HTTP Response Splitting Attack – Access Denied
-
Hello,
I am using mod_secure with my Apache server, and configured with the OWSA rules. When I go to Abandoned Carts –> Email Templates —> and Edit my Email template -> Update Changes, I get error 400. Log shows the following message:
ModSecurity: Access denied with code 400 (phase 2). Pattern match “(?:\\bhttp\\/(?:0\\.9|1\\.[01])|<(?:html|meta)\\b)” at ARGS:woocommerce_ac_email_body. [file “/etc/httpd/modsecurity.d/modsecurity_crs_40_generic_attacks.conf”] [line “213”] [id “950911”] [msg “HTTP Response Splitting Attack”] [data “<html”] [severity “ALERT”] [hostname “XXXXXXXX.com”] [uri “/wp-admin/admin.php”] [unique_id “XXXXXXXXXXXXXXXXX”]
For some reason mod_secure it thinking that this is a split html attack, any help?
Thanks
The topic ‘HTTP Response Splitting Attack – Access Denied’ is closed to new replies.