Author Topic: False-Positive report thread  (Read 37794 times)

Offline Cwaf_Team

  • Moderator
  • Comodo's Hero
  • *****
  • Posts: 211
Re: False-Positive report thread
« Reply #240 on: October 26, 2018, 05:08:18 AM »
225170: WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)

Request:   GET /folder/wp-json/wp/v2/users/?who=authors&per_page=-1
Action Description:   Access denied with code 403 (phase 2).
Justification:   Test '&REQUEST_COOKIES_NAMES:/^wordpress_([0-9a-fA-f]{32})$/' again st '![at]ge 1' is true.

This rule does happen on all WP installations with Gutenberg editor that will become default soon.

Not confirmed. Please share audit.log for this event. Thank you.

Offline Ansari_WAF

  • Newbie
  • *
  • Posts: 6
Re: False-Positive report thread
« Reply #241 on: November 20, 2018, 08:38:54 AM »
Rule 217280

WordPress 4.9.8
Plugin: Contact Form 7

Unable to save form in back-end if text on form includes keywords such as "head".

Log is attached

Further information not provided by hosting service.

log from andypatnz received on 20 nov 2018

You have just been sent a personal message by andypatnz on The Comodo Forum.

IMPORTANT: Remember, this is just a notification. Please do not reply to this email.

The message they sent you was:

I have finally got a log for this problem. I hope that this is what you were expecting.

Reply to this Personal Message here: https://forums.comodo.com/index.php?action=pm;sa=send;f=inbox;pmsg=105308;quote;u=738040

----

Hi
 We have fixed and it will be available on coming release.


Offline k2host

  • Newbie
  • *
  • Posts: 2
Re: False-Positive report thread
« Reply #242 on: February 06, 2019, 10:34:37 AM »
1. Rule ID: 211090

2. Versions:
Current rules version   1.196 (Latest version)
CWAF plugin version   2.24.3 (Latest version)

3.:
Code: [Select]
--80860430-A--
[06/Feb/2019:13:04:25 --0200] XFr3eN7aGDb0[at]BZw7OtwJwAAAkI 179.111.172.151 57472 98.142.105.99 443
--80860430-B--
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.afrecasp.com.br
Connection: keep-alive
Content-Length: 13977
Accept: */*
Origin: https://www.afrecasp.com.br
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Referer: https://www.afrecasp.com.br/wp-admin/post.php?post=544&action=elementor
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9,pt;q=0.8
Cookie: wordpress_sec_c57e3293a5ecc3de3505a05947321853=admin%7C1549573478%7CoVoRzk6t8iLwHyePIqnCH8Z4kN7Xc9gNGn4d81Fz8TE%7Cf8d1cdbf4bb1f652b74dc337cb2137d05ddbadec3cb8ff24f04bf6be669260ed; _ga=GA1.3.1493656263.1548024440; _gid=GA1.3.2001077342.1549400657; wordpress_test_cookie=WP+Cookie+check; wordpress_logged_in_c57e3293a5ecc3de3505a05947321853=admin%7C1549573478%7CoVoRzk6t8iLwHyePIqnCH8Z4kN7Xc9gNGn4d81Fz8TE%7C75a5dd11826d2ecaf0104fcbe80172da3641c06ab288ee04b843e3e3315015ea; wp-settings-time-1=1549401167; wp-settings-1=libraryContent%3Dbrowse%26editor%3Dtinymce%26hidetb%3D1%26advImgDetails%3Dshow; wfwaf-authcookie-a4e7047f40be509f09ace58f8afadeb3=1%7Cadministrator%7Cc70b25bc621a34561d0d8f171df031632186626c2c38bf86afadb973759117e0

--80860430-C--
actions=%7B%22c53%22%3A%7B%22action%22%3A%22render_widget%22%2C%22data%22%3A%7B%22data%22%3A%7B%22id%22%3A%22333d695%22%2C%22elType%22%3A%22widget%22%2C%22isInner%22%3Afalse%2C%22settings%22%3A%7B%22html%22%3A%22%3Chtml%3E%5Cr%5Cn%3Cbody%3E%5Cr%5Cn%5Cr%5Cn%3Ch4%3EPartida%3C%2Fh4%3E%5Cr%5Cn%3Ctable%3E%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A35%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.+John+Boyd+Dunlop+%2F+McDonalds+%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.John+Boyd+Dunlop+x+Av+Bar%C3%A3o+de+Monte+Alegre%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Bar%C3%A3o+de+Monte+Alegre+X+Rua+Alberto+Sarmento++(Receita+Federal)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A45%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERua+Orlando+Carpino+X++Av.+Andrade+Neves%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Andrade+Neves+(Posto+Ipiranga)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A50%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Orozimbo+Maia+X+Rua+Delfino+Cintra%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A53%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Moraes+Salles+X+Av.Glicerio+(Bradesco)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A57%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Moraes+Salles+X+Rua+Coronel+Quirino+(Pto+de+onibus+Coronel+Quirino)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A58%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Aquidab%C3%A3+x+Rua+Boaventura+do+Amaral%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A00%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Aquidab%C3%A3++(Lgo+do+Para+-+Cx+Economica+Federal)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A02%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Aquidab%C3%A3+X+Rua+Marechal+Carmona++(pto+de+onibus)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A03%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.+Aquidab%C3%A3+x+Av+Prestes+Maia+(Farol)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A05%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.+Prestes+Maia+-+Trevo%2C+via+expressa%2C+ap%C3%B3s+a+passarela++(atraz+da+casinha+azul)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A10%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+(Pto+de+onibus+Swiss+Park)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A15%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Vinhedo++(Pto+de+onibus+Capela+)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A20%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Louveira+(Pto+de+onibus+da+passarela+Frango+assado)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A25%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Videira+(Pto+de+Onibus)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A30%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Jundiai+(Pto+de+Onibus)+passarela+Carrefour+KM+61%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+x+Rod+Bandeirantes%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A40%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros++(Ponte+Cidade+Jardim+-Esta%C3%A7%C3%A3o+Cidade+Jardim+)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A45%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+-+Shopping+Eldorado%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A50%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+-+Esta%C3%A7%C3%A3o+Pinheiros+-+Editora+Abril+%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A53%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+-+Shopping+Villa+Lobos%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+x+Rua+Queiroz+Filho%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERua+Queiroz+Filho+x+Rua+Gast%C3%A3o+Vidigal+(COBASI)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E08%3A00%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Gast%C3%A3o+Vidigal++-++CEAGESP+-+CASP+(Bradesco)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%5Cr%5Cn+%3C%2Ftable%3E%5Cr%5Cn%5Cr%5Cn%22%2C%22_title%22%3A%22%22%2C%22_margin%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_margin_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_margin_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_padding%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_padding_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_padding_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_z_index%22%3A%22%22%2C%22_animation%22%3A%22%22%2C%22animation_duration%22%3A%22%22%2C%22_animation_delay%22%3A%22%22%2C%22_element_id%22%3A%22%22%2C%22_css_classes%22%3A%22%22%2C%22sticky%22%3A%22%22%2C%22sticky_on%22%3A%5B%22desktop%22%2C%22tablet%22%2C%22mobile%22%5D%2C%22sticky_offset%22%3A0%2C%22sticky_effects_offset%22%3A0%2C%22sticky_parent%22%3A%22%22%2C%22_background_background%22%3A%22%22%2C%22_background_color%22%3A%22%22%2C%22_background_color_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A0%7D%2C%22_background_color_b%22%3A%22%23f2295b%22%2C%22_background_color_b_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_gradient_type%22%3A%22linear%22%2C%22_background_gradient_angle%22%3A%7B%22unit%22%3A%22deg%22%2C%22size%22%3A180%7D%2C%22_background_gradient_position%22%3A%22center+center%22%2C%22_background_image%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_image_tablet%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_image_mobile%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_position%22%3A%22%22%2C%22_background_position_tablet%22%3A%22%22%2C%22_background_position_mobile%22%3A%22%22%2C%22_background_xpos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_xpos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_xpos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_ypos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_ypos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_ypos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_attachment%22%3A%22%22%2C%22_background_repeat%22%3A%22%22%2C%22_background_repeat_tablet%22%3A%22%22%2C%22_background_repeat_mobile%22%3A%22%22%2C%22_background_size%22%3A%22%22%2C%22_background_size_tablet%22%3A%22%22%2C%22_background_size_mobile%22%3A%22%22%2C%22_background_bg_width%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_bg_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_bg_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_video_link%22%3A%22%22%2C%22_background_video_start%22%3A%22%22%2C%22_background_video_end%22%3A%22%22%2C%22_background_video_fallback%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_background%22%3A%22%22%2C%22_background_hover_color%22%3A%22%22%2C%22_background_hover_color_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A0%7D%2C%22_background_hover_color_b%22%3A%22%23f2295b%22%2C%22_background_hover_color_b_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_hover_gradient_type%22%3A%22linear%22%2C%22_background_hover_gradient_angle%22%3A%7B%22unit%22%3A%22deg%22%2C%22size%22%3A180%7D%2C%22_background_hover_gradient_position%22%3A%22center+center%22%2C%22_background_hover_image%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_image_tablet%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_image_mobile%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_position%22%3A%22%22%2C%22_background_hover_position_tablet%22%3A%22%22%2C%22_background_hover_position_mobile%22%3A%22%22%2C%22_background_hover_xpos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_xpos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_xpos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_ypos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_ypos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_ypos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_attachment%22%3A%22%22%2C%22_background_hover_repeat%22%3A%22%22%2C%22_background_hover_repeat_tablet%22%3A%22%22%2C%22_background_hover_repeat_mobile%22%3A%22%22%2C%22_background_hover_size%22%3A%22%22%2C%22_background_hover_size_tablet%22%3A%22%22%2C%22_background_hover_size_mobile%22%3A%22%22%2C%22_background_hover_bg_width%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_hover_bg_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_hover_bg_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_hover_video_link%22%3A%22%22%2C%22_background_hover_video_start%22%3A%22%22%2C%22_background_hover_video_end%22%3A%22%22%2C%22_background_hover_video_fallback%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_transition%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_border_border%22%3A%22%22%2C%22_border_width%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_color%22%3A%22%22%2C%22_border_radius%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_box_shadow_box_shadow_type%22%3A%22%22%2C%22_box_shadow_box_shadow%22%3A%7B%22horizontal%22%3A0%2C%22vertical%22%3A0%2C%22blur%22%3A10%2C%22spread%22%3A0%2C%22color%22%3A%22rgba(0%2C0%2C0%2C0.5)%22%7D%2C%22_box_shadow_box_shadow_position%22%3A%22+%22%2C%22_border_hover_border%22%3A%22%22%2C%22_border_hover_width%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_hover_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_hover_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_hover_color%22%3A%22%22%2C%22_border_radius_hover%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_hover_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_hover_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_box_shadow_hover_box_shadow_type%22%3A%22%22%2C%22_box_shadow_hover_box_shadow%22%3A%7B%22horizontal%22%3A0%2C%22vertical%22%3A0%2C%22blur%22%3A10%2C%22spread%22%3A0%2C%22color%22%3A%22rgba(0%2C0%2C0%2C0.5)%22%7D%2C%22_box_shadow_hover_box_shadow_position%22%3A%22+%22%2C%22_border_hover_transition%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22hide_desktop%22%3A%22%22%2C%22hide_tablet%22%3A%22%22%2C%22hide_mobile%22%3A%22%22%2C%22_attributes%22%3A%22%22%2C%22custom_css%22%3A%22%22%7D%2C%22defaultEditSettings%22%3A%7B%7D%2C%22elements%22%3A%5B%5D%2C%22widgetType%22%3A%22html%22%2C%22editSettings%22%3A%7B%7D%7D%7D%7D%7D&_nonce=b346badb4d&editor_post_id=544&action=elementor_ajax
--80860430-F--
HTTP/1.1 403 Forbidden
Content-Length: 232
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

--80860430-E--

--80860430-H--
Message: Access denied with code 403 (phase 2). Match of "endsWith /sysext/install/start/install.php" against "REQUEST_FILENAME" required. [file "/var/cpanel/cwaf/rules/10_HTTP_HTTP.conf"] [line "40"] [id "211090"] [rev "2"] [msg "COMODO WAF: HTTP Response Splitting Attack||www.afrecasp.com.br|F|2"] [data "Matched Data: <html found within REQUEST_FILENAME: /wp-admin/admin-ajax.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"]
Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 179.111.172.151] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /sysext/install/start/install.php" against "REQUEST_FILENAME" required. [file "/var/cpanel/cwaf/rules/10_HTTP_HTTP.conf"] [line "40"] [id "211090"] [rev "2"] [msg "COMODO WAF: HTTP Response Splitting Attack||www.afrecasp.com.br|F|2"] [data "Matched Data: <html found within REQUEST_FILENAME: /wp-admin/admin-ajax.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.afrecasp.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "XFr3eN7aGDb0[at]BZw7OtwJwAAAkI"]
Action: Intercepted (phase 2)
Apache-Handler: application/x-httpd-lsphp
Stopwatch: 1549465464896542 460160 (- - -)
Stopwatch2: 1549465464896542 460160; combined=634379, p1=692, p2=3768, p3=0, p4=0, p5=315098, sr=96, sw=80, l=0, gc=314741
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.2 (http://www.modsecurity.org/); CWAF_Apache.
Server: Apache
WebApp-Info: "default" "c57e3293a5ecc3de3505a05947321853" "-"
Engine-Mode: "ENABLED"

--80860430-Z--
« Last Edit: February 06, 2019, 10:38:57 AM by k2host »

Offline Ansari_WAF

  • Newbie
  • *
  • Posts: 6
Re: False-Positive report thread
« Reply #243 on: February 07, 2019, 05:18:29 AM »
Hi k2host
 Thanks for contacting Us. We are working on this.

1. Rule ID: 211090

2. Versions:
Current rules version   1.196 (Latest version)
CWAF plugin version   2.24.3 (Latest version)

3.:
Code: [Select]
--80860430-A--
[06/Feb/2019:13:04:25 --0200] XFr3eN7aGDb0[at]BZw7OtwJwAAAkI 179.111.172.151 57472 98.142.105.99 443
--80860430-B--
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.afrecasp.com.br
Connection: keep-alive
Content-Length: 13977
Accept: */*
Origin: https://www.afrecasp.com.br
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Referer: https://www.afrecasp.com.br/wp-admin/post.php?post=544&action=elementor
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9,pt;q=0.8
Cookie: wordpress_sec_c57e3293a5ecc3de3505a05947321853=admin%7C1549573478%7CoVoRzk6t8iLwHyePIqnCH8Z4kN7Xc9gNGn4d81Fz8TE%7Cf8d1cdbf4bb1f652b74dc337cb2137d05ddbadec3cb8ff24f04bf6be669260ed; _ga=GA1.3.1493656263.1548024440; _gid=GA1.3.2001077342.1549400657; wordpress_test_cookie=WP+Cookie+check; wordpress_logged_in_c57e3293a5ecc3de3505a05947321853=admin%7C1549573478%7CoVoRzk6t8iLwHyePIqnCH8Z4kN7Xc9gNGn4d81Fz8TE%7C75a5dd11826d2ecaf0104fcbe80172da3641c06ab288ee04b843e3e3315015ea; wp-settings-time-1=1549401167; wp-settings-1=libraryContent%3Dbrowse%26editor%3Dtinymce%26hidetb%3D1%26advImgDetails%3Dshow; wfwaf-authcookie-a4e7047f40be509f09ace58f8afadeb3=1%7Cadministrator%7Cc70b25bc621a34561d0d8f171df031632186626c2c38bf86afadb973759117e0

--80860430-C--
actions=%7B%22c53%22%3A%7B%22action%22%3A%22render_widget%22%2C%22data%22%3A%7B%22data%22%3A%7B%22id%22%3A%22333d695%22%2C%22elType%22%3A%22widget%22%2C%22isInner%22%3Afalse%2C%22settings%22%3A%7B%22html%22%3A%22%3Chtml%3E%5Cr%5Cn%3Cbody%3E%5Cr%5Cn%5Cr%5Cn%3Ch4%3EPartida%3C%2Fh4%3E%5Cr%5Cn%3Ctable%3E%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A35%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.+John+Boyd+Dunlop+%2F+McDonalds+%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.John+Boyd+Dunlop+x+Av+Bar%C3%A3o+de+Monte+Alegre%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Bar%C3%A3o+de+Monte+Alegre+X+Rua+Alberto+Sarmento++(Receita+Federal)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A45%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERua+Orlando+Carpino+X++Av.+Andrade+Neves%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Andrade+Neves+(Posto+Ipiranga)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A50%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Orozimbo+Maia+X+Rua+Delfino+Cintra%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A53%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Moraes+Salles+X+Av.Glicerio+(Bradesco)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A57%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Moraes+Salles+X+Rua+Coronel+Quirino+(Pto+de+onibus+Coronel+Quirino)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E05%3A58%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Aquidab%C3%A3+x+Rua+Boaventura+do+Amaral%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A00%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Aquidab%C3%A3++(Lgo+do+Para+-+Cx+Economica+Federal)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A02%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Aquidab%C3%A3+X+Rua+Marechal+Carmona++(pto+de+onibus)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A03%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.+Aquidab%C3%A3+x+Av+Prestes+Maia+(Farol)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A05%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.+Prestes+Maia+-+Trevo%2C+via+expressa%2C+ap%C3%B3s+a+passarela++(atraz+da+casinha+azul)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A10%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+(Pto+de+onibus+Swiss+Park)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A15%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Vinhedo++(Pto+de+onibus+Capela+)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A20%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Louveira+(Pto+de+onibus+da+passarela+Frango+assado)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A25%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Videira+(Pto+de+Onibus)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E06%3A30%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+-+Jundiai+(Pto+de+Onibus)+passarela+Carrefour+KM+61%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERodovia+Anhanguera+x+Rod+Bandeirantes%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A40%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros++(Ponte+Cidade+Jardim+-Esta%C3%A7%C3%A3o+Cidade+Jardim+)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A45%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+-+Shopping+Eldorado%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A50%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+-+Esta%C3%A7%C3%A3o+Pinheiros+-+Editora+Abril+%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E07%3A53%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+-+Shopping+Villa+Lobos%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EMarginal+Pinheiros+x+Rua+Queiroz+Filho%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E+%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3ERua+Queiroz+Filho+x+Rua+Gast%C3%A3o+Vidigal+(COBASI)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%3Ctr%3E%5Cr%5Cn++%3Ctd%3E08%3A00%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+++%3Ctd%3EAv.Gast%C3%A3o+Vidigal++-++CEAGESP+-+CASP+(Bradesco)%5Cr%5Cn%3C%2Ftd%3E%5Cr%5Cn+%3C%2Ftr%3E%5Cr%5Cn+%5Cr%5Cn%5Cr%5Cn+%3C%2Ftable%3E%5Cr%5Cn%5Cr%5Cn%22%2C%22_title%22%3A%22%22%2C%22_margin%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_margin_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_margin_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_padding%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_padding_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_padding_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_z_index%22%3A%22%22%2C%22_animation%22%3A%22%22%2C%22animation_duration%22%3A%22%22%2C%22_animation_delay%22%3A%22%22%2C%22_element_id%22%3A%22%22%2C%22_css_classes%22%3A%22%22%2C%22sticky%22%3A%22%22%2C%22sticky_on%22%3A%5B%22desktop%22%2C%22tablet%22%2C%22mobile%22%5D%2C%22sticky_offset%22%3A0%2C%22sticky_effects_offset%22%3A0%2C%22sticky_parent%22%3A%22%22%2C%22_background_background%22%3A%22%22%2C%22_background_color%22%3A%22%22%2C%22_background_color_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A0%7D%2C%22_background_color_b%22%3A%22%23f2295b%22%2C%22_background_color_b_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_gradient_type%22%3A%22linear%22%2C%22_background_gradient_angle%22%3A%7B%22unit%22%3A%22deg%22%2C%22size%22%3A180%7D%2C%22_background_gradient_position%22%3A%22center+center%22%2C%22_background_image%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_image_tablet%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_image_mobile%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_position%22%3A%22%22%2C%22_background_position_tablet%22%3A%22%22%2C%22_background_position_mobile%22%3A%22%22%2C%22_background_xpos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_xpos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_xpos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_ypos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_ypos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_ypos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_attachment%22%3A%22%22%2C%22_background_repeat%22%3A%22%22%2C%22_background_repeat_tablet%22%3A%22%22%2C%22_background_repeat_mobile%22%3A%22%22%2C%22_background_size%22%3A%22%22%2C%22_background_size_tablet%22%3A%22%22%2C%22_background_size_mobile%22%3A%22%22%2C%22_background_bg_width%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_bg_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_bg_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_video_link%22%3A%22%22%2C%22_background_video_start%22%3A%22%22%2C%22_background_video_end%22%3A%22%22%2C%22_background_video_fallback%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_background%22%3A%22%22%2C%22_background_hover_color%22%3A%22%22%2C%22_background_hover_color_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A0%7D%2C%22_background_hover_color_b%22%3A%22%23f2295b%22%2C%22_background_hover_color_b_stop%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_hover_gradient_type%22%3A%22linear%22%2C%22_background_hover_gradient_angle%22%3A%7B%22unit%22%3A%22deg%22%2C%22size%22%3A180%7D%2C%22_background_hover_gradient_position%22%3A%22center+center%22%2C%22_background_hover_image%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_image_tablet%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_image_mobile%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_position%22%3A%22%22%2C%22_background_hover_position_tablet%22%3A%22%22%2C%22_background_hover_position_mobile%22%3A%22%22%2C%22_background_hover_xpos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_xpos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_xpos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_ypos%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_ypos_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_ypos_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A0%7D%2C%22_background_hover_attachment%22%3A%22%22%2C%22_background_hover_repeat%22%3A%22%22%2C%22_background_hover_repeat_tablet%22%3A%22%22%2C%22_background_hover_repeat_mobile%22%3A%22%22%2C%22_background_hover_size%22%3A%22%22%2C%22_background_hover_size_tablet%22%3A%22%22%2C%22_background_hover_size_mobile%22%3A%22%22%2C%22_background_hover_bg_width%22%3A%7B%22unit%22%3A%22%25%22%2C%22size%22%3A100%7D%2C%22_background_hover_bg_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_hover_bg_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_background_hover_video_link%22%3A%22%22%2C%22_background_hover_video_start%22%3A%22%22%2C%22_background_hover_video_end%22%3A%22%22%2C%22_background_hover_video_fallback%22%3A%7B%22url%22%3A%22%22%2C%22id%22%3A%22%22%7D%2C%22_background_hover_transition%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22_border_border%22%3A%22%22%2C%22_border_width%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_color%22%3A%22%22%2C%22_border_radius%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_box_shadow_box_shadow_type%22%3A%22%22%2C%22_box_shadow_box_shadow%22%3A%7B%22horizontal%22%3A0%2C%22vertical%22%3A0%2C%22blur%22%3A10%2C%22spread%22%3A0%2C%22color%22%3A%22rgba(0%2C0%2C0%2C0.5)%22%7D%2C%22_box_shadow_box_shadow_position%22%3A%22+%22%2C%22_border_hover_border%22%3A%22%22%2C%22_border_hover_width%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_hover_width_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_hover_width_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_hover_color%22%3A%22%22%2C%22_border_radius_hover%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_hover_tablet%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_border_radius_hover_mobile%22%3A%7B%22unit%22%3A%22px%22%2C%22top%22%3A%22%22%2C%22right%22%3A%22%22%2C%22bottom%22%3A%22%22%2C%22left%22%3A%22%22%2C%22isLinked%22%3Atrue%7D%2C%22_box_shadow_hover_box_shadow_type%22%3A%22%22%2C%22_box_shadow_hover_box_shadow%22%3A%7B%22horizontal%22%3A0%2C%22vertical%22%3A0%2C%22blur%22%3A10%2C%22spread%22%3A0%2C%22color%22%3A%22rgba(0%2C0%2C0%2C0.5)%22%7D%2C%22_box_shadow_hover_box_shadow_position%22%3A%22+%22%2C%22_border_hover_transition%22%3A%7B%22unit%22%3A%22px%22%2C%22size%22%3A%22%22%7D%2C%22hide_desktop%22%3A%22%22%2C%22hide_tablet%22%3A%22%22%2C%22hide_mobile%22%3A%22%22%2C%22_attributes%22%3A%22%22%2C%22custom_css%22%3A%22%22%7D%2C%22defaultEditSettings%22%3A%7B%7D%2C%22elements%22%3A%5B%5D%2C%22widgetType%22%3A%22html%22%2C%22editSettings%22%3A%7B%7D%7D%7D%7D%7D&_nonce=b346badb4d&editor_post_id=544&action=elementor_ajax
--80860430-F--
HTTP/1.1 403 Forbidden
Content-Length: 232
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

--80860430-E--

--80860430-H--
Message: Access denied with code 403 (phase 2). Match of "endsWith /sysext/install/start/install.php" against "REQUEST_FILENAME" required. [file "/var/cpanel/cwaf/rules/10_HTTP_HTTP.conf"] [line "40"] [id "211090"] [rev "2"] [msg "COMODO WAF: HTTP Response Splitting Attack||www.afrecasp.com.br|F|2"] [data "Matched Data: <html found within REQUEST_FILENAME: /wp-admin/admin-ajax.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"]
Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 179.111.172.151] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /sysext/install/start/install.php" against "REQUEST_FILENAME" required. [file "/var/cpanel/cwaf/rules/10_HTTP_HTTP.conf"] [line "40"] [id "211090"] [rev "2"] [msg "COMODO WAF: HTTP Response Splitting Attack||www.afrecasp.com.br|F|2"] [data "Matched Data: <html found within REQUEST_FILENAME: /wp-admin/admin-ajax.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.afrecasp.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "XFr3eN7aGDb0[at]BZw7OtwJwAAAkI"]
Action: Intercepted (phase 2)
Apache-Handler: application/x-httpd-lsphp
Stopwatch: 1549465464896542 460160 (- - -)
Stopwatch2: 1549465464896542 460160; combined=634379, p1=692, p2=3768, p3=0, p4=0, p5=315098, sr=96, sw=80, l=0, gc=314741
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.2 (http://www.modsecurity.org/); CWAF_Apache.
Server: Apache
WebApp-Info: "default" "c57e3293a5ecc3de3505a05947321853" "-"
Engine-Mode: "ENABLED"

--80860430-Z--

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek