Quote:
Yeah, dont turn these off the way you have, thats a total global exclusion you've got there.

Thanks for the reply! Well, I've only got one site on the server so it's probably not as bad as it could be but...
So I've clipped what I think is important from the audit log and censored out sensitive information from the post. So strangely, the first
&profile%5fwebsite1=http%3a%2f%2fwww%2ewebsitedomain%2ecom
doesn't cause a problem and will not 404. Only after I enter a 2nd entry, in this case, the next section of the string
&profile%5fpersonalblog=http%3a%2f%2fwww%2ewebsitedomain%2ecom
causes it to 404.
I hope this is the right information. By the way, if I rem out the 340162, then the following 3 kick in 340163, 340147, 340007 causing the same 404. Again, it works fine if I have a single field like website1 field filled in, but as soon as I add a second field, like personalblog, it 404's.
--8dbe1118-I--
name=username&mail=email%40emaildomain%2ecom&pass%5bpass1%5d=&pass%5bpass2%5d=&status=1&signature=%3cp%3e%0d%0a%09fdg+sfdg+fds+gfd+sgf+sgf+ds%3c%2fp%3e%0d%0a&signature%5fformat=1&profile%5fname=Webmaster&profile%5fbio=%3cp%3e%0d%0a%09g+fds+gfds+gfds+gf+sdgf+ds%3c%2fp%3e%0d%0a&profile%5frole%5fstaff=1&profile%5fwebsite1=http%3a%2f%2fwww%2ewebsitedomain%2ecom&profile%5fpersonalblog=http%3a%2f%2fwww%2ewebsitedomain%2ecom&profile%5ftwitter=&profile%5ffacebook=&profile%5flinkedin=&profile%5fpinkposse=&profile%5fphone=&profile%5faddress1=&profile%5faddress2=&profile%5fcity=&profile%5fstate=&profile%5fzip=&profile%5fcountry=&profile%5fbirthday%5bmonth%5d=6&profile%5fbirthday%5bday%5d=1&profile%5fbirthday%5byear%5d=2010&node%5fnotify%5fmailalert=1&comment%5fnotify%5fmailalert=1&timezone=%2d28800&xmlsitemap%5fuser%5fpriority=%2d2&form%5ftoken=00000000000000000000000000000000&form%5fbuild%5fid=form%2d00000000000000000000000000000000&form%5fid=user%5fprofile%5fform&op=Save&securelogin%5foriginal%5fbaseurl=http%3a%2f%2fwww%2ewebsitedomain%2ecom
--8dbe1118-F--
HTTP/1.1 404 Not Found
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Mon, 28 Mar 2011 21:07:25 GMT
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
--8dbe1118-H--
Message: Access denied with code 403 (phase 2). Match of "beginsWith http://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/usr/local/apache/conf/modsec_rules/10_asl_rules.conf"] [line "455"] [id "340162"] [rev "193"] [msg "Atomicorp.com - FREE UNSUPPORTED DELAYED FEED - WAF Rules: Remote File Injection attempt in ARGS (AE)"] [data "4125"] [severity "CRITICAL"]
Action: Intercepted (phase 2)
Stopwatch: 1301346445201088 633494 (7671* 15435 -)
Producer: ModSecurity for Apache/2.5.13 (
http://www.modsecurity.org/).
Server: Apache
--8dbe1118-Z--