• This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn more.

XF 1.4 Random auto redirect from thread to site homepage

#1
Random threads, mostly new, won't load; & send you to the website homepage. Just started happening in the last 2 weeks. Affects all browsers. You click on the thread & get sent to homepage. The new problem threads were created on devices using the latest version Tapatalk, and those threads can be viewed & replied to if they have the latest version. That theory went bad when I found a previously good thread from 2008 now not loading & auto redirecting also...forum not updated since last year; only tapatalk add-on updated in the past year; on 1/29/17 v 3.1.14.....any ideas?
 

Brogan

XenForo moderator
Staff member
#2
The new problem threads were created on devices using the latest version Tapatalk, and those threads can be viewed & replied to if they have the latest version.
If you mean the problem happens when using tapatalk, you would have to contact the tapatalk developers for support.
 
#3
Tapatalk is installed on forum, But I don't use it & do not have it installed on my computer or phone. Today I created a thread & it redirected to site homepage...
 
#4
Explain the thread naming scheme for the URL. 1 of my isp's firewall rules said having a period in title is an injection attack & blocks it....



It appears that his forum URL naming scheme might be triggering the rules. It is adding a period into the URL and some slashes. This is being interpreted as an injection attack.



GET /forum/index.php?threads/erin-hills-us-open.11166/
 

Brogan

XenForo moderator
Staff member
#5
The period is required - it is the delimiter between the route/URL and the ID.
That cannot be changed.

Your host will have to whitelist that rule.
If they won't/can't, you will have to find a new host.
 

Tracy Perry

Well-known member
#7
They are using OWASP; maybe you guys should let them know there's a problem with one of their rules...
Those rules are not perfect for everything. They typically have to be adjusted. That's why there is the ability to do it.
If they refuse to do it, then the suggestion for looking for another host would still apply.