The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

how to block these php code using mod_security

Discussion in 'Security' started by kevinchong, Dec 21, 2014.

  1. kevinchong

    kevinchong Registered

    Joined:
    Nov 8, 2014
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Hello,

    I have problem to create mod_security rules. I want to block people from upload or access these php codes in my server.

    - Removed -

    Can anyone help me?
     
    #1 kevinchong, Dec 21, 2014
    Last edited by a moderator: Dec 21, 2014
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
  3. quizknows

    quizknows Well-Known Member

    Joined:
    Oct 20, 2009
    Messages:
    942
    Likes Received:
    57
    Trophy Points:
    28
    cPanel Access Level:
    DataCenter Provider
    ModSecurity cannot block requests based on the content of the file that is being requested unless you use response body filtering.

    The main thing is to prevent compromise in the first place with a good rule set and your users keeping their CMS software updated. I know compromises will always happen some percentage of the time especially if you host a lot of sites, but trying to prevent access to the php shells after the fact is kind of a moot point; you need to determine the method of hack (bad/weak/compromised password, old vulnerable plugin, etc), then restore a known good backup, and patch the initial issue (update it, new passwords, etc.).
     
Loading...

Share This Page