mod_security: Access denied with code 400
Form sessions are intermittently disconnected. The problem traced to the error in OHS errror_log:
[Mon Nov 4 10:32:18 2013] [error] [client 10.16.7.231] mod_security: Access denied with code 400. Pattern match "\\.\\./" at POST_PAYLOAD. [hostname "rbalive.rbauction.com"] [uri "/forms/lservlet;jsessionid=51f4f1f3e503b8ae98c04ac3c23e9c5493969f4ebbef7d937c2efbb96e442577.e38Oax0RbheKbi0RahiPaxmNa350"] [unique_id UnfoMgoQQa4AAHccRbg]
The problem happens 1-2 times during business day.
[Mon Nov 4 10:32:18 2013] [error] [client 10.16.7.231] mod_security: Access denied with code 400. Pattern match "\\.\\./" at POST_PAYLOAD. [hostname "rbalive.rbauction.com"] [uri "/forms/lservlet;jsessionid=51f4f1f3e503b8ae98c04ac3c23e9c5493969f4ebbef7d937c2efbb96e442577.e38Oax0RbheKbi0RahiPaxmNa350"] [unique_id UnfoMgoQQa4AAHccRbg]
The problem happens 1-2 times during business day.
Keep in mind the problem occurs in forms session .
Any suggestions.
Thanks
Malcolm
Tagged:
0