Go Back   Web Hosting UK Forums | Linux Windows Dedicated Server and cPanel VPS Hosting Forum > Web Hosting and Domains > Web Hosting Forum

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-21-2007, 05:44 PM
Junior Member
 
Join Date: Nov 2006
Posts: 12
Question Sea-King Wordpress Save Failures

Hi - I hope this is the correct forum.

ourHandymen.co.uk, on Sea-King.webHosting.uk.com (87.117.200.15, uses Wordpress (an unmodified Fantastico install).

Recently, it's been failing to save blog edits - The changes are lost and the editors browser is re-directed to ourHandymen.co.uk/

Any help or advice on this would be much appreciated. - Best, Ian
Reply With Quote
  #2 (permalink)  
Old 05-21-2007, 10:09 PM
Administrator
 
Join Date: Mar 2006
Posts: 1,752
Default

Hello Ian,

Do you have a ticket open for this ?

If not then please open a ticket from http://support.webhosting.uk.com and one of our staff members will get this sorted for you. It would be helpful for me if you reply back over here with the ticket number.
__________________
Web Hosting UK - ASP MSSQL Hosting - cPanel Linux Hosting
AIM : webredback || msn : andrew @ webhosting.uk.com
Toll Free : 0808 262 0855
Reply With Quote
  #3 (permalink)  
Old 05-22-2007, 10:57 AM
Junior Member
 
Join Date: Nov 2006
Posts: 12
Default

Thanks. Victor J has explained the failure on CGP-57792-588.

It seems the web-based Wordpress blog entry/edit uses scripting techniques that have, proved vulnerable to XSS attacks/injections and, been configured out.

I expect it'd be possible to hack the config' and/or Wordpress to retain security, while allowing web-based blog entry/edit. However, it'd rather this came with a standard Wordpress upgrade/patch. Unless there's already one that Victor'n'I're unaware of?

Meantime, I'm looking at client-side Wordpress blog entry/edit applications. Since, I expect these'll not fall foul of insecure scripting techniques and I've wanted to select one anyhow (to ease blog entry, by less HTML savvy company staff). CodeX.Wordpress.org/Weblog_Client

Any recommendations for Windows app's would be most welcome. - Ian
Reply With Quote
  #4 (permalink)  
Old 05-22-2007, 09:56 PM
Administrator
 
Join Date: Mar 2006
Posts: 1,752
Default

I am not sure about that but temporary solution to this problem would be to disable mod_security for your account. You can add following code in .htaccess file located in your public_html



Code:
<IfModule mod_security.c>

    SecFilterEngine Off

    SecFilterScanPOST Off

</IfModule>
you cannot see the .htaccess file from FTP software so make sure that you edit the file from file manager or from FTP you should upload .htaccess.txt with this code and rename it to make it .htaccess.
__________________
Web Hosting UK - ASP MSSQL Hosting - cPanel Linux Hosting
AIM : webredback || msn : andrew @ webhosting.uk.com
Toll Free : 0808 262 0855
Reply With Quote
  #5 (permalink)  
Old 05-24-2007, 12:10 PM
Junior Member
 
Join Date: Nov 2006
Posts: 12
Smile .htaccess SecFilterEngine/ScanPOST Off Hack

Thanks! That has worked by having a hacked .htaccess version, which I put in place when editing blogs (switching back to the original, after editing).

My search for client-side editors and/or other solutions continues. - Best, Ian
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 03:17 AM.
Copyright 2002-2007 WebHosting.uk.com. All rights reserved.
Web Hosting UK Forum