• Resolved Anonymous User 50911

    (@anonymized-50911)


    I stumbled across this redirect loop problem today afrer upgrading to 4.4.1 and soon found that disabling “Modsecurity” fixed problems.

    My problem was specifically /wp-admin loop, I was able to access admin pages with full url like /widgets.php and index.php but not just /wp-admin.

    I hope this issue is solved in future versions of WP because disabling Modsecurity cannot be long-term solution…

    Apache Version 2.4.16
    PHP Version 5.5.30
    MySQL Version 10.1.6-MariaDB-cll-lve

Viewing 4 replies - 1 through 4 (of 4 total)
  • oops

    I am having the same issue.

    [Thu Jan 07 16:07:45.128256 2016] [:error] [pid 93076:tid 47808259901760] [client xxxxxx] ModSecurity: Access denied with code 403 (phase 4). Pattern match "(?i)(String\\\\.fromCharCode\\\\(.*?){4,}" at RESPONSE_BODY. [file "/usr/local/apache/conf/modsec_vendor_configs/comodo_apache/14_Outgoing_FilterGen.conf"] [line "28"] [id "214560"] [rev "1"] [msg "COMODO WAF: Potential Obfuscated Javascript in Output - Excessive fromCharCode"] [data "Matched Data: String.fromCharCode(55356,56806,55356,56826),0,0),d.toDataURL().length>3e3):\\x22diversity\\x22===a?(e.fillText(String.fromCharCode(55356,57221),0,0),c=e.getImageData(16,16,1,1).data.toString(),e.fillText(String.fromCharCode(55356,57221,55356,57343),0,0),c!==e.getImageData(16,16,1,1).data.toString()):(\\x22simple\\x22===a?e.fillText(String.fromCharCode( found within RESPONSE_BODY: <!DOCTYPE html>\\x0a<!--[if IE 8]>\\x0a<html xmlns=\\x22https://www.w3.org/1999/xhtml\\x22 class=\\x22ie8 wp-toolbar\\x22 ..."] [severity "CRITICAL"] [hostname "www.example.com"] [uri "/wp-admin/index.php"] [unique_id "Vo7hsEPhnyAAAWuUfwQAAAAG"]

    Thread Starter Anonymous User 50911

    (@anonymized-50911)

    Longer thread is actually in different forum:
    https://www.ads-software.com/support/topic/redirect-loop-after-update-wordpress-441

    Maybe some kind admin will move this thread to troubleshooting as well ??

    @Allar: The thread you link to has no relation to your problem. I assume the problem with your site is just a settings error. The problem from that thread you linked to has to do with the CORE of wordpress new update and the problems/errors are different than what you have listed here. You should seek out your own solution on that wp-admin problem of yours.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Redirect loop solution – disable "Modsecurity"’ is closed to new replies.