XF 2.0 "Oops. We ran into some problems" -- only one user having problems

Dan Blather

Member
I have one user who is encountering the "Oops. We ran into some problems" error whenever they try to post. Nobody else is having these issues. The member has no bans or discouragement.

I searched, and can't find out anything about what might be causing this when it's just one forum user having these problems.
 
They haven't been able to reproduce it, but it just happened to me, after editing a message. Here's the error:

Code:
PHP: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">

<html><head>

<title>500 Internal Server Error</title>

</head><body>

<h1>Internal Server Error</h1>

<p>The server encountered an internal error or

misconfiguration and was unable to complete

your request.</p>

<p>Please contact the server administrator at

XXXXXXXXXX@cyburbia.org to inform them of the time this error occurred,

and the actions you performed just before this error.</p>

<p>More information about this error may be available

in the server error log.</p>

</body></html>

core-compiled.js:43:149

defaultAjaxError

https://www.cyburbia.org/forums/js/xf/core-compiled.js:43:149

t

https://www.cyburbia.org/forums/js/xf/core-compiled.js:40:144

i

https://www.cyburbia.org/forums/js/vendor/jquery/jquery-3.2.1.min.js:2:28012

fireWith

https://www.cyburbia.org/forums/js/vendor/jquery/jquery-3.2.1.min.js:2:28783

A

https://www.cyburbia.org/forums/js/vendor/jquery/jquery-3.2.1.min.js:4:14058

c/<

https://www.cyburbia.org/forums/js/vendor/jquery/jquery-3.2.1.min.js:4:16323

mod_security is OFF.
 
Last edited:
You will need to check the server error log for more details.

If you don't know where that is on the server, or don't have access to it, contact your host.
 
Here we go.

Code:
/forums/posts/181129/edit 1/23/19, 12:21 PM 535 error 500  POST HTTP/1.1 https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/ Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:64.0) Gecko/20100101 Firefox/64.0

That's it. Generic 500 error.

EDIT: Tried it using a different browser (Brave) on a different OS (MacOS 10.14). Same error.

Here's the error concole from Firefox on MacOS.

Code:
PHP: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>500 Internal Server Error</title>
</head><body>
<h1>Internal Server Error</h1>
<p>The server encountered an internal error or
misconfiguration and was unable to complete
your request.</p>
<p>Please contact the server administrator at
XXXXXXXX@cyburbia.org to inform them of the time this error occurred,
and the actions you performed just before this error.</p>
<p>More information about this error may be available
in the server error log.</p>
</body></html>
core-compiled.js:43:149

defaultAjaxError https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:43 t https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:40
i6jQuery
ajax https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:41
submit https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:178
submit https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:178
proxy https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:70
dispatch9jQuery init https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:175
c https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:118
e https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:119
f https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:119
activate https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:43
handleAjax https://www.cyburbia.org/forums/js/xf/message.min.js?_v=b79782e5:13
setupHtmlInsert https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:48
c https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:81
setupHtmlInsert https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:46
handleAjax https://www.cyburbia.org/forums/js/xf/message.min.js?_v=b79782e5:13
proxy https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:70
m https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:40
i6jQuery ajax https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:41
click https://www.cyburbia.org/forums/js/xf/message.min.js?_v=b79782e5:12
_click https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:116 b
https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:114
watch https://www.cyburbia.org/forums/js/xf/core-compiled.js?_v=b79782e5:117
 
Last edited:
More: injection protection false positives.

Code:
[Wed Jan 23 11:36:21.624037 2019] [:error] [pid 56885:tid 140499528660736] [client xxx.xxx.xxx.xxx:51922] [client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 500 (phase 2). Pattern match "(insert[[:space:]]+into.+values|select.*from.+[a-z|A-Z|0-9]|select.+from|bulk[[:space:]]+insert|union.+select|convert.+\\\\(.*from)" at ARGS:message_html. [file "/etc/apache2/conf.d/modsec2.liquidweb.conf"] [line "242"] [id "300016"] [rev "2"] [msg "Generic SQL injection protection"] [severity "CRITICAL"] [hostname "www.cyburbia.org"] [uri "/forums/posts/181129/edit"] [unique_id "XEiYBdcpqO@KnbLt5xZ0oAAAABA"], referer: https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/

[Wed Jan 23 11:36:25.375605 2019] [:error] [pid 56885:tid 140499633559296] [client xxx.xxx.xxx.xxx:51923] [client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 500 (phase 2). Pattern match "(insert[[:space:]]+into.+values|select.*from.+[a-z|A-Z|0-9]|select.+from|bulk[[:space:]]+insert|union.+select|convert.+\\\\(.*from)" at ARGS:message_html. [file "/etc/apache2/conf.d/modsec2.liquidweb.conf"] [line "242"] [id "300016"] [rev "2"] [msg "Generic SQL injection protection"] [severity "CRITICAL"] [hostname "www.cyburbia.org"] [uri "/forums/posts/181129/edit"] [unique_id "XEiYCdcpqO@KnbLt5xZ0pAAAAAQ"], referer: https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/

[Wed Jan 23 11:36:36.535259 2019] [:error] [pid 56885:tid 140499570620160] [client xxx.xxx.xxx.xxx:51924] [client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 500 (phase 2). Pattern match "(insert[[:space:]]+into.+values|select.*from.+[a-z|A-Z|0-9]|select.+from|bulk[[:space:]]+insert|union.+select|convert.+\\\\(.*from)" at ARGS:message_html. [file "/etc/apache2/conf.d/modsec2.liquidweb.conf"] [line "242"] [id "300016"] [rev "2"] [msg "Generic SQL injection protection"] [severity "CRITICAL"] [hostname "www.cyburbia.org"] [uri "/forums/posts/181129/edit"] [unique_id "XEiYFNcpqO@KnbLt5xZ0sgAAAAo"], referer: https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/
 
More: injection protection false positives.

Code:
[Wed Jan 23 11:36:21.624037 2019] [:error] [pid 56885:tid 140499528660736] [client xxx.xxx.xxx.xxx:51922] [client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 500 (phase 2). Pattern match "(insert[[:space:]]+into.+values|select.*from.+[a-z|A-Z|0-9]|select.+from|bulk[[:space:]]+insert|union.+select|convert.+\\\\(.*from)" at ARGS:message_html. [file "/etc/apache2/conf.d/modsec2.liquidweb.conf"] [line "242"] [id "300016"] [rev "2"] [msg "Generic SQL injection protection"] [severity "CRITICAL"] [hostname "www.cyburbia.org"] [uri "/forums/posts/181129/edit"] [unique_id "XEiYBdcpqO@KnbLt5xZ0oAAAABA"], referer: https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/

[Wed Jan 23 11:36:25.375605 2019] [:error] [pid 56885:tid 140499633559296] [client xxx.xxx.xxx.xxx:51923] [client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 500 (phase 2). Pattern match "(insert[[:space:]]+into.+values|select.*from.+[a-z|A-Z|0-9]|select.+from|bulk[[:space:]]+insert|union.+select|convert.+\\\\(.*from)" at ARGS:message_html. [file "/etc/apache2/conf.d/modsec2.liquidweb.conf"] [line "242"] [id "300016"] [rev "2"] [msg "Generic SQL injection protection"] [severity "CRITICAL"] [hostname "www.cyburbia.org"] [uri "/forums/posts/181129/edit"] [unique_id "XEiYCdcpqO@KnbLt5xZ0pAAAAAQ"], referer: https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/

[Wed Jan 23 11:36:36.535259 2019] [:error] [pid 56885:tid 140499570620160] [client xxx.xxx.xxx.xxx:51924] [client xxx.xxx.xxx.xxx] ModSecurity: Access denied with code 500 (phase 2). Pattern match "(insert[[:space:]]+into.+values|select.*from.+[a-z|A-Z|0-9]|select.+from|bulk[[:space:]]+insert|union.+select|convert.+\\\\(.*from)" at ARGS:message_html. [file "/etc/apache2/conf.d/modsec2.liquidweb.conf"] [line "242"] [id "300016"] [rev "2"] [msg "Generic SQL injection protection"] [severity "CRITICAL"] [hostname "www.cyburbia.org"] [uri "/forums/posts/181129/edit"] [unique_id "XEiYFNcpqO@KnbLt5xZ0sgAAAAo"], referer: https://www.cyburbia.org/forums/threads/cyburbia-forums-rules-and-guidelines.14714/


Whitelist ID 300016
in Modsecurity conf... or your host should do it for you...
 
Top Bottom