403 forbidden

Author
Discussion

CoolHands

18,875 posts

197 months

Friday 3rd April 2020
quotequote all
I’m getting this this morning repeatedly on the corona thread. Thought I’d been banned

V8mate

45,899 posts

191 months

Friday 3rd April 2020
quotequote all
I'm getting 403 in the Council thread

ant1973

5,693 posts

207 months

Saturday 4th April 2020
quotequote all
.

LowiePete

497 posts

140 months

Sunday 5th April 2020
quotequote all
Unable to update my profile without 403 error frown

Bobberoo99

39,167 posts

100 months

Sunday 5th April 2020
quotequote all
Hi, getting the dreaded 403 error when trying to reply to my Under £200 watch thread, I can reply to other threads but not my own thread???

jammy-git

29,778 posts

214 months

Sunday 5th April 2020
quotequote all
Try changing the wording of your post.

For some strange reason, I got the 403 error when replying to a thread in the Business section, went back, change the wording and it worked, edited the post and changed the wording again and it worked again. Edited and changed it to the original wording, still wouldn't post.

Bobberoo99

39,167 posts

100 months

Sunday 5th April 2020
quotequote all
jammy-git said:
Try changing the wording of your post.

For some strange reason, I got the 403 error when replying to a thread in the Business section, went back, change the wording and it worked, edited the post and changed the wording again and it worked again. Edited and changed it to the original wording, still wouldn't post.
I did try posting something different, computer still said no!! frown

gazza285

9,864 posts

210 months

Sunday 5th April 2020
quotequote all
Cannot post in the Music forum, from either W10 or IOS.

gazza285

9,864 posts

210 months

Sunday 5th April 2020
quotequote all
gazza285 said:
Cannot post in the Music forum, from either W10 or IOS.
Reworded the text, posted fine.

SlimJim16v

5,795 posts

145 months

Tuesday 7th April 2020
quotequote all
I still can't access the forum at all using Duck Duck. 403

afrere_ph

48 posts

63 months

PH TEAM

Tuesday 7th April 2020
quotequote all
Hey folks! Thanks for bearing with us on this one -

As some of you have guessed this boiled down to some new security measures we've put in place.. unfortunately the standard/default ruleset we were using was interpreting some text as dangerous and erroneously blocking the request.

An example of this was 300bhp/ton's (very helpful!) repro text of "find online" which was flagging a block rule to stop XSS (e.g. assumed onerror, onclick).

The reason this took some time to sort out was that this firewall is an external product, so we needed to first introduce clearer logging (to understand the scope of the problem), and then research the marketplace for an appropriate replacement, and finally ensure the new product still fit our security requirements whilst not catching false positives such as this.

Anyway.. things should hopefully be looking better for you all now! beer

SlimJim16v

5,795 posts

145 months

Tuesday 7th April 2020
quotequote all
Yes, thanks, all OK for me now.

dhutch

14,407 posts

199 months

Tuesday 7th April 2020
quotequote all
Amazing work. Thanks for the time and feedback.

Bobberoo99

39,167 posts

100 months

Wednesday 8th April 2020
quotequote all
Thanks for the feedback, and the fix!!!

Escapegoat

5,135 posts

137 months

Thursday 9th April 2020
quotequote all
Just had the 403 when trying to create a new topic in the "Computers, Gadgets and Stuff" area. As my post is about websites, it includes a couple of example (non-existent) URLs.

ETA: taking out all of the URLs allowed me to post. A bit of a shame, as the whole point was to ask questions about domain names sub-domains and DDNS.

Edited by Escapegoat on Thursday 9th April 09:44

afrere_ph

48 posts

63 months

PH TEAM

Thursday 9th April 2020
quotequote all
Hey Escapegoat - that is a little frustrating! I wonder what format the urls are in (query strings, encoded characters) that may trigger the rules blocking it?

For instance - no issue with:

https://www.pistonheads.com/

https://www.pistonheads.com/classifieds/used-cars

https://www.pistonheads.com/classifieds?Category=u...

https://www.pistonheads.com/classifieds?Category=u...

Escapegoat

5,135 posts

137 months

Thursday 9th April 2020
quotequote all
The URLs in my posting were hypothetical examples - related to setting up a NAS at home for sharing files over the Internet. So the URLs were along the lines of http://files.myownwebsite.com/shared/2029report.pd...

(will try to post this as-is)

ETA: yes, that worked just fine, as you can see.

rscott

14,858 posts

193 months

Sunday 12th April 2020
quotequote all
Getting the 403 trying to reply to this thread - https://www.pistonheads.com/gassing/topic.asp?h=0&...

This is the content I'm trying to post.

afrere_ph

48 posts

63 months

PH TEAM

Tuesday 14th April 2020
quotequote all
Hi rscott - thanks for letting us know - I've had a quick look, and can see that the text causing this is -



- which the firewall is interpreting as attempted SQL injection - https://www.w3schools.com/sql/func_sqlserver_cast....

Unfortunately we are not able to override this, and so this then falls into the small amount of edge cases which can trigger these blocking rules.

To make the user experience better we are planning to improve the 403 error page seen to better instruct users what may be causing this when it occasionally pops up.

Cheers!

dhutch

14,407 posts

199 months

Thursday 23rd April 2020
quotequote all
Here seems as good as any time to bring it up.... does PH have any plans to update the software the site runs?

Improve the user interface, particularly on mobiles and relating to the uploading of images, text formatting etc and likely fixing this issue once and for all.

Appears mad that the forum does not handle entries in a way which would remove the ability to type what you like without risking compromise or a blocking filter.


Daniel