<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheets/rss.css" type="text/css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Just a Thought...: What is mod_security?</title>
    <link>http://bloritsch.d-haven.net/articles/2007/07/25/what-is-mod_security</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>Random thoughts</description>
    <item>
      <title>What is mod_security?</title>
      <description>&lt;p&gt;It&amp;#8217;s an &lt;a href="http://www.modsecurity.org/"&gt;Apache plugin&lt;/a&gt;  designed to drastically cut down on spam.  We&amp;#8217;re talking referrer spam, comment spam, etc.  It checks &lt;span class="caps"&gt;URL&lt;/span&gt; parts, submitted content, etc.  I was quite surprised to find out about it, because I didn&amp;#8217;t sign up for it.  It was preconfigured with my host, TextDrive.  I found out because I was writing a blog entry dealing with OpenID, and my personal plans for using it.  When I submitted the article the server responded with a mysterious &amp;#8220;Precondition Failed&amp;#8221; message.  I was sure Typo was to blame for it.  Apparently there was something (I couldn&amp;#8217;t tell you what right now) that caused mod_security to kick in and reject my post.&lt;/p&gt;


	&lt;p&gt;Rather than trying to find out what the protected words are, particularly since they will likely change, I&amp;#8217;m going to try and have mod_security lifted only for the content editing portion of Typo.  I really want it&amp;#8217;s protection for comment spam and referrer spam.  If it&amp;#8217;s an all or nothing proposition (remember that Rails apps are proxied through Apache, and the .htaccess file is not read), then I will have to live with the mod_security restrictions.&lt;/p&gt;


	&lt;p&gt;I may have to resort to doing everything through the blog web service.  We&amp;#8217;ll see how it goes.  So, if any of you types a comment and instead of seeing it on my blog you see some ominous &amp;#8220;Precondition Failed&amp;#8221; message it&amp;#8217;s because you are trying to spam me!  No seriously, it&amp;#8217;s because you hit on a keyword that a bunch of spammers use.&lt;/p&gt;</description>
      <pubDate>Wed, 25 Jul 2007 23:09:00 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:fd91a052-d563-4ffe-9b61-fe07736e4e24</guid>
      <author>Berin Loritsch</author>
      <link>http://bloritsch.d-haven.net/articles/2007/07/25/what-is-mod_security</link>
      <category>mod_security</category>
      <category>blog</category>
      <category>typo</category>
      <category>hosting</category>
    </item>
  </channel>
</rss>
