• Resolved alecsatin

    (@alecsatin)


    Hi,
    I’ve been using Simple Security Firewall for many months now. It’s been a reliable and excellent plugin.

    Yesterday for the first time it hiccuped. Auto-updating of this plugin only is enabled. So I have to assume it’s something in this plugin that has changed. I haven’t made any changes in any other WordPress or plugin settings.

    From the edit post page, I copied and pasted updated text into the “text” text-box. When I pressed update, I was presented with this error message:

    You were blocked by the WordPress Security Firewall. Something in the URL, Form or Cookie data wasn’t appropriate.

    Warning – You have 1 remaining transgression(s) against this site and then you will be black listed.
    Seriously, stop repeating what you are doing or you will be locked out.

    For now, I’ve whitelisted my IP. I don’t like this option.

    Any idea on what is being checked/ what has changed in the plugin?

    Thank you.
    Alec

    P.S. Here is the entry from the Audit Log:

    11:15 am 03 Nov 2015 firewall block Page parameter failed firewall check. The offending parameter was “excerpt” with a value of “

    https://ww.wp.xz.cn/plugins/wp-simple-firewall/

Viewing 9 replies - 1 through 9 (of 9 total)
  • Plugin Author Paul

    (@paultgoodchild)

    Can you check the text that is in the excerpt box please for that post? I doubt it’s actually empty and something in there I think…

    Thread Starter alecsatin

    (@alecsatin)

    One possibility – the excerpts are almost always custom crafted and differ slightly from the main text.

    Plugin Author Paul

    (@paultgoodchild)

    Yea, I’d like to know the content for the excerpt for the post that’s being blocked. And is this happening when saving other posts and pages?

    Thread Starter alecsatin

    (@alecsatin)

    Yes, the excerpt box is populated.

    Thread Starter alecsatin

    (@alecsatin)

    Here it is:

    I’ve spent time yesterday and today reading some of the hushed-over events happening in my church denomination. The conflicts are both doctrinal and cultural. The doctrinal issues include Justification by Faith and Scriptural preservation. The cultural issues include the existence of a Brahmin caste, a tendency to follow tradition over Scripture, and a covering over of serious crimes. All of this makes me nervous and uncomfortable. I can not longer overlook these things. […]

    Plugin Author Paul

    (@paultgoodchild)

    I think the word “include” is being picked up in the PHP Code firewall filter. πŸ™‚

    Thread Starter alecsatin

    (@alecsatin)

    Yes, it was “include” in the excerpt. Excellent help most appreciated. All is working well now. Great plugin.

    Plugin Author Paul

    (@paultgoodchild)

    Great! Glad it helped… I’ve reviewed the code that matches on that and I may tweak it a little, but it’s tricky to get it right and working for all legitimate cases..

    Thread Starter alecsatin

    (@alecsatin)

    It’s better to be more protective than less. Now that I know about “include”, I can work around it.

    Alec

Viewing 9 replies - 1 through 9 (of 9 total)

The topic ‘New issue has developed when editing posts’ is closed to new replies.