<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: WordPress vs. mod_security</title>
	<atom:link href="http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/</link>
	<description>Software, the Internet and you.</description>
	<pubDate>Mon, 12 May 2008 16:16:16 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: DS</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-40030</link>
		<dc:creator>DS</dc:creator>
		<pubDate>Tue, 30 Oct 2007 23:15:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-40030</guid>
		<description>Thanks alot, that was very helpful.</description>
		<content:encoded><![CDATA[<p>Thanks alot, that was very helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Slevi</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-39110</link>
		<dc:creator>Slevi</dc:creator>
		<pubDate>Fri, 12 Oct 2007 14:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-39110</guid>
		<description>Thanks for the tip, I was having issues with this in the past but just couldn't come with a better solution than writing P'ython instead :P. Will keep this one in mind :D.</description>
		<content:encoded><![CDATA[<p>Thanks for the tip, I was having issues with this in the past but just couldn&#8217;t come with a better solution than writing P&#8217;ython instead :P. Will keep this one in mind :D.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesse</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-38975</link>
		<dc:creator>Jesse</dc:creator>
		<pubDate>Wed, 10 Oct 2007 00:55:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-38975</guid>
		<description>Thanks a bunch for the tip. I was very nearly pulling out my hair wondering why the "P" word was giving me 403 errors on my blog. The span solution seems to have done the trick. ;)</description>
		<content:encoded><![CDATA[<p>Thanks a bunch for the tip. I was very nearly pulling out my hair wondering why the &#8220;P&#8221; word was giving me 403 errors on my blog. The span solution seems to have done the trick. <img src='http://www.thunderguy.com/semicolon/wp/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-35247</link>
		<dc:creator>David</dc:creator>
		<pubDate>Sun, 05 Aug 2007 00:41:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-35247</guid>
		<description>I had the same problem on a website I am developing hosted at http://www.aiso.net/. It was filtering out "python" with a space at the end. Considering I was trying to post a media r release which contained the word "carpet python" - it took me quite some time to figure out why on earth i was getting a 403.

However, I contacted tech support, told them of the problem, they figured it was mod_security and removed the rule.

Frankly though, I'd rather not have mod_security enabled in the first place. I'd rather just write secure web applications.

David.</description>
		<content:encoded><![CDATA[<p>I had the same problem on a website I am developing hosted at <a href="http://www.aiso.net/" rel="nofollow">http://www.aiso.net/</a>. It was filtering out &#8220;python&#8221; with a space at the end. Considering I was trying to post a media r release which contained the word &#8220;carpet python&#8221; - it took me quite some time to figure out why on earth i was getting a 403.</p>
<p>However, I contacted tech support, told them of the problem, they figured it was mod_security and removed the rule.</p>
<p>Frankly though, I&#8217;d rather not have mod_security enabled in the first place. I&#8217;d rather just write secure web applications.</p>
<p>David.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bennett</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-34106</link>
		<dc:creator>Bennett</dc:creator>
		<pubDate>Tue, 10 Jul 2007 22:37:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-34106</guid>
		<description>If you try to post a comment with the magic text in it, you simply end up with a 403 error and the comment never gets through. (I just tried it.) The filter applies only to incoming text -- this includes the POST body and the URL.</description>
		<content:encoded><![CDATA[<p>If you try to post a comment with the magic text in it, you simply end up with a 403 error and the comment never gets through. (I just tried it.) The filter applies only to incoming text &#8212; this includes the POST body and the URL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Software Evolution &#187; Blog Archive &#187; WordPress vs. mod_security</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-30812</link>
		<dc:creator>Software Evolution &#187; Blog Archive &#187; WordPress vs. mod_security</dc:creator>
		<pubDate>Mon, 18 Jun 2007 10:35:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-30812</guid>
		<description>[...] More:  continued here  [...]</description>
		<content:encoded><![CDATA[<p>[...] More:  continued here  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ozh</title>
		<link>http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-29403</link>
		<dc:creator>Ozh</dc:creator>
		<pubDate>Thu, 14 Jun 2007 08:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.thunderguy.com/semicolon/2007/06/13/wordpress-vs-mod_security/#comment-29403</guid>
		<description>Weird. This seems to be a totally dumb rule to add into mod_security, I thought this was only filtering on GET (maybe POST?) urls. What then if someone comments with a filtered word? Does it ban the whole page? That's dumb :)

You should warn your hosting company about this issue, and by the way ask them a list of censored words. Then, you'll make in seconds a plugin converting all "censored" into "cen&#60;em&#62;&#60;/em&#62;sored" or something.</description>
		<content:encoded><![CDATA[<p>Weird. This seems to be a totally dumb rule to add into mod_security, I thought this was only filtering on GET (maybe POST?) urls. What then if someone comments with a filtered word? Does it ban the whole page? That&#8217;s dumb <img src='http://www.thunderguy.com/semicolon/wp/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>You should warn your hosting company about this issue, and by the way ask them a list of censored words. Then, you&#8217;ll make in seconds a plugin converting all &#8220;censored&#8221; into &#8220;cen&lt;em&gt;&lt;/em&gt;sored&#8221; or something.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
