modsecurity

  1. webmastergreg

    OWASP 3.3.2 and "ping" with rules 932150 and 1234123447

    Hello FYI I was confronted with the blocking of an interface following modsecurity blocking by rule N°1234123447 Precisely the request: "?_wblapi=/forsef/v1/ping" Triggers rule N°1234123447 because of the term "ping" In bold just below. ModSecurity: Access denied with code 501, [Rule: 'ARGS'...
  2. M

    [SOLVED] Update OWASP CRS?

    Is it possible to get the most updated OWASP Core Rule Set on CentOS? We would like to implement ModSecurity rules that are available on the latest versions. We’re on version 3.0 and the current stable version is 3.3. Are there compatibility issues with cPanel for the latest version?
  3. PeteS

    Error in ModSecurity transfer

    On transferring Service Configurations, ModSecurity completed with one failure: Failed: (XID 2chkk6) The WHM API v1 call “modsec_make_config_inactive” failed: The following configuration is not active: modsec_vendor_configs/OWASP3/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf Upon retrying it...
  4. leonep

    ModSecurity Traditional Mode or Anomaly Score

    Hi guys, based on your experience in a shared hosting environment it is preferable to set modsecurity to traditional mode or anomaly score? I am running on traditional but i have frequent false-positive. the good in traditional mode is less load on server. what do you think? thanks
  5. G

    Using ModSecurity

    I've installed mod_security2 and read the cPanel docs: https://blog.cpanel.com/how-to-install-and-configure-modsecurity-in-cpanel/ but I have a few other questions. 1. Should I install OWASP? What does it do? 2. I see under "Configuration" that I can provide a link to a MaxMind database...
  6. A

    ModSecurity SQL Injection

    Hi, the last few days i've been battling with one specific website (out of many on the same server) which wont render correctly. When inspecting, the site loads as plain HTML and the console shows a load of 403 or 404 errors for every image, CSS file or JS script. I have finally got it narrowed...
  7. leonep

    Modsecurity hit internal 127.0.0.1

    HI, I am wondering what are this hit from 127.0.0.1 from modsecurity. I have a lot of triggering event about 920340: Request Containing Content, but Missing Content-Type header 933150: PHP Injection Attack: High-Risk PHP Function Name Found 930130: Restricted File Access Attempt 920170: GET or...
  8. X

    SOLVED ModSecurity

    Is there a way to make ModSecurity send alert emails for every rule triger?
  9. rinkleton

    httpd crashing almost daily - log messages for modsecurity

    For about a week or so, httpd has been crashing about once a day. In the "Log Messages" section of the cpanel service failure notification email, it lists a bunch of modsecurity hits in red. Nothing stands out about them, just the run of the mill malicious bots. Maybe only the quantity...
  10. J

    SOLVED mod_security logs HUGE and Failed to access DBM file entries

    Hello. I hope everyone is safe and healthy and taking care of themselves and their loved ones. In my /var/log/apache/error_log file as of today the beginning entry is May 18, 2021. When I search for information about trimming this file (if it's okay to do so) I see reports that there should...
  11. DennisMidjord

    Blocking web crawlers. ModSecurity or in vhost?

    Lately, a lot of our customers' websites has been crawled by a lot of bots. Yesterday, a single website was crawled by 4 different bots at the same time. All of the bots were bad bots. We want to block these bots but I'm wondering which method is the best performance wise or if it really doesn't...
  12. benito

    No ModSecurity™ Domain Manager in cPanel

    Hello! A customer needed to disable ModSecurity. We found that in one server, none of our customers have ModSecurity™ Domain Manager icon in their cPanel. Looks installed and enabled in Feature Manager. I tried to reinstall and the problem persist. Any tip? Regards,
  13. R

    Debugging Modsec & Litespeed Server

    Hello Everyone, I have a strange one here, I have setup a new WordPress site/Directory and all of a sudden I am getting 404 errors on css and image file loading on this particular website. So, I can only think either ModSec is blocking this file types (they are not being triggered in the main...
  14. J

    modsec_audit always empty

    Hello. In my attempt to track down a malicious IP address attacking the server I've been looking at logs. Not only cannot I not find the malicious IP address in any logs which I know was attacking because a different service has logged it in it's application and it shows in that database -...
  15. R

    cPanel ModSecurity False Positives & Missing Data...

    Hi, My server runs the following ModSecurity Rules: Imunify360 LiteSpeed Rule Set (Minimized ModSec Ruleset) COMODO ModSecurity LiteSpeed Rule Set I had to disable the following rule set because it was causing a LOT off false positives within our WordPress websites, to the extent that we...
  16. manoaratefy

    Disable ModSecurity on default vhost

    Good morning, I need to serve something on my default vhost (the vhost who serves /var/www/html). How to disable ModSecurity in this area? .htaccess disabling not working ( SecFilterEngine Off)
  17. sneader

    Advice on enabling the cPanel/OWASP-CRS Mod Security Rule Set

    We have Mod Security enabled, and using mod sec rules developed and provided by our data center. It has worked out very well, but there are some things we like about the OWASP Core Rule Set (CRS) that cPanel is making available to us. I'm investigating enabling these rules, either in...
  18. N

    ModSecurity update causing 403 Forbidden for PUT requests to server, requires editing tx.allowed_methods

    Hi all, this may be nothing but I wanted to post my experience this morning with our website suddenly refusing PUT requests. This morning I visited the WHM interface and got an upgrade popup saying that new ModSecurity rules would be installed (my memory is not perfect but it definitely...
  19. N

    SOLVED ModSecurity cPanel False Info on version 92.0.4?

    Hello, I have version 92.0.4 and I see something strange. When I go to an account in cPanel and then SECURITY> ModSecurity says: But I'm sure the modsecurity is enabled on the server. I test it and blocks successful rules in domains, server etc. It's something wrong with this info inside...
  20. S

    SOLVED ModSecurity: IP whitelisting doesn't work

    Hello, I have added exclude rule to ModSecurity in /etc/apache2/conf.d/modsec/modsec2.user.conf to whitelisting Googlebot from being blocked, but it doesn't work. Googlebot will still blocked if accessing to robots.txt. SecRule REMOTE_ADDR "^66\.249\.xxx\.xxx$"...