Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member Solokron's Avatar
    Join Date
    Aug 2003
    Posts
    783

    Question Modsec Exception Rule

    I have been going through the modsec documentation and I am not sure about how to accomplish this.

    The following rules help out greatly in deterring most injection exploits:

    SecFilterSelective REQUEST_URI "!(horde/services/go\.php)" "chain,id:390144,rev:1,severity:2,msg:'Rootkit attack: Generic Attempt to install rootkit'"
    SecFilterSelective REQUEST_URI "=(http|www|ftp)\:/(.+)\.(c|dat|kek|gif|jpe?g|jpeg|png|sh|txt|bmp|dat|txt|js|html?|tmp|asp)\x20?\?"
    SecFilterSelective REQUEST_URI "!(horde/services/go\.php)" "chain,id:390145,rev:1,severity:2,msg:'Rootkit attack: Generic Attempt to install rootkit'"
    SecFilterSelective REQUEST_URI "=(http|www|ftp)\:/(.+)\.(c|dat|kek|gif|jpe?g|jpeg|png|sh|txt|bmp|dat|txt|js|html?|tmp|asp)\?"

    The problem I am encountering is PHP Live uses a referrer listing in the addresses which is triggering this rule:

    /livehelp/image.php?l=phpadmin&x=1&deptid=0&pagex=http%3A//www.website.com/&unique=1173772540796
    &refer=http%3A//www.referringwebsite.com/details.asp%3FID%3D3754&text= HTTP/1.1

    How would a go about creating an exception rule to allow the rule to function as normally but ignore image.php in this case?


    Thanks!

  2. #2
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Specify the page instead of making it too generic. Generic rules can get you into trouble.
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  3. #3
    Member Solokron's Avatar
    Join Date
    Aug 2003
    Posts
    783

    Default

    I appreciate the response. Unfortunately it does not answer the question.

    Quote Originally Posted by ramprage View Post
    Specify the page instead of making it too generic. Generic rules can get you into trouble.

  4. #4
    Member
    Join Date
    Aug 2002
    Posts
    1,120

    Default

    Have a look at this thread:

    http://forums.cpanel.net/showthread.php?t=56518

    See if that is what you are after.

  5. #5
    Member Solokron's Avatar
    Join Date
    Aug 2003
    Posts
    783

    Default

    That is exactly what I was looking for. Thank you Sparek-3.

    Quote Originally Posted by sparek-3 View Post
    Have a look at this thread:

    http://forums.cpanel.net/showthread.php?t=56518

    See if that is what you are after.

Similar Threads & Tags
Similar threads

  1. Critical Exception in CPanel
    By jhajeer in forum New User Questions
    Replies: 1
    Last Post: 01-29-2010, 10:43 AM
  2. Why modsec.conf Rule reset to default every cpanel upgrade
    By dlthhost in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 08-30-2007, 10:39 PM
  3. Mod_security exception
    By _xandih in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 10-20-2006, 03:08 PM
  4. [Unknown exception] in /
    By cosmin in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 04-05-2006, 03:06 PM
  5. Mailscannner filename exception rule?
    By dory36 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 01-14-2005, 08:19 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube