No more permissions – what happened
Quote from klwild on September 2, 2024, 10:50 amFor a few days now I’ve been getting the error message like the screenshot when I want to create a post
Something happened, but I don’t know what it could be.
Can anyone help? Klaus Wilde
For a few days now I’ve been getting the error message like the screenshot when I want to create a post
Something happened, but I don’t know what it could be.
Can anyone help? Klaus Wilde
Quote from Yworld on September 2, 2024, 12:04 pmHello @klwild
Look in the server error log to see what is written there at the time the topic was created. Remember what was updated or added from the plugins before the error occurred.
Hello @klwild
Look in the server error log to see what is written there at the time the topic was created. Remember what was updated or added from the plugins before the error occurred.
Quote from klwild on September 3, 2024, 1:43 pmNow that’s stupid!
I couldn’t find anything in the log and sometimes it works and sometimes it doesn’t!
It’s all so unstable.
Klaus
Now that’s stupid!
I couldn’t find anything in the log and sometimes it works and sometimes it doesn’t!
It’s all so unstable.
Klaus
Quote from klwild on September 4, 2024, 1:32 pmI found this in the error.log:
[Wed Sep 04 13:24:07.224530 2024] [:error] [pid 2479749] [client 119.203.190.177:0] [client 119.203.190.177] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDVxT554VzMPxWT3DqwAAAAG8”]
[Wed Sep 04 13:24:10.172252 2024] [:error] [pid 2561729] [client 120.202.162.222:0] [client 120.202.162.222] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDWs9y9sa-v@qdkt2MZQAAAJc”]
[Wed Sep 04 13:24:13.556435 2024] [:error] [pid 2580260] [client 172.105.0.235:0] [client 172.105.0.235] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDXc5eEcYzw1F12lEymAAAAFY”]
[Wed Sep 04 13:24:15.275676 2024] [:error] [pid 2593770] [client 43.134.224.168:0] [client 43.134.224.168] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDX0ykJpBDLdl6X1Q6qwAAAJg”]
[Wed Sep 04 13:24:37.292491 2024] [:error] [pid 2589881] [client 183.134.101.182:0] [client 183.134.101.182] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDdX@FhQ7PXZshIF7XDQAAAEI”]
[Wed Sep 04 13:24:40.199001 2024] [:error] [pid 2581742] [client 121.170.174.109:0] [client 121.170.174.109] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDeONkSQR23TRfCk7a0QAAAI4”]
[Wed Sep 04 13:24:59.580601 2024] [:error] [pid 2555483] [client 192.111.134.10:0] [client 192.111.134.10] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDi6cUC2ZsPKZRCpd0mQAAACc”]
[Wed Sep 04 13:25:01.863575 2024] [:error] [pid 2574181] [client 103.175.14.183:0] [client 103.175.14.183] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDjX4nv08Abt571H6ujQAAAJk”]
[Wed Sep 04 13:25:13.807556 2024] [:error] [pid 2594149] [client 66.42.224.229:0] [client 66.42.224.229] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDmf7LUbamlyYkwEq88QAAAG4”]
I found this in the error.log:
[Wed Sep 04 13:24:07.224530 2024] [:error] [pid 2479749] [client 119.203.190.177:0] [client 119.203.190.177] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDVxT554VzMPxWT3DqwAAAAG8”]
[Wed Sep 04 13:24:10.172252 2024] [:error] [pid 2561729] [client 120.202.162.222:0] [client 120.202.162.222] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDWs9y9sa-v@qdkt2MZQAAAJc”]
[Wed Sep 04 13:24:13.556435 2024] [:error] [pid 2580260] [client 172.105.0.235:0] [client 172.105.0.235] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDXc5eEcYzw1F12lEymAAAAFY”]
[Wed Sep 04 13:24:15.275676 2024] [:error] [pid 2593770] [client 43.134.224.168:0] [client 43.134.224.168] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDX0ykJpBDLdl6X1Q6qwAAAJg”]
[Wed Sep 04 13:24:37.292491 2024] [:error] [pid 2589881] [client 183.134.101.182:0] [client 183.134.101.182] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDdX@FhQ7PXZshIF7XDQAAAEI”]
[Wed Sep 04 13:24:40.199001 2024] [:error] [pid 2581742] [client 121.170.174.109:0] [client 121.170.174.109] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDeONkSQR23TRfCk7a0QAAAI4”]
[Wed Sep 04 13:24:59.580601 2024] [:error] [pid 2555483] [client 192.111.134.10:0] [client 192.111.134.10] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDi6cUC2ZsPKZRCpd0mQAAACc”]
[Wed Sep 04 13:25:01.863575 2024] [:error] [pid 2574181] [client 103.175.14.183:0] [client 103.175.14.183] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDjX4nv08Abt571H6ujQAAAJk”]
[Wed Sep 04 13:25:13.807556 2024] [:error] [pid 2594149] [client 66.42.224.229:0] [client 66.42.224.229] ModSecurity: Access denied with code 510 (phase 1). Match of “rx ^0$” against “REQUEST_HEADERS:Content-Length” required. [file “/usr/share/modsecurity-crs/activated_rules/modsecurity_crs_21_protocol_anomalies.conf”] [line “84”] [id “960904”] [rev “2”] [msg “Request Containing Content, but Missing Content-Type header”] [severity “NOTICE”] [ver “OWASP_CRS/2.2.9”] [maturity “9”] [accuracy “9”] [hostname “mecker-ecke.com”] [uri “/xmlrpc.php”] [unique_id “ZthDmf7LUbamlyYkwEq88QAAAG4”]
Quote from Yworld on September 5, 2024, 10:54 amThis does not apply to the forum. Attempts to hack your site or errors in some settings. You can find out from the host.
See what errors occur when creating a message in the browser console – console option. Conflicts and other problems may arise…
This does not apply to the forum. Attempts to hack your site or errors in some settings. You can find out from the host.
See what errors occur when creating a message in the browser console – console option. Conflicts and other problems may arise…
Quote from klwild on September 5, 2024, 10:16 pmNo. I think it’s because of the ASGAROS forum!
I activated the health check and only activated the ASGAROS forum (of course I had to), changed the topic and deleted cookies and browser data as usual, but the same error always occurred, even though I tested everything with a new user.
You can create a new account and try if you want to create a post
What else can I do to fix the error?
Klaus Wilde
No. I think it’s because of the ASGAROS forum!
I activated the health check and only activated the ASGAROS forum (of course I had to), changed the topic and deleted cookies and browser data as usual, but the same error always occurred, even though I tested everything with a new user.
You can create a new account and try if you want to create a post
What else can I do to fix the error?
Klaus Wilde
Quote from Yworld on September 6, 2024, 10:10 amYou have errors with tooltips and other popups on all your pages. Fix and check. I don’t see any other errors yet.
Check with your host regarding the error described by modsecurity. It may make sense to downgrade the module.
If the hoster has not installed protection against this method, you can try disabling the mod_security module for a while. Enter in .htaccess:
<IfModule mod_security.c> SecFilterEngine Off SecFilterScanPOST Off </IfModule>
Check and don’t forget to remove it, even if it works and the error disappears, describe the situation to the host.
You have errors with tooltips and other popups on all your pages. Fix and check. I don’t see any other errors yet.
Check with your host regarding the error described by modsecurity. It may make sense to downgrade the module.
If the hoster has not installed protection against this method, you can try disabling the mod_security module for a while. Enter in .htaccess:
<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
</IfModule>
Check and don’t forget to remove it, even if it works and the error disappears, describe the situation to the host.
Uploaded files:Quote from klwild on September 6, 2024, 12:39 pmThanks for your answer @yworld.
I tried this with htaccess, but there were no changes.
How does the first error in the screenshot (Syntax Error missing) come about? I can’t reproduce it.
I tried PHP Debug without success, and the server logs don’t say anything clever either.
In the WP Health-Check I deactivated everything and only activated the ASGAROS forum. The same error. Finally, I tried another theme, which also showed the same error.
What else can I try?
Thank you for your efforts Klaus
Thanks for your answer @yworld.
I tried this with htaccess, but there were no changes.
How does the first error in the screenshot (Syntax Error missing) come about? I can’t reproduce it.
I tried PHP Debug without success, and the server logs don’t say anything clever either.
In the WP Health-Check I deactivated everything and only activated the ASGAROS forum. The same error. Finally, I tried another theme, which also showed the same error.
What else can I try?
Thank you for your efforts Klaus
Quote from Yworld on September 6, 2024, 12:48 pm@klwild, Option – in the main site settings, go to the permanent links item and click save.
@klwild, Option – in the main site settings, go to the permanent links item and click save.