Modsecurity 2.9.6 [Fix Security]

vpsstore

Member
Nov 13, 2010
17
0
51
Thank you, there are quite a few - but you have to work back from 949110 which is the one that does the dirty work.


eg. for Opayo/Sagepay (amongst other codes)
920600
980130


This must be affecting quite a lot of people - assuming we aren't the only people with it switched on!
 

ciao70

Well-Known Member
Nov 3, 2006
149
33
178
949100 ( absolutely must not be deactivated, it counts the anomalous score of the various rules)

You need to disable only the individual rules that are creating the problem

920600 This rule restricts these to familiar charsets. (OK)

 
  • Like
Reactions: vpsstore

vpsstore

Member
Nov 13, 2010
17
0
51
949100 ( absolutely must not be deactivated, it counts the anomalous score of the various rules)

You need to disable only the individual rules that are creating the problem

920600 This rule restricts these to familiar charsets. (OK)

Yup, thanks, we are aware of the importance of 949110. Our hosts aren't though and they turned it off and asked us to ignore the warnings - we reinstated and have been working back to identify the actual triggers.
 

kitmancraig2

Registered
Dec 8, 2022
4
0
1
UK
cPanel Access Level
Website Owner
Same problems with paypal and opayo. Tracked the various triggers and had the following list:

920600
920420
980130

Added these as global exemptions. Did not work.

We have to add exemptions for 949110 for the 2 call back scripts which I understand to be very bad.

I would appreciate a solution that does not involve disabling 949110.
 

ciao70

Well-Known Member
Nov 3, 2006
149
33
178
Same problems with paypal and opayo. Tracked the various triggers and had the following list:

920600
920420
980130

Added these as global exemptions. Did not work.

We have to add exemptions for 949110 for the 2 call back scripts which I understand to be very bad.

I would appreciate a solution that does not involve disabling 949110
Hi,

If only those 3 rules are the problem, once disabled, they should no longer trigger 949110.

Maybe there is some other rule to disable, but not 949110 and 980130 (these exclude the detection of many other rules)


You could report the problem here

 
Last edited:

kitmancraig2

Registered
Dec 8, 2022
4
0
1
UK
cPanel Access Level
Website Owner
Hi,

If only those 3 rules are the problem, once disabled, they should no longer trigger 949110.

Maybe there is some other rule to disable, but not 949110 and 980130 (these exclude the detection of many other rules)


You could report the problem here

As I mentioned in my original post. These were the rules that were showing in the hitlist but disabling them and not 949110 did not work. I have tried again today and it does not work.
 

kitmancraig2

Registered
Dec 8, 2022
4
0
1
UK
cPanel Access Level
Website Owner
As I mentioned in my original post. These were the rules that were showing in the hitlist but disabling them and not 949110 did not work. I have tried again today and it does not work.
These are the hits that occurred when I added the 3 rules to the exclusion of the script. You can see the top one is what happened when I removed the rules and added 949110 back.

This is very serious and I cannot believe more people aren't affected.
 

Attachments

ciao70

Well-Known Member
Nov 3, 2006
149
33
178
I don't know if I understood correctly, when you disable the 920600 rule you still have the problem?

Once you deactivate a rule, it must be confirmed and published
 

ciao70

Well-Known Member
Nov 3, 2006
149
33
178
Hi,



  • mod_security2
    • EA-11091: Fix linking issues on C6/C7

 

savoures

Registered
Dec 29, 2022
1
0
1
Greece
cPanel Access Level
Root Administrator
Hello
I have the same problem with 3-4 eshops under my hosting. After the upgrade to the newest version of mod security Paypal payments dont work. I had to disable it in these cpanels in order not to cause problems to my customers.
Also Another problem is that when a customer tries to add new products with a name like "Φωτιστικό εσωτερικού χώρου 3XE15"
When he writes something like 3XE15 in the title then the system locks his IP. I also had to disable it on that cpanel too
 

ciao70

Well-Known Member
Nov 3, 2006
149
33
178
Modsecurity 2.9.7 released



Is there an update date by Cpanel?