The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Apache errors when using OWASP ModSecurity

Discussion in 'Security' started by tomdchi, Mar 7, 2015.

  1. tomdchi

    tomdchi Well-Known Member

    Joined:
    Feb 24, 2008
    Messages:
    115
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Atlanta, GA
    cPanel Access Level:
    DataCenter Provider
    I just upgraded to the latest WHM (11.48.1) and enabled the OWASP ModSecurity rule set. I am seeing these errors in the apache logs:

    Code:
    [Fri Mar 06 17:42:23 2015] [error] [client 204.17.62.24] ModSecurity: Audit log: Failed to create subdirectories: /usr/local/apache/logs/modsec_audit/apisure/20150306/20150306-1742 (Read-only file system)
    
    [Sat Mar 07 14:49:39 2015] [error] [client 72.236.170.26] ModSecurity: collection_store: Failed to access DBM file "/var/cpanel/secdatadir/ip": Permission denied
    
    [Sat Mar 07 14:49:39 2015] [error] [client 72.236.170.26] ModSecurity: Geo Lookup: Failed to lock proc mutex: Permission denied
    What can I do to fix these?
     
  2. cPanelPeter

    cPanelPeter Technical Analyst III
    Staff Member

    Joined:
    Sep 23, 2013
    Messages:
    569
    Likes Received:
    15
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello,

    I'm guessing you have ModRuid2 enabled? If so documentation may help you.
     
  3. keat63

    keat63 Well-Known Member

    Joined:
    Nov 20, 2014
    Messages:
    765
    Likes Received:
    20
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    I too also get these, and i'm using Ruid2.
    Ruid2 appears to be creating some errors with an OS Commerce site i'm toying with, so I'm considering temporarily removing Ruid2 this evening to see the outcome.

    I'm happy to report back here tomorrow if it helps.
     
Loading...

Share This Page