You can't unless you remove their ability to run any perl CGI scripts. That's why I said that it isn't possible.My friend (a hacker) still can use cgi/perl as a webshell. How can I disable cgi/perl shell function like I disable functions show_source, system, shell_exec, passthru, exec on php
Strange!! There was no # on the line LoadModule security_module libexec/mod_security.soSyntax error on line 286 of /usr/local/apache/conf/httpd.conf:
Cannot add module via name 'mod_security.c': not in list of loaded modules
OK, I'll try it.You can't unless you remove their ability to run any perl CGI scripts. That's why I said that it isn't possible.
If you've installed mod_security through WHM, try uninstalling it and then reinstall it to quickly fix the error.
Trying to reinstall itYou can't unless you remove their ability to run any perl CGI scripts. That's why I said that it isn't possible.
If you've installed mod_security through WHM, try uninstalling it and then reinstall it to quickly fix the error.
Trying to see the error messageAddon Modules
Main >> cPanel >> Addon Modules
Updating addonupdates....
Done
Updating modsecurity....
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/.cpanelsync.lock (0)[email protected]
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686.tar.bz2 (0)[email protected]%......Done
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/.cpanelsync.bz2 (0)[email protected]%......Done
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/install.bz2 (0)[email protected]%......Done
Got file ./install ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/uninstall.sql.bz2 (0)[email protected]%......Done
Got file ./uninstall.sql ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/modsec.sql.bz2 (0)[email protected]%......Done
Got file ./modsec.sql ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/addon_modsec.cgi.bz2 (0)[email protected]%......Done
Got file ./addon_modsec.cgi ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/progversion.bz2 (0)[email protected]ected......receiving...100%......Done
Got file ./progversion ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/modsec.conf.bz2 (0)[email protected]%......Done
Got file ./modsec.conf ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/modsecurity.apache.bz2 (0)[email protected]%......Done
Got file ./modsecurity.apache ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/uninstall.bz2 (0)[email protected]%......Done
Got file ./uninstall ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanel...urity-Linux-i686/modsec.user.conf.default.bz2 (0)[email protected]%......Done
Got file ./modsec.user.conf.default ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/modsecparse.pl.bz2 (0)[email protected]%......Done
Got file ./modsecparse.pl ok (md5 matches)
Fetching http://httpupdate.cpanel.net/cpanelsync/addons/modules/modsecurity-Linux-i686/version.bz2 (0)[email protected]%......Done
Got file ./version ok (md5 matches)
Installing Mod_Security version 1.9.1
Downloading modsecurity-apache-1.9.1.tar.gz...
Done
Editing httpd.conf
Done
Copying over default Mod_Security ruleset
Done
Backing up modsec database
Done
Setting up Front End
Done
/etc/rc.d/init.d/httpd start: httpd could not be started
The default audit log is located at /user/local/apache/logs/audit_log
All pages that are prevented from loading by mod_security will have a 406 error
Done
Updating pro....
Done
Process Complete
Check it, recheck it again.Syntax error on line 286 of /usr/local/apache/conf/httpd.conf:
Cannot add module via name 'mod_security.c': not in list of loaded modules
/etc/rc.d/init.d/httpd start: httpd could not be started
putted after the lineLoadModule security_module libexec/mod_security.so
lol, dunno how. The scripts write it that way, not me!!!AddModule mod_security.c
before the lineLoadModule security_module libexec/mod_security.so
Restart the httpdAddModule mod_security.c
GOT IT, but the GAME not OVER yet/etc/rc.d/init.d/httpd restart: httpd restarted
And the hacker give up :D
Hi WiroWaas,Got it,
I use it
And the hacker give up :D
one more ptotection, mod_evasive. I want to install it but when I read http://forums.cpanel.net/showthread.php?t=46855 , you said that IMX still causes problems with PHP because of the way FP interacts with apache, mod_evasive percieves the activity as a DOS attack.
Any sollution?
Thread starter | Similar threads | Forum | Replies | Date |
---|---|---|---|---|
![]() |
Block cPanel and WHM access | Security | 3 | |
A | Script to block IPs based on error log? | Security | 2 | |
V | Question about UDP Block of port 67 | Security | 5 | |
![]() |
ModSecurity OWASP blocking GTMetrix | Security | 1 | |
A | SOLVED csf not blocking IPs | Security | 2 |