403 forbidden

Author
Discussion

CoolHands

18,772 posts

196 months

Friday 3rd April 2020
quotequote all
I’m getting this this morning repeatedly on the corona thread. Thought I’d been banned

V8mate

45,899 posts

190 months

Friday 3rd April 2020
quotequote all
I'm getting 403 in the Council thread

ant1973

5,693 posts

206 months

Saturday 4th April 2020
quotequote all
.

LowiePete

497 posts

139 months

Sunday 5th April 2020
quotequote all
Unable to update my profile without 403 error frown

Bobberoo99

38,896 posts

99 months

Sunday 5th April 2020
quotequote all
Hi, getting the dreaded 403 error when trying to reply to my Under £200 watch thread, I can reply to other threads but not my own thread???

jammy-git

29,778 posts

213 months

Sunday 5th April 2020
quotequote all
Try changing the wording of your post.

For some strange reason, I got the 403 error when replying to a thread in the Business section, went back, change the wording and it worked, edited the post and changed the wording again and it worked again. Edited and changed it to the original wording, still wouldn't post.

Bobberoo99

38,896 posts

99 months

Sunday 5th April 2020
quotequote all
jammy-git said:
Try changing the wording of your post.

For some strange reason, I got the 403 error when replying to a thread in the Business section, went back, change the wording and it worked, edited the post and changed the wording again and it worked again. Edited and changed it to the original wording, still wouldn't post.
I did try posting something different, computer still said no!! frown

gazza285

9,839 posts

209 months

Sunday 5th April 2020
quotequote all
Cannot post in the Music forum, from either W10 or IOS.

gazza285

9,839 posts

209 months

Sunday 5th April 2020
quotequote all
gazza285 said:
Cannot post in the Music forum, from either W10 or IOS.
Reworded the text, posted fine.

SlimJim16v

5,721 posts

144 months

Tuesday 7th April 2020
quotequote all
I still can't access the forum at all using Duck Duck. 403

afrere_ph

48 posts

62 months

PH TEAM

Tuesday 7th April 2020
quotequote all
Hey folks! Thanks for bearing with us on this one -

As some of you have guessed this boiled down to some new security measures we've put in place.. unfortunately the standard/default ruleset we were using was interpreting some text as dangerous and erroneously blocking the request.

An example of this was 300bhp/ton's (very helpful!) repro text of "find online" which was flagging a block rule to stop XSS (e.g. assumed onerror, onclick).

The reason this took some time to sort out was that this firewall is an external product, so we needed to first introduce clearer logging (to understand the scope of the problem), and then research the marketplace for an appropriate replacement, and finally ensure the new product still fit our security requirements whilst not catching false positives such as this.

Anyway.. things should hopefully be looking better for you all now! beer

SlimJim16v

5,721 posts

144 months

Tuesday 7th April 2020
quotequote all
Yes, thanks, all OK for me now.

dhutch

14,399 posts

198 months

Tuesday 7th April 2020
quotequote all
Amazing work. Thanks for the time and feedback.

Bobberoo99

38,896 posts

99 months

Wednesday 8th April 2020
quotequote all
Thanks for the feedback, and the fix!!!

Escapegoat

5,135 posts

136 months

Thursday 9th April 2020
quotequote all
Just had the 403 when trying to create a new topic in the "Computers, Gadgets and Stuff" area. As my post is about websites, it includes a couple of example (non-existent) URLs.

ETA: taking out all of the URLs allowed me to post. A bit of a shame, as the whole point was to ask questions about domain names sub-domains and DDNS.

Edited by Escapegoat on Thursday 9th April 09:44

afrere_ph

48 posts

62 months

PH TEAM

Thursday 9th April 2020
quotequote all
Hey Escapegoat - that is a little frustrating! I wonder what format the urls are in (query strings, encoded characters) that may trigger the rules blocking it?

For instance - no issue with:

https://www.pistonheads.com/

https://www.pistonheads.com/classifieds/used-cars

https://www.pistonheads.com/classifieds?Category=u...

https://www.pistonheads.com/classifieds?Category=u...

Escapegoat

5,135 posts

136 months

Thursday 9th April 2020
quotequote all
The URLs in my posting were hypothetical examples - related to setting up a NAS at home for sharing files over the Internet. So the URLs were along the lines of http://files.myownwebsite.com/shared/2029report.pd...

(will try to post this as-is)

ETA: yes, that worked just fine, as you can see.

rscott

14,799 posts

192 months

Sunday 12th April 2020
quotequote all
Getting the 403 trying to reply to this thread - https://www.pistonheads.com/gassing/topic.asp?h=0&...

This is the content I'm trying to post.

afrere_ph

48 posts

62 months

PH TEAM

Tuesday 14th April 2020
quotequote all
Hi rscott - thanks for letting us know - I've had a quick look, and can see that the text causing this is -



- which the firewall is interpreting as attempted SQL injection - https://www.w3schools.com/sql/func_sqlserver_cast....

Unfortunately we are not able to override this, and so this then falls into the small amount of edge cases which can trigger these blocking rules.

To make the user experience better we are planning to improve the 403 error page seen to better instruct users what may be causing this when it occasionally pops up.

Cheers!

dhutch

14,399 posts

198 months

Thursday 23rd April 2020
quotequote all
Here seems as good as any time to bring it up.... does PH have any plans to update the software the site runs?

Improve the user interface, particularly on mobiles and relating to the uploading of images, text formatting etc and likely fixing this issue once and for all.

Appears mad that the forum does not handle entries in a way which would remove the ability to type what you like without risking compromise or a blocking filter.


Daniel