Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Feb 2009
    Posts
    8

    Default Who writes and maintains the default WHM mod_sec rules?

    I did search through these forums and I know where to find rules and documentation to make my own rule set; however, in the mean time, I would like to know if these WHM default rules are modsecurity.org's core rules or rules completely put together by cpanel?
    Do the default rules change when you update from modsecurity 1.x to 2.x in easapache, so that the rules are still compatible? Are they updated any other time?

  2. #2
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,768
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    We use a subset of the rules that are provided by the mod_security team. The subset is/was selected by testing the default rules provided against the procuct ( cPanel ) as well as some of the third party software provided ( e.g. wordpress ). Rules that cause a problem are dropped. Only rules that do not cause an issue are provided by our installation of mod_security.

    I believe the rule definition changed between mod_security 1 and 2, but the end result should be the same.

    The rules are only updated when updating mod_security.

    There is support in place for providing your own rules, which are generally preserved across mod_security updates ( a warning might be issued when changing major versions ). These of course are updated whenever you opt to change them.

  3. #3
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,172
    cPanel/Enkompass Access Level

    Root Administrator

Similar Threads & Tags
Similar threads

  1. Updated mod_sec rules
    By p0liX in forum Security
    Replies: 143
    Last Post: 10-02-2011, 08:01 AM
  2. Updated mod_sec rules
    By p0liX in forum cPanel and WHM Discussions
    Replies: 117
    Last Post: 12-14-2009, 01:30 PM
  3. mod_sec rules (where to get the best version)
    By cookiesunshinex in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 06-30-2009, 12:12 AM
  4. Can someone help with mod_sec rules and an application I am trying to run?
    By betoranaldi in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 05-15-2009, 02:06 PM
  5. mod_sec rules to drop this...
    By chae in forum cPanel Developers
    Replies: 4
    Last Post: 11-13-2006, 01:10 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube