access restricted - security rule - updating views

  • Posts: 195
  • Thank you received: 5
  • Hikashop Business
9 years 5 months ago #203492

-- HikaShop version -- : 2.4.0
-- Joomla version -- : 3.4.1
-- PHP version -- : 5.4.40
-- Browser(s) name and version -- : FF
-- Error-message(debug-mod must be tuned on) -- : The page you are trying to access is restricted due to a security rule.

When trying to update any of the views in order to customize them, we're getting the following error:

The page you are trying to access is restricted due to a security rule.

If you believe the security rule is affecting the normal operation of your website, contact your host support team and provide detailed instructions how to recreate this error.
They will be able to assist you with rectifying the problem and adjusting the security configuration if needed.


The url for the page is:
administrator/index.php?option=com_hikashop&ctrl=view&task=edit&id=0|t3_blank|component|com_hikashop|cart|sendcart.php

The page is just a light blue page, with a white box and the text above in blue (no template applied to the page).

This is happening with multiple user access (including super admin access).

I'm also getting an error (with Firebug):

"NetworkError: 400 Bad Request - http:// ... /administrator/index.php?option=com_hikashop&ctrl=view&task=edit&id=0|purity_iii|component|com_hikashop|checkout|end%2Ephp"

(similar error on all the other view pages, just changing the specific file name at the end)

We do have Aeekba Admin Tools installed (including htaccess rules); however, I couldn't find any notes anywhere here (or on akeeba site) that indicated any compatability (or special configuration required) between the 2 extensions.

Also, this was working fine a few versions (of HS) before.

Any ideas what might be happening?

Please Log in or Create an account to join the conversation.

  • Posts: 26159
  • Thank you received: 4028
  • MODERATOR
9 years 5 months ago #203496

Hi,

Because your posting a view content, it contains some PHP code and it's possible that you have some security checks which refuse the content due to that PHP content submitted.

Regards,


Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Also helping the HikaShop support team when having some time or couldn't sleep.
By the way, do not send me private message, use the "contact us" form instead.
The following user(s) said Thank You: cpaschen

Please Log in or Create an account to join the conversation.

  • Posts: 195
  • Thank you received: 5
  • Hikashop Business
9 years 5 months ago #203844

After doing some additional digging with our hosting company we found that this was being caused by a mod_security rule that was triggered (based on some excessive traffic to the site). So it had nothing to do with HikaShop.

Please Log in or Create an account to join the conversation.

  • Posts: 36
  • Thank you received: 1
8 years 6 months ago #239744

I had this same issue and submitted a ticket with Site Ground. The support they provide is outstanding.
Here's the response:
...
I have carefully investigated your request and noticed that your IP address has triggered one of the mod_security rules installed on the server. I have disabled the particular rule by adding directives in the .htaccess file located in the administrator/ directory. The component is once again working as expected.
...

Thought I would share in case anyone else is on Site Ground with the same issue. My Site Ground Support ticket #: 1731238

The following user(s) said Thank You: nicolas

Please Log in or Create an account to join the conversation.

  • Posts: 195
  • Thank you received: 5
  • Hikashop Business
8 years 6 months ago #239838

Yes, if you have SiteGround hosting and have 'strange' things like this happen, always consider that SiteGround has all sorts of 'stuff' that they have running that may be effecting how your site performs (or doesn't in this case).
[This is why we finally left SiteGround.]

Please Log in or Create an account to join the conversation.

  • Posts: 4
  • Thank you received: 0
  • Hikamarket Multivendor Hikashop Business
7 years 9 months ago #263715

I had the same problem and told SiteGound about the ticket you referenced. They said it was a great help in resolving my problem. Many thanks for sharing it! Best regards, Jim

Please Log in or Create an account to join the conversation.

  • Posts: 26159
  • Thank you received: 4028
  • MODERATOR
7 years 8 months ago #263716

Hi,

Two weeks ago, I submitted some modifications which will be available in HikaShop 3.0.1 ; these modifications should allow to avoid the problem regarding the mod_security rule.
I was not able to test it in a lot of servers but I good faith that it targeting the right element.

Regards,


Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Also helping the HikaShop support team when having some time or couldn't sleep.
By the way, do not send me private message, use the "contact us" form instead.

Please Log in or Create an account to join the conversation.

Time to create page: 0.074 seconds
Powered by Kunena Forum