{"version":"1.0","provider_name":"Rochen Documentation","provider_url":"https:\/\/www.rochen.com\/docs","author_name":"Wendy Robinson","author_url":"https:\/\/www.rochen.com\/docs\/author\/rochen-wendy\/","title":"The Benefits and Effects of mod_security - Rochen Documentation","type":"rich","width":600,"height":338,"html":"<blockquote class=\"wp-embedded-content\" data-secret=\"MtDFnh8s9O\"><a href=\"https:\/\/www.rochen.com\/docs\/documentation\/the-benefits-and-effects-of-mod_security\/\">The Benefits and Effects of mod_security<\/a><\/blockquote><iframe sandbox=\"allow-scripts\" security=\"restricted\" src=\"https:\/\/www.rochen.com\/docs\/documentation\/the-benefits-and-effects-of-mod_security\/embed\/#?secret=MtDFnh8s9O\" width=\"600\" height=\"338\" title=\"&#8220;The Benefits and Effects of mod_security&#8221; &#8212; Rochen Documentation\" data-secret=\"MtDFnh8s9O\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" class=\"wp-embedded-content\"><\/iframe><script type=\"text\/javascript\">\n\/* <![CDATA[ *\/\n\/*! This file is auto-generated *\/\n!function(d,l){\"use strict\";l.querySelector&&d.addEventListener&&\"undefined\"!=typeof URL&&(d.wp=d.wp||{},d.wp.receiveEmbedMessage||(d.wp.receiveEmbedMessage=function(e){var t=e.data;if((t||t.secret||t.message||t.value)&&!\/[^a-zA-Z0-9]\/.test(t.secret)){for(var s,r,n,a=l.querySelectorAll('iframe[data-secret=\"'+t.secret+'\"]'),o=l.querySelectorAll('blockquote[data-secret=\"'+t.secret+'\"]'),c=new RegExp(\"^https?:$\",\"i\"),i=0;i<o.length;i++)o[i].style.display=\"none\";for(i=0;i<a.length;i++)s=a[i],e.source===s.contentWindow&&(s.removeAttribute(\"style\"),\"height\"===t.message?(1e3<(r=parseInt(t.value,10))?r=1e3:~~r<200&&(r=200),s.height=r):\"link\"===t.message&&(r=new URL(s.getAttribute(\"src\")),n=new URL(t.value),c.test(n.protocol))&&n.host===r.host&&l.activeElement===s&&(d.top.location.href=t.value))}},d.addEventListener(\"message\",d.wp.receiveEmbedMessage,!1),l.addEventListener(\"DOMContentLoaded\",function(){for(var e,t,s=l.querySelectorAll(\"iframe.wp-embedded-content\"),r=0;r<s.length;r++)(t=(e=s[r]).getAttribute(\"data-secret\"))||(t=Math.random().toString(36).substring(2,12),e.src+=\"#?secret=\"+t,e.setAttribute(\"data-secret\",t)),e.contentWindow.postMessage({message:\"ready\",secret:t},\"*\")},!1)))}(window,document);\n\/* ]]> *\/\n<\/script>\n","description":"Before deploying mod_security we saw a lot of scripts (e.g. phpBB) being exploited through Cross Site Scripting (CSS) vulnerabilities. Hackers can exploit vulnerable scripts through CSS vulnerabilities by using carefully crafted URLs when hitting your scripts. E.g. script.php?post=hack-code-here etc. These exploited scripts can then be used to send Unsolicited Commercial..."}