The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

SOLVED Mod Security rule changes in cPanel 64

Discussion in 'General Discussion' started by jndawson, Mar 29, 2017.

  1. jndawson

    jndawson Well-Known Member

    Joined:
    Aug 27, 2014
    Messages:
    145
    Likes Received:
    13
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    We just got the 64.0.1 update last night.

    We're also having issues with installed SSL certs that aren't working. For example, our WHMCS system won't allow log ins and the cert won't display.
     
  2. jndawson

    jndawson Well-Known Member

    Joined:
    Aug 27, 2014
    Messages:
    145
    Likes Received:
    13
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    Update - We think it may be related to the mod_sec update:

    Code:
    [Wed Mar 29 04:02:27.596068 2017] [:error] [pid 14535] [client 12.34.56.78] ModSecurity: Exec: Execution failed while reading output: /etc/cxs/cxscgi.sh (End of file found) [hostname "whmcs.tld"] [uri "/submitticket.php"] [unique_id "WNuUQ9BuloIAADjH@3MAAAAG"]
    [Wed Mar 29 04:02:27.596953 2017] [:error] [pid 14535] [client 12.34.56.78] ModSecurity: Rule processing failed. [hostname "whmcs.tld"] [uri "/submitticket.php"] [unique_id "WNuUQ9BuloIAADjH@3MAAAAG"]
    [Wed Mar 29 04:02:28.042947 2017] [:error] [pid 14535] [client 12.34.56.78] ModSecurity: Audit log: Failed to create subdirectories: /usr/local/apache/logs/modsec_audit/risp/20170329/20170329-0402 (Read-only file system) [hostname "whmcs.tld"] [uri "/submitticket.php"] [unique_id "WNuUQ9BuloIAADjH@3MAAAAG"]
    [Wed Mar 29 04:02:28.043133 2017] [:error] [pid 14535] [client 12.34.56.78] ModSecurity: Input filter: SecUploadDir is undefined, unable to store multipart files. [hostname "whmcs.tld"] [uri "/submitticket.php"] [unique_id "WNuUQ9BuloIAADjH@3MAAAAG"]
    [Wed Mar 29 07:38:48.728399 2017] [:error] [pid 19393] [client 12.34.56.78] ModSecurity: Exec: Execution failed while reading output: /etc/cxs/cxscgi.sh (End of file found) [hostname "whmcs.tld"] [uri "/admin/supporttickets.php"] [unique_id "WNvG@NBuloIAAEvBd1EAAAAC"]
    [Wed Mar 29 07:38:48.728439 2017] [:error] [pid 19393] [client 12.34.56.78] ModSecurity: Rule processing failed. [hostname "whmcs.tld"] [uri "/admin/supporttickets.php"] [unique_id "WNvG@NBuloIAAEvBd1EAAAAC"]
    [Wed Mar 29 07:38:48.887514 2017] [:error] [pid 19393] [client 12.34.56.78] ModSecurity: Audit log: Failed to create subdirectories: /usr/local/apache/logs/modsec_audit/risp/20170329/20170329-0738 (Read-only file system) [hostname "whmcs.tld"] [uri "/admin/supporttickets.php"] [unique_id "WNvG@NBuloIAAEvBd1EAAAAC"]
    [Wed Mar 29 07:38:48.887666 2017] [:error] [pid 19393] [client 12.34.56.78] ModSecurity: Input filter: SecUploadDir is undefined, unable to store multipart files. [hostname "whmcs.tld"] [uri "/admin/supporttickets.php"] [unique_id "WNvG@NBuloIAAEvBd1EAAAAC"]
    
     
  3. jndawson

    jndawson Well-Known Member

    Joined:
    Aug 27, 2014
    Messages:
    145
    Likes Received:
    13
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    We opened support ticket
    8340785
     
  4. jndawson

    jndawson Well-Known Member

    Joined:
    Aug 27, 2014
    Messages:
    145
    Likes Received:
    13
    Trophy Points:
    18
    cPanel Access Level:
    Root Administrator
    Update:

    The v.64 update changes the path for php temp sessions from /tmp to /var/cpanel/php/sessions. We had
    'Jail Apache Virtual Hosts using mod_ruid2 and cPanel® jailshell' set to 'On'. Turning to off corrected the session errors and a bunch of other things.

    Thank you, cPanel people.
     
  5. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    37,037
    Likes Received:
    1,281
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
Loading...

Share This Page