\" \/>\n<meta property=\"article:modified_time\" content=\"2016-02-18T16:33:02+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/\",\"url\":\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/\",\"name\":\"Events calendar triggering false positives with Config Server security in cpanel -\",\"isPartOf\":{\"@id\":\"https:\/\/theeventscalendar.com\/support\/#website\"},\"datePublished\":\"2015-11-30T21:52:41+00:00\",\"dateModified\":\"2016-02-18T16:33:02+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/theeventscalendar.com\/support\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Topics\",\"item\":\"https:\/\/theeventscalendar.com\/support\/topics\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Calendar Products\",\"item\":\"https:\/\/theeventscalendar.com\/support\/forums\/forum\/events\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Events Calendar PRO\",\"item\":\"https:\/\/theeventscalendar.com\/support\/forums\/forum\/events\/events-calendar-pro\/\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"Events calendar triggering false positives with Config Server security in cpanel\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/theeventscalendar.com\/support\/#website\",\"url\":\"https:\/\/theeventscalendar.com\/support\/\",\"name\":\"\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/theeventscalendar.com\/support\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Events calendar triggering false positives with Config Server security in cpanel -","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/","og_locale":"en_US","og_type":"article","og_title":"Events calendar triggering false positives with Config Server security in cpanel -","og_description":"Our website is running on a cpanel server which uses ConfigServer Security &amp; Firewall &#8211; csf v8.08 Home Some (or maybe all) people who click on a link that will open an event, experience a 403 error. At some point, CSF thinks that a SQL injection attack is happening and blacklists that person&#8217;s IP. Here [&hellip;]","og_url":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/","article_modified_time":"2016-02-18T16:33:02+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/","url":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/","name":"Events calendar triggering false positives with Config Server security in cpanel -","isPartOf":{"@id":"https:\/\/theeventscalendar.com\/support\/#website"},"datePublished":"2015-11-30T21:52:41+00:00","dateModified":"2016-02-18T16:33:02+00:00","breadcrumb":{"@id":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/theeventscalendar.com\/support\/forums\/topic\/events-calendar-triggering-false-positives-with-config-server-security-in-cpanel\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/theeventscalendar.com\/support\/"},{"@type":"ListItem","position":2,"name":"Topics","item":"https:\/\/theeventscalendar.com\/support\/topics\/"},{"@type":"ListItem","position":3,"name":"Calendar Products","item":"https:\/\/theeventscalendar.com\/support\/forums\/forum\/events\/"},{"@type":"ListItem","position":4,"name":"Events Calendar PRO","item":"https:\/\/theeventscalendar.com\/support\/forums\/forum\/events\/events-calendar-pro\/"},{"@type":"ListItem","position":5,"name":"Events calendar triggering false positives with Config Server security in cpanel"}]},{"@type":"WebSite","@id":"https:\/\/theeventscalendar.com\/support\/#website","url":"https:\/\/theeventscalendar.com\/support\/","name":"","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/theeventscalendar.com\/support\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/theeventscalendar.com\/support\/wp-json\/wp\/v2\/topic\/1032833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/theeventscalendar.com\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/theeventscalendar.com\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/theeventscalendar.com\/support\/wp-json\/wp\/v2\/topic\/1032833\/revisions"}],"predecessor-version":[{"id":1032889,"href":"https:\/\/theeventscalendar.com\/support\/wp-json\/wp\/v2\/topic\/1032833\/revisions\/1032889"}],"wp:attachment":[{"href":"https:\/\/theeventscalendar.com\/support\/wp-json\/wp\/v2\/media?parent=1032833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}