I have had this enabled for a while but recently I been getting emails with the following:
Time: Wed Jun 9 08:50:00 2010 -0600
IP: 8*.***.***.*0 (GB/United Kingdom/host8*.***.***.*0.range**-***.btcentralplus.com)
Failures: 5 (mod_security)
Interval: 300 seconds
Blocked: Permanent Block
Log entries:
[Wed Jun 09 08:49:03 2010] [error] [client 8*.***.***.*0] ModSecurity: Access denied with code 501 (phase 2). Match of "rx ^((??:POS|GE)T|OPTIONS|HEAD))$" against "REQUEST_METHOD" required. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "38"] [id "960032"] [msg "Method is not allowed by policy"] [severity "CRITICAL"] [tag "POLICY/METHOD_NOT_ALLOWED"] [hostname "hosting.*********"] [uri "/"] [unique_id "TA@p37IgX0wAAD58hV4AAAAa"]
This is around 4 times per email
Can someone explain the above and roughly what the attempt was.
Thank you in advance.



LinkBack URL
About LinkBacks
?:POS|GE)T|OPTIONS|HEAD))$" against "REQUEST_METHOD" required. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "38"] [id "960032"] [msg "Method is not allowed by policy"] [severity "CRITICAL"] [tag "POLICY/METHOD_NOT_ALLOWED"] [hostname "hosting.*********"] [uri "/"] [unique_id "TA@p37IgX0wAAD58hV4AAAAa"]
Reply With Quote





