Closed (cannot reproduce)
Project:
Drupad
Version:
7.x-1.8
Component:
Miscellaneous
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Reporter:
Created:
9 May 2012 at 16:32 UTC
Updated:
21 Nov 2012 at 08:08 UTC
Hi,
I tried to get Drupad to work, no success.
Work with Drupal 7.14.
In Testing / Debug tried snippet #1 and #2. With #2 I got a 500 (Internal Server Error) with #1 and without snippets, error 401.
Please give assistance.
Comments
Comment #1
harri00413 commentedComment #2
jchatard commentedPlease check
admin/reports/statusand check that everything is OK.Please tell me:
- what HTTP server you are using,
- check your HTTP server logs to see what is going on.
Comment #3
harri00413 commentedHi,
Status all green.
Webserver: Apache/2.2.0 (Fedora) mod_perl/2.0.4 Perl/v5.8.8
PHP: 5.2.17
Server API: CGI/FastCGI
Logs: Possibly this will help, from the server error log when I tried to test the drupad app with the button: "Launch the test".
[Tue Jun 05 12:24:54 2012] [error] [client 195.109.63.130] ModSecurity: Warning. Pattern match "(?:\\b(?:(?:type\\b\\W*?\\b(?:text\\b\\W*?\\b(?:j(?:ava)?|ecma|vb)|application\\b\\W*?\\bx-(?:java|vb))script|c(?:opyparentfolder|reatetextrange)|get(?:special|parent)folder|iframe\\b.{0,100}?\\bsrc)\\b|on(?:(?:mo(?:use(?:o(?:ver|ut)|down|move|up)|ve)|key(?:press|d ..." at ARGS_NAMES:ajax_page_state[js][misc/jquery.cookie.js]. [file "/etc/httpd/modsecurity.d/modsecurity_crs_40_generic_attacks.conf"] [line "102"] [id "950004"] [msg "Cross-site Scripting (XSS) Attack"] [data ".cookie"] [severity "CRITICAL"] [tag "WEB_ATTACK/XSS"] [hostname "www.rhijnenvechtstreek.nl"] [uri "/"] [unique_id "T83edn8AAAEAABM0HyEAAAAM"]
[Tue Jun 05 12:24:55 2012] [error] [client 84.241.180.142] ModSecurity: Warning. Match of "rx ^OPTIONS$" against "REQUEST_METHOD" required. [file "/etc/httpd/modsecurity.d/modsecurity_crs_21_protocol_anomalies.conf"] [line "41"] [id "960015"] [msg "Request Missing an Accept Header"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/MISSING_HEADER"] [hostname "www.rhijnenvechtstreek.nl"] [uri "/"] [unique_id "T83ed38AAAEAAAKIhw4AAAAD"]
[Tue Jun 05 12:25:18 2012] [error] [client 195.109.63.130] ModSecurity: Warning. Pattern match "(?:\\b(?:(?:type\\b\\W*?\\b(?:text\\b\\W*?\\b(?:j(?:ava)?|ecma|vb)|application\\b\\W*?\\bx-(?:java|vb))script|c(?:opyparentfolder|reatetextrange)|get(?:special|parent)folder|iframe\\b.{0,100}?\\bsrc)\\b|on(?:(?:mo(?:use(?:o(?:ver|ut)|down|move|up)|ve)|key(?:press|d ..." at ARGS_NAMES:ajax_page_state[js][misc/jquery.cookie.js]. [file "/etc/httpd/modsecurity.d/modsecurity_crs_40_generic_attacks.conf"] [line "102"] [id "950004"] [msg "Cross-site Scripting (XSS) Attack"] [data ".cookie"] [severity "CRITICAL"] [tag "WEB_ATTACK/XSS"] [hostname "www.rhijnenvechtstreek.nl"] [uri "/"] [unique_id "T83ejX8AAAEAADqu6i8AAAAB"]
[Tue Jun 05 12:25:18 2012] [error] [client 84.241.180.142] ModSecurity: Warning. Match of "rx ^OPTIONS$" against "REQUEST_METHOD" required. [file "/etc/httpd/modsecurity.d/modsecurity_crs_21_protocol_anomalies.conf"] [line "41"] [id "960015"] [msg "Request Missing an Accept Header"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/MISSING_HEADER"] [hostname "www.rhijnenvechtstreek.nl"] [uri "/"] [unique_id "T83ejn8AAAEAABodAccAAAAO"]
I have no idea what this means.
After using snippet #2, the below lines appeared in the log.
84.241.180.142 - - [05/Jun/2012:12:56:00 +0200] "GET /?q=drupad/check-config/1.4 HTTP/1.0" 500 654 "-" "Drupad testing client"
195.109.63.130 - - [05/Jun/2012:12:55:59 +0200] "POST /?q=system/ajax HTTP/1.1" 200 3412 "http://www.rhijnenvechtstreek.nl/?q=admin%2Fconfig%2Fsystem%2Fdrupad&ren..." "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
195.109.63.130 - - [05/Jun/2012:12:56:00 +0200] "GET /modules/overlay/overlay-parent.css?m5550k HTTP/1.1" 200 1063 "http://www.rhijnenvechtstreek.nl/?q=admin%2Fconfig%2Fsystem%2Fdrupad&ren..." "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
84.241.180.142 - - [05/Jun/2012:12:56:26 +0200] "GET /?q=drupad/check-config/1.4 HTTP/1.0" 500 654 "-" "Drupad testing client"
195.109.63.130 - - [05/Jun/2012:12:56:25 +0200] "POST /?q=system/ajax HTTP/1.1" 200 2479 "http://www.rhijnenvechtstreek.nl/?q=admin%2Fconfig%2Fsystem%2Fdrupad&ren..." "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.52 Safari/536.5"
Again, I haven't got the foggiest.
Comment #4
jchatard commentedOh men!
That is really strange, I never saw such logs. Maybe this has to do with some Fedora specific security features.
Could you try on a fresh server, or even on a workstation?
If this is due to a specific server config, I won't be much of any help.
Comment #5
Adam S commentedThis is caused by ModSecurity extension preventing any file with the word 'cookie' from being sent. So jquery.cookie.js wrecks the whole thing (see the pattern). Just update the ModSecurity Core Rule Set where this bug has been fixed on the server and all should be well.
Comment #6
harri00413 commentedMy ISP says the settings are correct.
So this is going nowhere fast. Thanks for your braintime. This issue might as well be closed, no solution in sight, money gone.
Wordpress does this very well by the way. Already installed one site with it.
Cheers,
Frank
Comment #7
jchatard commentedOk...