You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -
Number of replies: 19

Hi,

I've upgraded from 2.9 to 3.1.1 and now I'm having some serious problems when making chanches.

Resulting in:

You don't have permission to access /course/modedit.php on this server.  Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.


changed the rights off modedit.php from 644 to 755. No result

I found out that the existing code in a label caused the problem.

But I can't figure out whats wrong:

<p class="western"><img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAANYAAABTCAIAAABs/G4SAAAC40lEQVR4nO3dPW7iQByGcVvKUUCrFDkA3ACUYquUKXGLC8qtttwCWqfckgPADeAIKCJ3mdgGLzbmQ8vHvJ7h+VUJRMJ/+WFsEo3yZIwJAJ0n9QHg0ZEgxEgQYiQIMU2CYRh6+TGIuS5QSTB9pTu9TJ3N17LJ47nuVGElQWvvYFYLt9hbBQH7SBBiJAgxEoQYCUKMBCFGghAjQYiRIMRIEGIkCDEShBgJQowEIUaCECNBiJEgxEgQYiQIMRKEGAlCjAQhZiPBg1tr6w86t/2RuW7ycpZWwbOH6+gOcOa6HhdiiJEgxEgQYiQIMRKEGAlCjAQh1uAEvybddrzcfT+YmaSnO5ybYa6qBieY6YzXi2Er+yobMIw8OVvMVdLwBHdar2+deKU+itvzf64sxunb+CWOPzZP7S2PziQ4/xMvBzMvloqKx5hrGa9+GZPkT0RhP/pZirDhCS7jdhjnX6VvHVM9UfOo+znaLvuuOThX+WZqd0VzyrHz1RmPim/az51g+vkV9IrpGp7g5kzkS3n5qLN30kc+mPToLndwrvXqZWYW+alKB3yfvLoX4ZHzdVLDE9xoDf+Op+129KNYvnuJMaNJ9118XNfam6uXJMUz2VLhrtr5OsmJBLOhFrPV3j2EDw7PNY/S+/f1wrUlsOR/zpcjCQbZGjEbhP0w8OX3F4W9ubJ7jKC4Hrvs31zr59M/2OAE03eSGZYfyC6/yZEfdsjxubb5GTfzOz5Xr/x47ccanOAJ248j6T1TGPvyx4X0A/HvbKZ+uP31mTd/NjnDzQQ9WQ+rasvDg3AzQXiEBCFGghCzlKCjexnPYq7r2UiwvinVj//by1w3wYUYYiQIMRKEGAlCjAQhRoIQI0GIkSDESBBiJAgxEoQYCUKMBCFGghAjQYiRIMRIEGIkCDEShBgJQowEIUaCEKskaHP3KDtw3XK/fZyVBK3tgfVjv20dc11AcyH28jwFzHUR7gUhRoIQ+wZD+FFSzX4FBAAAAABJRU5ErkJggg==" name="Afbeelding9" style="font-size: 10pt; line-height: 1.5em;" height="83" width="214" align="left" border="0"></p>
<p class="western"><br clear="left">$U=U_{1}=U_{2}=U_{3}=U_{...}$<span face="Arial, sans-serif" style="font-family: Arial, sans-serif;"><span>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (V)</span></span></p>
<p class="western"><img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABAAAAADACAIAAAAV2IZzAAAOrklEQVR4nO3dPVIbWRcGYFH1LQUIKK9ArECQEDl1JkKUOHPozAmEUjapo0kGrcCswOXAsBd9QsagnxZq9f/VeZ7QVUg9mtPd5+17+97/zWazHgAAEMP/2j4AAACgOQIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABFI+ADzdnZ+MHio4lFz6t48/bo6b+jboEuca5akiGqbkqJsaK8IIAAAABFI+ABzf/JjdrP3b9ProYlL6k4f3s/Gg9KfAoXCuUZ4qomFKjrqpsSLqGQEYjGezcfGf/1CGV6B2zjXKU0U0TMlRNzW2S61TgJ5//qt9f/tDjltQE+ca5akiGqbkqJsa26r2dwDmv/19L/dPP49cAX50qINzjfJUEQ1TctRNjWVq4iXgwdWwN8n1ww+/HPiAC9TKuUZ5qoiGKTnqpsY2NbIKUN4fvn92Uv/BwAFzrlGeKqJhSo66qbENzSwDenLW7/V2LtHa/3gZJHZBXZxrlKeKaJiSo25qbF0zAeD49EOO3x0oy7lGeaqIhik56qbG1nVpI7APp2FyF7TKuUZ5qoiGKTnqFqnGGgoA+YZegLKca5SnimiYkqNuamxNh0YAAr15Aa1yrlGeKqJhSo66haqxDgUAAACgbgIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAALxjen10MVn5l+H9bDxo6WgIQMlRNzWGAAAAAJEIAAAAEIgAAAAAgQgAAAAQiAAAAACBCAAAABCIAAAAAIEIAAAAEIgAAAAAgQgAAAAQiAAAAACBCAAAABCIAAAAAIEIAAAAEIgAAAAAgQgAAAAQiAAAAACBCAA0bXp9dDFp+yBKGt7PxoO2DwIAoAgBAAAAAhEAAAAgEAEAAAACEQAAACAQAQAAAAIRAGjaYDybjds+CACAqAQAAAAIRAAAAIBABAAAAAhEAAAAgEAEAAAACEQAAA7B9ProYtLMV00ujur5pv7t44+b41o+muopOeqmxqiPAAAAAIEIAAAAEIgAAAAAgQgAAAAQiAAAAACBCADAIRiMZ7NxHR+8uQ7H8H42HtTxVSRFyVE3NUZ9BAAAAAhEAAAAgEAEAAAACEQAAACAQAQAAAAIRACgaZurD6THegkAQLIEAAAACEQAAACAQAQAAAAIRAAAAIBABACgVk935yejBy9OU4GXYtrQv338cXPc/PFwwLatV+FSxmEQAGjaYDybjds+CJqwrVuDPe0qpYfRydGoJwhQgV3FNrk4es4Fao3ECQBA5Q5hrVe6Ya8YuQgCOjOK2uPKtag1owGkSwAAKqT1p0KFyum5M/ulMWNPRUYsJxdHPaVGmgQAoBJaf6pVpqLmjdlPAwHkVny+4uTi/EylkSABAChJ60/l5g1ZyaJ6GJ1cn3o4Sw7T65XuP2Niz3sXuYfRp7tLEYDUBA4Az4H/+8eEgntyB0wIi0Zt5YYpD1DW092njcexGV3Z7tc1r69EAHaYXv+9YG1/feTP4hXbrm0Po2/TG4VGWhoKAI+/OrcUyPTb/L7R/9j2YeSX3AHTisbPteObH7OblX8ZjO+HExEgZW1fsRdXu1fbX7R8Kb53Iufk693ngYcm3ddeyf1t//O8Oz6PAY9nmaFz8u90PJAAOq3ty1rndGgE4OHX4/x63tS3Tf9NrD9J7oDprtrPtcHVsDdRsIetvip6uvv6t3jyLeizvS3zbPaQ1FFyL8WWfzWfeei8/5UROCWAg9BsI9qyZgLA0++fjXxPbks3mDQkd8C0pCPn2slZf34pbfsoKKjdKnr67/uf0tlnOc95W/bYy84AOrMEtFVyf0bWbx/3ioiDz7f9yUap/fz91BtEaR1T1JGbY4d0aASgudMna3pppyV3wHScWxXl1VRFf/v/4f2e7zttezQrARyM6ktuMH58/Hx8vOdnHt98GY7McjxIkW6OjQSA1wc672to6CW5bjq5A6Y9XTnXjk8/GAFIVrtV9Gei7vC+yLSd7Eezoe7paWqx5Pbu/hcyxjg/nCqxLuvKzbFDGgkAed+8aOIqnVw3ndwB06YunWukqtUqWrzt1L/9XOyJffaj2Uj39DQld+HafMTRPztp62DII7kaq18DASD/9PX639ZaW+y3+5I7YNrUpXONVLVbRYt5usMvxdft8QJ6eg7hwtX/eBmjaUzUIdRY5WoPAPs9wK51W+3kVidP7oBpVYfONZLVdhVtriq7r4zJGR7OdlnbJVcJ/X+nHUSNVa/WAFBob+35Tz/JvyJXbsk108kdMG3q0rlGqg6jirx/kpBkS251RZn+7T/2muiqZGusfjUFgJLd6/Nv39tnZd5ajyaHrRVW7D9B809u3TrXSNOBV5HXM7sn8ZJbmVBeZsoa9Um8xupXPgAUSlf5vPz8y/ZZGLq3++AeRidHo4x/z/t/fGd9/f1PyPuBdR8wKev0uUYiAlaRGUDtOsCSW9qYc99NBKjDAdZYA7q0D0Dl6lxAZ63c1hvw9WSwKKGdRWPFH4BqmZ5NtZZeKN17twrojPIBoPw7W7VZP7TNjFgsx618TvZHDMaz2Xj9+54f339/7xvrOmAOQ4fPtUO2OJnbPojqHHwVre/3mWD/r+S67O1BXcoP/9UYhz0CUIuVZ/vvz7x5LsnTtaGAeQg472niAeqwvt2P+dlU6bX99zSO1AkAe3m6O19q5/PsVTkYP97+XH2MLwMA1GN1u5/CO4rBptfnf7p/DoAAsIfVKfp5t6o/vvnn9vvaTJ55Brg+9douQKWW3s7sefxPdVYG/1+W47D6BikTAHJbe0N3eJX7vM+KAL3JxfWVawdAdVb6f4//qcL2FWaeV/cwGECqBICc1hfo2aP/7z1HgC/D0fqCoZOvd58HLhwAlVhancXmTJSWax35nYt7QEcJAPlMv60+ANiv/58bXA17k7VLycPo2/TGIABABVYu02b/UNi+q8qb1EuKBIA8Vp4rPSuwsczg821/sn5JMQgAUIWVy3TeV7Qgw9qiknlGAiYX52eGAUiKAJDD+rpyxXaWP7782B89rH3Qw/f/nm5cMwBKWXr8n/Ly7HTQ3zXz3w8CD6NPd5ciAOkQAHbb7P+L7Sx/fPphfo1Y+0cJAKCk6fVrZ2buPzXJ3OBziVm9JEUA2Gmz/y8q6z2A3sOvx3k2qOYLAOJZav+H957BUqfn6UGX20KAWb0kRADYaXVfmYUiM4CenZz1N8cAfv5+6g1cMACKeGv/zf2hEc8h4DRzPpAxfdIhAOzy9PtnZZ+VPQnIEABAIUu7s3v4T4MG4/vhZDMCuKGTDAFgl4wBAA/tAdr3tj+Lh/80LXNpP+0ByRAAGpU5BwiAvU2vXyZi24yVNmTu8GkIgFQIAACk5m3uj6k/tCV7EACSIAAUIeIDtOZtKcbhvQ1YaU/mi32QBAGgkCpn+RXbVAAgpuWpP7p/WrWxurc7OqkQAHbJnLZf5RBA0TVFAcJ5nfpj4j9dsN4iuKOTCgFgl+wRvuqGAIZXnmAB5PA69Uf3TzcZACAZAsBO2fv3VrXbh/4fIIflif+6f7rJAADJEAB2q3AS0MamAvp/gJ289ksK3NJJhwCwW+Zav73Jv9PxYM9TfWNXYRcLgB3euv8Sr/1Or48ufpo5RLWe/vv+9livf/vZLZ1kCAB5ZM4Cmny9+zzY716yNgDgYgHwvpXuv2j7/ufV4f7tpe6fSi3f1YdfpEsSIgDkkrnbx97vAawNALhYALynqu5/8SH9j/p/KvV09/X10aAneiQmeADIPZP/+Oaf2+8naxHgYfTp7jL/PWllqLDgxcIWZEAQ5bv/t0/o6f+p3PTbW3Xd/uOJHpmWL0N7XcoK/2FOwQNA9nKemXNFt0SAb9ObnFNS16YKFrxY5D9gaM/G6y7V7p7H4Vvp3R9GJ0ejkh+o/yfD893z70P8/d4vf92RomddKrZaLrDen0vZr1x1VvgP8wsVADKW9M+YxjO9nv/ow/vNszkzAkwurq/y/C95uvv09pd5LxYlDxggRWv3viro/9mw3MP3nm/nR5OcT1rXns1al4pMi/ZsXZ62sfAf7iNUAMh6mXeeqs57r+f7y21n2/Sc45sfj73ztQwwuTg/23XBWG7/97lYlD1gaMfGgremr5FXDd2//p8Mq9NyXyxGm95PAcsVaks6tssYCl/YOR5e+A/3EisAbNnUa210+d3pOVkZYMfQTPEhxioOGBq3/GbcmwLrZhHNysSfCllygX38ucluNver4VTzT9KCBYDeYHw/nLz7dGn39Jx5Bphdrt+msscOV64WhfavqeKAoTnvdHCLm6ptnNimlkf/C3ZcIUP2Hj9v3nn1RO9PDhnTuBd27hdd+A/3Ei0APHfUj7c/t3Qo+XuT5xBws9HqbLtclLpWVHPAUJ99GrdFVH7hJkoj9P9kG4xn9739Yqe7LvllPsId3u+uoMJ/uI94ASC7eS/UiSw+qPfOM8+K+pvKDhhqMb+LzsZtHwTJU0c070/V7Zp7pu2nmHl9PZ4VWc2z8B/mFzEALPxt3rv2We1+CQBE4wZLbQoXV91VGTYAAABARAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABCIAAABAIAIAAAAEIgAAAEAgAgAAAAQiAAAAQCACAAAABPJ/v2qspYnHr3UAAAAASUVORK5CYII=" name="Object11" style="vertical-align: middle;" height="21" width="130" align="absmiddle">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span face="Arial, sans-serif" style="font-family: Arial, sans-serif;"><span>(A)</span></span></p>
<p class="western"><img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAJAAAAA9CAIAAADNpnffAAADZElEQVR4nO2bvXKqUBCADzN5FLBw8gT4BJiGyjYdltLQpbRLIyV2t7WyiT6BPkHGQnyXczlgHFCC/C67ZL/KZCbZo59nzw+7L1JKwdDhpe8BMNVgYcRgYffs59r0exUeFnrfI8mFhaVQrtamafY9jiJYWAorkDK4+BNj0/dIfoeFEYOFEYOFEYOFEYOFEYOFESNHmNrXusfMr5ydDCygETGF5AjTFwc5Sh331XFyOhmjPfu3RnxuTl4eDc3F+T3NT4mX87cQr6NEkOWtzLV7CiOVkCODJz439z2IZ+QLC09HYc6M3J+YXskVlplg+3mUJ5xd+XyYyiwPYEwytMgTdvnaRHuO41SLP3ZzFUpZJRmSyCxkyRMWp0C14wjVXPmZaV2haVqn/38ApKsC8rb1t4Sox9uN7T6wOI1hIUdYao+hv81MN23suj7F808k57WHZaniGsZFJZV4FJbZcSTGlr5nJZsOK9g5662dHMkW/1anr7eHTQSvYV2SFXa75FA7jng26IsPx526hra5HqMt21meL8JSJ+rPkx0s+hn3nyUrTF1y3Bu4nzDGWGzVIfrib8de5zMJuMICvqCjasTql7/66HUdrWrGWdjdvi3gCgv4go5aEWvc1sdJ0f88jTqeXsAVFvAFHbUi1nm8EiXF6WYcHmr8KdOUOsKipOh8DP3qHiu1HmBaAW/b+4KfOBODhRGDhRGDhREDrzDgCgv4go56EfEKA75Dhr+yrhcRr7BmqK+vgKtHgAs3VGGDhYURY2DCsk+7r2VEyQPyLq7SgMMpsAirXYqTrTC4LeRPFhUq4R4iohHGlASLMOBSHLrhsAhrG5WsBhkOnTDgZidy4dAJA252IhcOnTAB3uxEKxxGYcDNTrTCIRTWrNlp6OHwCWvY7DT0cPiEwTY7kQuHThhwsxO5cOiEFTU7Jeznk7PX1ra7KFzq0NTWfe7zd/cMbMIKm51+rsfNlQcTbraTB/VxRure/bfmyp6EKwMmYWWanQIp7WiGgYTTF23uFku8uzJgElam2amfcOFJzLyG8lp6d5iEISWaGlv7ECDpJWBhxUSL5nIcHvA05bOwAuK5JRHZEtSE3RbuteZ2Xuh58d/d41FcCzW6LyyNW/tmyfYj/ToLLWF5C/cwgt3F+z02LWGM+A8KdrQGa+NnoAAAAABJRU5ErkJggg==" name="Object125" style="vertical-align: middle;" height="61" width="144"><span face="Arial, sans-serif" style="font-family: Arial, sans-serif;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;</span><span face="Arial, sans-serif" style="font-family: Arial, sans-serif;">(Ω)</span></p>
<p class="western"><img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABAAAAAE9CAIAAAAao4cAAAASyElEQVR4nO3dvVYb1xoGYLHWuRRw4eUrgCsQaVylTQel1KRLmS4NlKhL6yqN4QrgClgURveigzBgsLfQHs2e3+95qpyAxeR4v2hezbdn/rdarSYAAEAM/+v6AAAAgPYoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoALtZnh8dzG8e/uHkcnUx7fpoYLBECfLJC1QlNWkKQFUvKwmoQ5Qgn7xAVVLzHgUgn5UERYgS5JMXqEpqtlMAclhJUIQoQT55gaqkJpcC8D4rCYoQJcgnL1CV1FSjAGxiJUERogT55AWqkppdKAC/spKgCFGCfPICVUnN7hSA16wkKEKUIJ+8QFVSU5cC8J2VBEWIEuSTF6hKaspQANauTl8vpudHRVhjUJEoQT55gaqkphQFYG36+WSymPz8iLj92fVqdnW6d7zo6rhgYEQJ8skLVCU1pSgAj6YXq9Wmr1yeLKwoyCNKkE9eoCqpKUQB2OqxbVpQUJcoQT55gaqkpgIFYLuDj4eTidEyqEuUIJ+8QFVSk08B2G7/wyfrCeoTJcgnL1CV1ORTADJolFCEKEE+eYGqpCabAgAAAIEoAAAAEIgCAAAAgSgAGWwqgSJECfLJC1QlNdkUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBSADMtvt10fAoyBKEE+eYGqpCabAgAAAIEoADXdfltOpvtdHwUMnihBPnmBqqTmDQUAAAACUQAy3N/dbPzazd39ZKJQQg5RgnzyAlVJTTYFYLv3t5S4pASZRAnyyQtUJTX5FICtrv6Zb+6TD43yy9flbGZBwTaiBPnkBaqSmgoUgPctz4+OF+9/y8384Ghyf21JwTtECfLJC1QlNdUoAJtcne5tW0kvHpbU3nwyOblcXUybPCYYIFGCfPICVUnNLhSAJw/N8eDdK0cZFsd7b1ag9UVAogT55AWqkpoiFAAAAAhEAXiyP7tezbo+CBg+UYJ88gJVSU0RCgAAAASiAAAAQCAKAAAABKIAAIT25hZ6h2dukg2VSBBDpAAAAEAgCgAAAASiAAAAQCAKAAAABKIAAABAIAoAAAAEogAAAEAgCgAAAASiAAAAQCAKAAAABKIAAABAIAoAAAAEogAAAEAgCgAAAASiAAAAQCAKAAAABKIAAABAIAoAfbM8PzqY33R9FPkOz+6vZ/tdHwUAQCYFAAAAAlEAAAAgEAUAAAACUQDom/3Z9WrW9UEAAIyVAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAMCANPynvZn6wNy/6ih6VR69IEKwpAAAAEIgCAAAAgSgAAAAQiAIAMCDln5R3dbp3vHj+H+aNGTkJgjUFAAAAAlEAAAAgEAUAAAAC2bEA7O3tlT0OhmK1WnV9CEEJ3SAISPtEY0wkqH0SNET1k7JLAbBWInv422/4F3TDT2kprpUtX0I3FM0HhDdEY2QkqGUSNFD1k1K5AFgr0DKhgyTRgDokKDJ7AAAAIBAFAAAAAlEA6JvyT2kBAOBF5QJgdw60TOggSTSgDgmKzBUAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAAAACEQBAACAQBQAAAAIRAEAAIBAFAAAAAhEAQAAgEAUAIDQpher1UXXBwGDJUEMkQIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIE0UQCuTveOFw287maHZ/fXs/1WfyT0jNxBkmhAHRI0TuO4AnAzP9ibv/4XFg80Tu4gSTSgDglqQxMFYHqxWl28+TfL86OD+U0DP2qTl8Vj0RCF3EGSaEAdEjRO7VwB2J9dr2btr5jJ86KxYohI7iBJNKAOCRqDNkeAHlbM/aTCctnyN1xhKu1xxZxcri6mmT8aRkPuIEk0oA4JGraW9wDsz/49+7JlteQ2u5eLUpmLZnG8t7BeiEjuIEk0oA4JGrDWNwHvf/j0UN6KvuTjosm7FPWwXm5dOSIeuYMk0YA6JGiw2r8L0PTzyWRR/oZS64m033LWy8384GhiuRCM3EGSaEAdEjRUHdwG9ODjYem6+CR3Hu1huZx+cNmIUOQOkkQD6pCggRrHcwB+yF0ui+PTz1YLlCF3kCQaUIcENWdsBWCStydlYrVAUXIHSaIBdUhQQzooAA3sGPn5J2Sulr/P/5waGyMGuYMk0YA6JGigRngFYG1/9tfJfOttpG6+fF3OLBYoRO4gSTSgDglqwEgLQOa+dIsFipI7SBINqEOCihttAbBYoANyB0miAXVIUGnjLQCZi+XufjKxVqAUuYMk0YA6JKiwEReAvHvT3n5bTqYWC5Qid5AkGlCHBJU15gKQRVuE9skdJIkG1CFB2cZcAJq/NRXwM7mDJNGAOiSorDEXAAAA4CfhC8Dhx4OuDwHCkTtIEg2oQ4KyjbkALL/dbv+mTx/MikFBcgdJogF1SFBZYy4A93fbZ8V0RShL7iBJNKAOCSprxAXg6r9t94t9WCq//6YrQkFyB0miAXVIUGHjLQCWCrRP7iBJNKAOCSpttAXAUoH2yR0kiQbUIUHFjbQALM//3r5UTv6aWSpQjtxBkmhAHRLUgFEWgOX5H/OtW0VOLi+mbRwMBCF3kCQaUIcENWKEBeDq9MBKgZbJHSSJBtQhQQ0ZWwFYnh8db71OdHh2b6VAOXIHSaIBdUhQc0ZVAK5O97IWyrUxMShG7iBJNKAOCWrUaApA1jqZnFyu1EQoRu4gSTSgDglq3BgKQN4ysU6gJLmDJNGAOiSoHYMuAJmLxBUiKEjuIEk0oA4JatXgCsDy/ChjP/gLqwQKkDtIEg2oQ4I608MCcDM/2JvXfRFrBCqRO0gSDahDgnqqhwWgBisE2id3kCQaUIcENWlEBcB+EGif3EGSaEAdEtSwERWAxfHpZ6sF2iV3kCQaUIcENayHBWDTJZ/t28OtFtiV3EGSaEAdEtRTPSwAm0wvLk8WVgu0Su4gSTSgDgnq2IAKQO5qOfpo0wiUI3eQJBpQhwR1alAFYL1a7s9ut9wy9mb+x/lvVgsUI3eQJBpQhwR1aGAFYDLZn/179sVqgVbJHSSJBtQhQZ0ZXAHIXS0Hpx/MjUExcgdJogF1SFBHBlgA1qvl+vLO7nFoldxBkmhAHRLUiUEWgInd49AFuYMk0YA6JKh9Qy0Ado9DF+QOkkQD6pCgtg23ANg9Dl2QO0gSDahDgto15AJg9zh0Qe4gSTSgDglq07ALgNUCXZA7SBINqEOC2jP0ApC3e9wNpKAsuYMk0YA6JKgtwy8AE7vHoQtyB0miAXVIUCtGUQDyto5YLVCW3EGSaEAdEtSCkRSAvLkxN5CCsuQOkkQD6pCgxo2mANg6Al2QO0gSDahDgho2ogKQu3XEaoGS5A6SRAPqkKBGjaoATLK2jtg9DoUNJXdXp+v3ksMzF41pyVCi8d33gPzi5LIfh0dAw0rQsIytAPRq9/jy/GjL1auEKicnuT/ACQ9N61HuUnbKIhTQ82h8t+HM/8nieG/9RT2ALgwiQYM0vgLQo93j+7Pr1WySefKxy+/Wpx/w3uv7lU1LepO7t94/s4Hm9TQaT/LL8WMP8JZC6/qdoOEaYwHo3e7x7+fpm09E6n5A//j6v/4W94uadvUsd0796YueReOH6iF5aAETby20rLcJGrRxFoBe7h7f2GEPf/+twDH89F/s7J8O9CN35n3onX5E462HoOxUkXUA2tfHBA3dWAtAL58mnbOAyzi59MuZTnSfu6vTg/nk7H719C7gOgD90H003lqe//HmzShxJXpzeMxb0Lq+JWj4xlsAJrlbR9q8aLT/2++H85ufGsDN3f3DV2q/9vLrl6cXPjz70/KnMx3nbnqxWlU8GmhFn96Srv7Zfr14naWLDRfUVADa16cEjUAHBWD57fbdrxc6H36Us3Wk1ca4P/vrZP7z8l38d3Uxrf3z7++e/jNP/rL0+UXc3E0/n0wWGgCbRIzG8vzv75HYvgNtvcfsQ+pSwOLv8z+n3mwImaBRGPUVgLWssZs2G+P0z7PDxU/HU6ABvPp97uN/Ote73EE/9CIaT9eLs+8/kT7ruvnydTmTX9rViwSNQwcF4OWT6k1uvy0n03J/b1mr5aExHk3aWS6pMaDaH6W8zP+U2VHM+ATO3cHHw4cf1eiPYMDiReP7+8Xh2b/5L5886JKf7DJc8RI0Eu0XgG0Xixr4pZKzdeRxuezdtXFrg9QYUM2PUl7O/43/kCZ3kBQwGusTtkqn/2upN67CJ3YMUsAEjUTrBeDVzqONyszEv5G5E3BxvHfbwlNzE2NAN/N/rma7rtOX/1NPPlvppMgdJAWMxvqEbZfPiuymISFggsai5QLwMqn+viY2F+XeDGTdGed1H821TdkxoKv/jP/zHrmDpJDRWG/r3ekPGqbjZyETNBZtFoAKN+Ru5MpNzu7xVz9/3uTTtAqOAf3Y/mv8nwS5gyTRqGj/w6e3BeDTB+85kUnQsLVTAHZ6MufieG+Rf5eCLFWfxPV4CI/Kt8dSY0DG/9lE7iBJNIo4/HjQ8RHQEQkagyYKQMlHbz61ttdq/bXt+jDeH8dRrECWGQMy/s8TuYMk0WiGi85RSNA4jf45AL/I2z3ezpHUHwMy/s8w9Cd30CsDisbb2704/6cXBpSgnmmiADw+PryB1y2mNwdYdwzI+D8/9GZZb9L7A2Sker/yen+AT97c7927Thy9X6C9P8B+incFoFfqjQEZ/wegHc8XnB9514GBUwC6VWcMyPg/AO14ff5v6BQGTwHo2s5jQMb/AWjHq/P/yk8RBvpHAejcbmNAxv8BaMfr5z2Z/oExUAC6t8sYkPF/ANrxMnC6vmli0HsmwsgoAH1QeQzI+D8ArXj18b/TfxgLBaAXKo4BGf8HoA3L8z+ePnA6PLt3+g9joQD0Q5UxIOP/ALThx+n/yeXuj2sFekcB6IvsMSDj/wC04OX034f/MDYKQG9kjgEZ/wegeVenB9/fbnz4D+OjAPRH1hiQ8X8AmrY8P/r+duTDfxglBaBPto4BGf8HoGnPH/4/nP378B9GSQHolS1jQMb/AWjW84f/zv5hxBSAfnl3DMj4PwCNev7w3+A/jJoC0Debx4CM/wPQoKvTvcdPoE4uVwb/YdQUgN7ZMAb0+dsX4/8ANOR59MfZPwSgAPRPcgxofvxUCYz/A1DYw9n/4+iPm/5ADApAHyXGgJ4Z/wegqFdn/wb/IQYFoJdSY0Brxv8BKKnO2f/jn52oDTA8CkA/pcaAjP8DUFLts/+bhz/qjQmGRwHoq8QYkPF/AErZ/ez/+U9OvDHBQCkAvfXLGJDxfwDKeL7j52R9l4mDvfmOL+ONCYZJAeivt2NAxv9hN/d3b7fT3NzdP8Sro4OBPnh19l+P838CeXXlK+vCWdXvb5cC0GevxoCM/8Nunp+g98Piv6uLqdMWgnpzUlKT83/C+Dk46wtnd+88M6Pq97dOAei1lzEgU5awgw2nOovjvdu+fRgDbSh59u/8n0CWX7/8Gpzbb8vJNP1GUvX726cA9NvTGJDfspAta7rh9dSzB58SRfKkZGfemYgjeXv2Tx82ns1X/f72KQB9N71YrS66PggYEJmBDfZn16tZ1wcBQ/QQnvtJhZn+qt/fOgUAAADeVbVA97twKwAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQiAIAAACBKAAAABCIAgAAAIEoAAAAEIgCAAAAgSgAAAAQyP8BCrevoPrWGjAAAAAASUVORK5CYII=" name="Object12" style="vertical-align: middle;" height="41" width="146" align="absmiddle">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<span face="Arial, sans-serif" style="font-family: Arial, sans-serif;"><span>(S of Ω</span></span><sup><span face="Arial, sans-serif" style="font-family: Arial, sans-serif;"><span>-1</span></span></sup><span face="Arial, sans-serif" style="font-family: Arial, sans-serif;"><span>)</span></span></p>
<table style="width: 241px; height: 102px;" border="0">
<tbody>
<tr>
<td>Grootheid</td>
<td>symbool</td>
<td>Eenheid</td>
<td>symbool</td>
</tr>
<tr>
<td>spanning</td>
<td>U</td>
<td>Volt</td>
<td>V</td>
</tr>
<tr>
<td>stroom</td>
<td>I</td>
<td>Ampère</td>
<td>A</td>
</tr>
<tr>
<td>weerstand</td>
<td>R</td>
<td>Ohm</td>
<td><span>Ω</span></td>
</tr>
<tr>
<td>geleidbaarheid</td>
<td>G</td>
<td>Siemens</td>
<td><span>S of&nbsp;<span>Ω<sup>-1</sup></span></span></td>
</tr>
</tbody>
</table>


Any suggestion?

The problem with:

You don't have permission to access /course/modedit.php on this server.  Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

is happening quite often and not only with the modedit.php


Thanks.

Hans.




Average of ratings: -
In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

What operating system and web server (I'm assuming Apache) is this?

What is the full entry in your web server's error log for these errors? 

The second part of the error - "additionally, a 403 error..." is because your web server isn't configured properly but shouldn't stop Moodle working. 

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -

Im on a shared host with ssh Access?


In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

To repeat myself then...

"What is the full entry in your web server's error log for these errors?"   (you might have to ask someone if it's shared hosting)

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -
I've asked my hosting provider for the logging.

In the mean time I also installed the site (moodle 3.1.1. latest stable from Github) on an other domain, on an other (also shared) server.
It worked on that test system?
Don't know what differences to look for, but the failing system in on PHP 5.5.37. and the test system is on PHP 5.4.45

Also tried a .htaccess file in the root of my site and in de /course folder with:
<IfModule mod_security.c>
  SecFilterEngine Off
  SecFilterScanPOST Off
</IfModule>

That had no effect at all.

Hans.



In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

I'd go and have a cup of coffee until the log results come back. It could be lots of things - quite possibly a configuration error on the server. 

One thing to look out for... do you have Moodle mixed up with any other software? Wordpress is a common culprit as it has an "interesting" htaccess file that can break Moodle. 

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -
Hi Howard,

My moodle site is running in it's own sub-domain.

Got the logging:

Forbidden

You don't have permission to access /course/modedit.php on this server.

Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.


[Wed Jul 13 13:16:00.036581 2016] [:error] [pid 30892:tid 139709776889600] [client 5.104.113.88] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(asfunction|data|javascript|livescript|mocha|vbscript):" at ARGS:actions[0][drafttext]. [file "/usr/local/cwaf/rules/07_XSS_XSS.conf"] [line "223"] [id "212770"] [rev "2"] [msg "COMODO WAF: XSS Attack Detected||techniek.mijnelo.eu|F"] [data "Matched Data: data: found within ARGS:actions[0][drafttext]: <pclass=\x22western\x22><imgsrc=\x22data:image/png;base64,ivborw0kggoaaaansuheugaaanyaaabtcaiaaabs/g4saaac40leqvr4no3dpw7iqbygcvvkuucrfdka3acuyquukxglc8qtttwcwqfckgpadeaikcj3mdgglzbmq8vhvj7h+vujrmj/+wfseo3yziwjaj0n9qhg0zegxegqyiqimu2cyrh6+tgius5qstb9ptu9tj3n17lj47nuvgelqwvvyfylt9hbbqh7sbbijagxeoqycukmbcfgghajqyirimriegikcdeshbgjqoweiuacecnbijegxegqyiqimrkegalcjaqhzipbg1tr6w86t/2ruw7ycpzwwboh6+gocoa6hhdiijegxegqyiqimrkegalcjaqh1uaevybddrzcft+yma..."] [hostname "techniek.mijnelo.eu"] [uri "/lib/editor/atto/autosave-ajax.php"] [unique_id "V4Yi8LL7Hw0AAHisqKoAAABL"]

[Wed Jul 13 13:16:59.326821 2016] [:error] [pid 30884:tid 139709485324032] [client 5.104.113.88] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(asfunction|data|javascript|livescript|mocha|vbscript):" at ARGS:actions[0][drafttext]. [file "/usr/local/cwaf/rules/07_XSS_XSS.conf"] [line "223"] [id "212770"] [rev "2"] [msg "COMODO WAF: XSS Attack Detected||techniek.mijnelo.eu|F"] [data "Matched Data: data: found within ARGS:actions[0][drafttext]: <pclass=\x22western\x22><imgsrc=\x22data:image/png;base64,ivborw0kggoaaaansuheugaaanyaaabtcaiaaabs/g4saaac40leqvr4no3dpw7iqbygcvvkuucrfdka3acuyquukxglc8qtttwcwqfckgpadeaikcj3mdgglzbmq8vhvj7h+vujrmj/+wfseo3yziwjaj0n9qhg0zegxegqyiqimu2cyrh6+tgius5qstb9ptu9tj3n17lj47nuvgelqwvvyfylt9hbbqh7sbbijagxeoqycukmbcfgghajqyirimriegikcdeshbgjqoweiuacecnbijegxegqyiqimrkegalcjaqhzipbg1tr6w86t/2ruw7ycpzwwboh6+gocoa6hhdiijegxegqyiqimrkegalcjaqh1uaevybddrzcft+yma..."] [hostname "techniek.mijnelo.eu"] [uri "/lib/editor/atto/autosave-ajax.php"] [unique_id "V4YjK7L7Hw0AAHiksYEAAAAQ"]

[Wed Jul 13 13:17:59.295306 2016] [:error] [pid 6394:tid 139960352917248] [client 5.104.113.88] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(asfunction|data|javascript|livescript|mocha|vbscript):" at ARGS:actions[0][drafttext]. [file "/usr/local/cwaf/rules/07_XSS_XSS.conf"] [line "223"] [id "212770"] [rev "2"] [msg "COMODO WAF: XSS Attack Detected||techniek.mijnelo.eu|F"] [data "Matched Data: data: found within ARGS:actions[0][drafttext]: <pclass=\x22western\x22><imgsrc=\x22data:image/png;base64,ivborw0kggoaaaansuheugaaanyaaabtcaiaaabs/g4saaac40leqvr4no3dpw7iqbygcvvkuucrfdka3acuyquukxglc8qtttwcwqfckgpadeaikcj3mdgglzbmq8vhvj7h+vujrmj/+wfseo3yziwjaj0n9qhg0zegxegqyiqimu2cyrh6+tgius5qstb9ptu9tj3n17lj47nuvgelqwvvyfylt9hbbqh7sbbijagxeoqycukmbcfgghajqyirimriegikcdeshbgjqoweiuacecnbijegxegqyiqimrkegalcjaqhzipbg1tr6w86t/2ruw7ycpzwwboh6+gocoa6hhdiijegxegqyiqimrkegalcjaqh1uaevybddrzcft+yma..."] [hostname "techniek.mijnelo.eu"] [uri "/lib/editor/atto/autosave-ajax.php"] [unique_id "V4YjZ7L7Hw0AABj62O0AAAAR"]


Hans.


In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

Comodo provides security software - and it looks like some of it is running on your server. 

It's decided that it doesn't like some parts of Moodle. Oddly, I hadn't seen this before but have seen similar issue several times in the last few months (with different security products).

This is one for your hosting support to sort out. It's nothing to do with Moodle. Moodle isn't a security risk. 

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -
Hi Howard,

Thought the problem was solved with the mod_security upgrade but ... it's not.

Got an error:

Forbidden

You don't have permission to access /user/profile/index.php on this server.

Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.


And in the server logging:
Sun Jul 17 12:36:12.597059 2016] [fcgid:warn] [pid 17261:tid 140645821814528] (32)Broken pipe: [client 5.104.113.88:36150] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function, referer: http://techniek.mijnelo.eu/course/modedit.php?add=label&type=&course=150&section=4&return=0&sr=0
[Sun Jul 17 18:20:36.802682 2016] [:error] [pid 24955:tid 140455949858560] [client 5.104.113.88:46648] [client 5.104.113.88] ModSecurity: Access denied with code 403 (phase 2). String match "deletefield" at ARGS_GET:action. [file "/usr/local/cwaf/rules/32_Apps_OtherApps.conf"] [line "243"] [id "220482"] [rev "1"] [msg "COMODO WAF: found CVE 2014-0010 attack||techniek.mijnelo.eu|F"] [hostname "techniek.mijnelo.eu"] [uri "/user/profile/index.php"] [unique_id "V4uwVLL7Hw0AAGF7zqUAAAAH"], referer: http://techniek.mijnelo.eu/user/profile/index.php


Any suggestions what this is?

Hans.
In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -

Most of it is solved.

http://cdn.mathjax.org/mathjax/2.6-latest/MathJax.js

in the Filter caused a problem with the mod_security settings. Moving it to the moodle site solved part of the problem.

mod_security settings needed to be adjusted by the hosting provider.


Still getting some 'you don't have access etc...'  error messages. I've asked the hosting provider to look into this.


Hans.

Average of ratings: Useful (1)
In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -
Didn't had an answer from my hosting provider yet.

Found something on a Comodo forum:
https://forums.comodo.com/free-modsecurity-rules-comodo-web-application-firewall-b223.0/-t114134.0.html
Could this be part of a solution? If so, what's the solution?

Any suggestions?

Hans.
In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

Do you have access to your web server's config files to configure mod_security? If not, or you have no idea (likely - nor do I really) then there's nothing you can do anyway. 

It's one for whoever set this stuff up.

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -

Hi Howard,

The hosting provider did an update on mod_security. It's updated now to 2.9.1

First impression is good.

Hans.

Average of ratings: Useful (1)
In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Ken Task -
Picture of Particularly helpful Moodlers

+1 to Howard's suggestion ...

Whatever COMODO is it's finding a vulnerability:
CVE 2014-0010

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0010

Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

Looks like a rule:
/usr/local/cwaf/rules/32_Apps_OtherApps.conf"] [line "243"] [id "220482"] [rev "1"

So what does line 243 in /usr/local/cwaf/rules/32_Apps_OtherApps.conf show?

The ip address from which you are accessing is what?

The apache error log line shows a client 5.104.113.88 - using port 36150.  Is that your IP address?

If that's *not* your IP as it would show to the moodle server, then sounds like
it's possible that remote attacker is hijacking session.   Before assuming the worse, however, check into this: http://resources.infosecinstitute.com/session-hijacking-cheat-sheet/

The forum posting you found has to do with Apache's Server Signature being on ... which would disclose things about apache, but your server has Server Signature OFF ... as it should be.   Test yourself ... go to http://yoursever/xxxx to force a 404 error.    Look at the bottom of the error page ... see info that discloses information about Apache version and mods, etc. loaded?    You shouldn't ... I don't see any sig.

What would happen *if you could* comment out that rule line/lines?

'spirit of sharing', Ken

In reply to Ken Task

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -

Hi Ken, Howard,

I don't understand the details of this mod_security thing but it's driving me nuts.

Again a problem??

Wanted to add an iframe in a label.

What's it nagging about.

Is it a Moodle (3.1.1.) problem or is Mod_security over reacting?

Any suggestions? (pleas keep in mind, I'm on a shared host with no apache root access).

Hans.


<iframe src="https://academo.org/demos/virtual-oscilloscope/?embedded=true" height="380" width="800"></iframe>


Forbidden

You don't have permission to access /course/modedit.php on this server.

Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

http://techniek.mijnelo.eu/course/modedit.php

Tue Jul 19 10:53:18.015559 2016] [:error] [pid 8099:tid 140301347845888] [client 5.104.113.88:51682] [client 5.104.xxx.xx] ModSecurity: Access denied with code 403 (phase 2). Pattern match "< {0,1}iframe" at ARGS:introeditor[text]. [file "/usr/local/cwaf/rules/07_XSS_XSS.conf"] [line "96"] [id "212280"] [rev "1"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||techniek.mijnelo.eu|F"] [data "Matched Data: <iframe found within ARGS:introeditor[text]: <br>bron virtuele oscilloscoop: https://github.com/edwardball/academo.org<br><iframe src=\\x22https://academo.org/demos/virtual-oscilloscope/?embedded=true\\x22 height=\\x22380\\x22 width=\\x22800\\x22></iframe>"] [severity "CRITICAL"] [hostname "techniek.mijnelo.eu"] [uri "/course/modedit.php"] [unique_id "V43qfrL7Hw0AAB@j5RwAAAAC"], referer: http://techniek.mijnelo.eu/course/modedit.php?update=3060&return=0&sr=0



In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Ken Task -
Picture of Particularly helpful Moodlers

Could attempt to explain each and every error COMODO/Modesurity) might find forever and ever, however, that would be futile (although educational).    Have no idea how many rules that package provides ... probably a large number judging the specific reference in the error log: 212280.

The resource you;'ve linked to is interactive (a good educational resource and appears NOT to be malicious IMHO), but it does ask my browser to allow access to my microphone.  To COMODO/Modseucity rules in play on the shared server, that's a no-no.

If your expectation is that someone can provide a 'work around' for it, those might be possible, but the explanation of that could be highly technical and, more than likely, a trial and error sort of thing ... which frustrates you even more.  Plus never work.

So ... how about a poor analogy ...

You are on a shared host.  Assume, then, that all customers on that shared server
host with this provider because they provide this 'service' (modsecurity).

This means you are a passenger (your site) on a bus (shared server) ... the bus is the hosting providers server upon which your site resides and the driver is whatever app/config the provider has setup.

Since you are not the driver, you may not be able to tell the driver of the bus to turn/stop/speed up nor turn on AC/Heat, etc., etc. because drivers actions affects/pertains to all other passengers on the bus.  **UNLESS** the provider grants you the access to control what security rules are used on your site(s) on that server.  Nothing Moodle can do about it.

You must talk to provider.  Mangelot Hosting (Netherlands)

I would have gone the extra mile and viewed their information from their home page, but would have to translate every page.   They might provide an upgrade path for you ... shared to something else that grants you, the customer, a 'bus driver's license'. ;)

Moodle has only setting to allow embedding or not.  It warns you that setting  presents
potential for XSS (cross site scripting).   Since the system hasn't evaluated what you've just copied and pasted into a dialog box, Moodle accepts the data with the checking it does.   After saving it, now modsecurity/COMODO etc. kicks in and won't allow.

Again ... you must talk to provider.

'spirit of sharing', Ken

In reply to Hans B0s

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

You are getting very close to the "find another host" point...

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Ken Task -
Picture of Particularly helpful Moodlers

Uhhh ... that 'close to' for me or the OP?   Been down this road before where the first thought and recommendation is 'find another hosting solution' ... which leads to more questions ... like "Why?" and comments such as  "I want to drive my volks like a jag and at the same $4.95 a month price."  (well, not really, but ...)  

Some folks just have to 'experience' and thus know beyond a shadow of a doubt (advice given by some stranger). ;)  When the pain of change is less than the pain of staying the same, then ....

'spirit of sharing', Ken

In reply to Ken Task

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Howard Miller -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers

Well... if it doesn't run and the support people can't/won't help then it really doesn't matter what it costs. 

A broken Jag and a broken VW are the same thing... you are still walking wink

In reply to Howard Miller

Re: You don't have permission to access /course/modedit.php on this server. Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.

by Hans B0s -

Hi Howard,

Your right. I'm still walking.

Perhaps I should be looking for an other host.

Any suggestions: Europe based, Moodle friendly, low-budget, 20 (or more) Gb,  ssh, reliable, serious about security.

Unless of course. mod_security/Comodo  becomes open source friendly. It's not only Moodle facing these problems.


Thank.

Hans.