+ Reply to Thread
Results 1 to 11 of 11

What's that with the Sucuri Website Firewall?

  1. #1
    Registered User
    Join Date
    08-05-2017
    Location
    UTC+07:00
    MS-Off Ver
    2016
    Posts
    46

    What's that with the Sucuri Website Firewall?

    Hi Moderators/Administrators,

    I'm new here. My posts here were worked as it should until two days ago (9/2/2017), where, if I post something with a tag, like code tag or even italics/bold tag, I get a Sucuri Website Firewall alert, saying that HTML content is not allowed.

    As a result, I could not post my codes in their proper form, not to mention stressing something in bold or quoting someone's response.

    I went to the Scuri Website and had a chat with their people, demanding an explanation, but they said YOU are the one who used their service and set the block. YOU are the one who decides who's on the white list and who's not.

    I'm confused. I'm a registered user, just like everyone else. Why am I special? Have I done something wrong?

  2. #2
    Forum Guru Glenn Kennedy's Avatar
    Join Date
    07-08-2012
    Location
    Northern Ireland
    MS-Off Ver
    Excel 2010.. mostly
    Posts
    14,342

    Re: What's that with the Sucuri Website Firewall?

    If, for example you tried to post ">10..." it won't let you (sometimes) unless you put a space in after the > symbol.

    It just let me do it now, though...

    The quirkiness of Old Sucky is one of the many "endearing" features of the Forum,.
    Glenn



  3. #3
    Registered User
    Join Date
    08-05-2017
    Location
    UTC+07:00
    MS-Off Ver
    2016
    Posts
    46

    Re: What's that with the Sucuri Website Firewall?

    You know what...it works now.

    Usually, I paste a code segment, select it and clicked "#" to wrap a
    Please Login or Register  to view this content.
    I'm really confused. I'm new here, but not new to forums. Never seen anything like this.

  4. #4
    Forum Guru Glenn Kennedy's Avatar
    Join Date
    07-08-2012
    Location
    Northern Ireland
    MS-Off Ver
    Excel 2010.. mostly
    Posts
    14,342

    Re: What's that with the Sucuri Website Firewall?

    Learn to live with it..... The owners aren't hugely responsive to "issues". That said, it's a lot better than it once was...

  5. #5
    Forum Expert Doc.AElstein's Avatar
    Join Date
    05-23-2014
    Location
    '_- Hidden - Scroll to the right in the Code Window '_-
    MS-Off Ver
    Office 2007 2010 PC but Not mac. XP and Vista mostly
    Posts
    3,419

    What's that with the Sucuri Website Firewall? - It don't like some character combinations

    Glenn, I don’t think I have seen any instances where the > causes the Sucuri firewall to pop up. I think what you are referring to is the <
    That frequently causes the the Sucuri firewall to pop up.

    You would never normally get something like _..

    <1000

    _..to post without the Sucuri firewall to popping up.

    That is the most common character combination that we see causing the Sucuri firewall to pop up: It is is the < followed by 4 or more characters. The reason why I say characters in italics is that that statement is not strictly correct: That is because not all characters after the < cause the problem. The space is one “character” that doesn’t cause the Sucuri firewall to pop up.
    So <100 or < 10 or <10 0 or <10 are all OK: You see I have broken up the 4 forbidden characters with an allowed character. ( A space is an allowed “character” )
    The most common workaround we suggest is to add a space after the <
    So < 1000 is OK – here Sucurri sees as the first 4 characters after the < as < 100

    The other workaround which I used above to get <1000 to post in this forum post is to break up the 4 forbidden characters with another allowed character which is the [
    That [ is used for a BB CODE tag, so you can do the “Black character trick” to get <1000 to post:
    What you post is this, (which is the normal way in BB Code in making one of the characters black)
    <10[color=Black]0[/color]0

    Sucuri firewall works on what you have in the editor before you post and not what you finally see. So it accepts <10[color=Black]0[/color]0
    As far as Sucurri is concerned, it sees as the first 4 characters after the < as 10[c
    The allowed [ has cured the problem

    That is also a way to get rude words past the sensor… Of course, Glenn, we wouldn’t fucking do that, would we?


    Here some references to the < problem and the other things Sucuri firewall dose not like:
    https://www.excelforum.com/suggestio...ml#post4666465
    https://www.excelforum.com/the-water...ml#post4645090
    https://www.excelforum.com/suggestio...ml#post4626828
    https://www.excelforum.com/suggestio...ml#post4615552
    https://www.excelforum.com/developme...ml#post4641199
    http://www.excelforum.com/developmen...ml#post4295092
    http://www.excelforum.com/the-water-...ml#post4283991
    http://www.excelforum.com/suggestion...ml#post4412541
    https://www.excelforum.com/the-water...ml#post4591609
    http://www.excelforum.com/showthread...41#post4412541
    http://www.excelforum.com/the-water-...ml#post4226385
    http://www.excelforum.com/suggestion...-a-thread.html
    http://www.excelforum.com/showthread...t=#post4520072
    http://www.excelforum.com/showthread...t=#post4502342



    Once you know about these little “fun” characteristics, and the work arounds, you almost grow fond of them – they add a sort of imperfect human character to the forum , ….



    Alan
    Last edited by Doc.AElstein; 09-05-2017 at 03:30 AM.
    '_- Google first, like this _ site:ExcelForum.com Gamut
    Use Code Tags: Highlight code; click on the # icon above,
    Post screenshots COPYABLE to a Spredsheet; NOT IMAGES PLEASE
    http://www.excelforum.com/the-water-...ml#post4109080
    https://app.box.com/s/gjpa8mk8ko4vkwcke3ig2w8z2wkfvrtv
    http://excelmatters.com/excel-forums/ ( Scrolll down to bottom )

  6. #6
    Forum Expert Doc.AElstein's Avatar
    Join Date
    05-23-2014
    Location
    '_- Hidden - Scroll to the right in the Code Window '_-
    MS-Off Ver
    Office 2007 2010 PC but Not mac. XP and Vista mostly
    Posts
    3,419

    Re: What's that with the Sucuri Website Firewall?

    Quote Originally Posted by ysdai7287 View Post
    .. "Go Advanced" or "Post Quick Reply"..the Scuri Website Firewall shot me down...
    Hi ysdai7287,
    I have sometimes experienced the Scuri Website Firewall shooting me down when I "Go Advanced" or "Post Quick Reply" . Usually that is just temporary and if I have another go, and / or refresh the page and have another go then all is well.
    But Important : Always copy the contents of your reply window to the clipboard before hitting "Go Advanced". This precaution is a good idea as another inconsistent forum Bug is that reply contents can vanish without trace when doing things like Editing or Going Advanced. (If that does then happen, then you can then paste your back up from the clipboard)

    https://www.excelforum.com/exceltip-...ens-when_.html

    ( Alternatively prepare all your posts in WORD or a text document , ( then copy them to the forum editor when ready to post) as many of us do, so you always have a back up )

    Alan
    Last edited by Doc.AElstein; 09-05-2017 at 03:23 AM.

  7. #7
    Registered User
    Join Date
    08-05-2017
    Location
    UTC+07:00
    MS-Off Ver
    2016
    Posts
    46

    Re: What's that with the Sucuri Website Firewall?

    Thanks Doc for your very informative explanation. It certainly cleared up a lot of things.

    I usually have the habit Ctrl-A & Ctrl-C in the edit window before hitting Reply, but that was back when the Internet connection wasn't that stable. Haven't been posting in forums in a long time and I had no idea now there's a new Scuri threat in place, and this backup habit was also forgotten along the way.

    The only tags that I use are usually [Quote] and [Code]. Might be something like a <snip> in the quote area or similar thing somewhere in the code box that tripped the alarm. And since I did not backup, I never knew what hit me.

    Thanks a lot! You saved my day.

  8. #8
    Forum Expert Doc.AElstein's Avatar
    Join Date
    05-23-2014
    Location
    '_- Hidden - Scroll to the right in the Code Window '_-
    MS-Off Ver
    Office 2007 2010 PC but Not mac. XP and Vista mostly
    Posts
    3,419

    Re: What's that with the Sucuri Website Firewall?

    Hi ysdai7287
    You is welcome. If you ever pin down a new specific thing that causes the Sucuri Website Firewall to pop up, then let us know.. we must make a list of them and the workarounds sometime….

    I think the general reason for the Sucuri Website Firewall being in place is to stop people / spammers trying to insert / inject bits of SQL code or similar. …. - Some of the less common reported problems are when you use words or word combinations like SQL commands. You will find those in the referenced links, but they are much more tricky to pin down.
    ( Regardless of what actually trips the Sucuri Website Firewall, it usually gives a message saying forbidden HTML. Also it usually says some incorrect crap about what browser you are using. So the messages and report it gives you is not to be taken too seriously )
    Alan


    P.S. if you have problems posting and want to experiment first before posting “for real”, or if you want to experiment generally with these and any other posting problems, then you can start a test Thread here: https://www.excelforum.com/development-testing-forum/
    Just give the Thread a Title like “Just testing, no reply needed”. ( You have to be logged in to “see” that Sub Forum.) You can practice and test any posting stuff there

  9. #9
    Registered User
    Join Date
    08-05-2017
    Location
    UTC+07:00
    MS-Off Ver
    2016
    Posts
    46

    Re: What's that with the Sucuri Website Firewall?

    Quote Originally Posted by Doc.AElstein View Post
    ...If you ever pin down a new specific thing that causes the Sucuri Website Firewall to pop up, then let us know.. we must make a list of them and the workarounds sometime….
    Is there already a list like this somewhere, like in a single thread? If so, I will then know whether or not it's already been covered.
    And yes, if this does happen again, I'll go play around in that subforum.

  10. #10
    Forum Expert Doc.AElstein's Avatar
    Join Date
    05-23-2014
    Location
    '_- Hidden - Scroll to the right in the Code Window '_-
    MS-Off Ver
    Office 2007 2010 PC but Not mac. XP and Vista mostly
    Posts
    3,419

    Re: What's that with the Sucuri Website Firewall?

    Quote Originally Posted by ysdai7287 View Post
    Is there already a list like this somewhere, like in a single thread? ...
    Hi
    No, .. I was hoping to get around to doing it sometime.. The URL list in Post #5 contains, I think, most of the reported problems, at least the ones I have noticed reported or experienced myself.
    (Some of those threads there report / talk about the same problem).

    If you come across anything new, then pop a reply in this Thread ( you are allowed to "Add solutions to existing threads even if they are Solved - it does not then come under the forbidden "High jacking" of a thread). I am subscribed to this Thread, so I will catch any additions you make.
    Thanks
    Alan
    Last edited by Doc.AElstein; 09-10-2017 at 05:08 AM.

  11. #11
    Registered User
    Join Date
    08-05-2017
    Location
    UTC+07:00
    MS-Off Ver
    2016
    Posts
    46

    Re: What's that with the Sucuri Website Firewall?

    Yes sir, got it. Thanks.

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0 RC 1