Hi,
Mod_security is not enabled in my server -i.e I checked the httpd.conf file and the apache modules folder. Reference to the particulat module is not in the conf file and the mod-security.so file is not in the folder. Any other hints, plz?
Regards,
Jack ---------------------------------------------------------------- "May He protect us both. May He cause us both to enjoy.May we exert together. May our studies become brilliant. May we not hate each other"
-----Original Message----- From: mediawiki-l-bounces@lists.wikimedia.org [mailto:mediawiki-l-bounces@lists.wikimedia.org] On Behalf Of Brion Vibber Sent: Friday, June 06, 2008 12:27 AM To: MediaWiki announcements and site admin list Subject: Re: [Mediawiki-l] Strange problem with search
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Jack Eapen C wrote:
When I search with SOME keywords, my production wiki returns a "blank" page. If I use the same words on the test wiki, no probs-results are returned (content in both wikis are same). Some of the problematic words are "transaction" (transaction backout has no problem), function, cards (plastic cards is fine), account etc.
Sounds like one of those "security" plugins for your web server, perhaps mod_security.
It's set in an overprotective mode that freaks out and denies access when it sees bits of text coming through the form submission that it thinks are indicative of an SQL or code injection attack.
Contact your system administrator and let them know they've misconfigured the software and should back it out to more reasonable settings.
_______________________________________________ MediaWiki-l mailing list MediaWiki-l@lists.wikimedia.org https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
This electronic mail (including any attachment thereto) may be confidential and privileged and is intended only for the individual or entity named above. Any unauthorized use, printing, copying, disclosure or dissemination of this communication may be subject to legal restriction or sanction. Accordingly, if you are not the intended recipient, please notify the sender by replying to this email immediately and delete this email (and any attachment thereto) from your computer system...Thank You