Yet another ModSecurity thread...
So as per our other recent post, we've recently switched from our own customized version of the AtomiCorp rules to the OWASP rules provided by cPanel.
On all of our servers, /usr/local/apache/logs/error_log is filled with these:
This particular server is a brand new server with a fresh copy of cPanel, and actually never had the AtomiCorp rules in place to begin with - we just installed the OWASP as a "ModSecurity Vendor". If I click the ModSecurity Tools link I do see a ton of hits being processed correctly... so I'm not sure what's going on here.
I have a ticket open with cPanel - they cleared our custom whitelist but the errors persist, so they've escalated the ticket.
This is happening on all our servers - so I can't imaging we're the only ones having this issue...
So as per our other recent post, we've recently switched from our own customized version of the AtomiCorp rules to the OWASP rules provided by cPanel.
On all of our servers, /usr/local/apache/logs/error_log is filled with these:
Code:
[Mon Feb 09 18:51:54 2015] [error] [client xxxx] ModSecurity: Rule processing failed. [hostname "xxxx"] [uri "xxxx"] [unique_id "VNlIGsBjLFwAACtCD9YAAAAb"]
[Mon Feb 09 18:51:55 2015] [error] [client xxxx] ModSecurity: Geo Lookup: Failed to lock proc mutex: Identifier removed [hostname "xxxx"] [uri "/"] [unique_id "VNlIG8BjLFwAACp6PnUAAAAW"]
[Mon Feb 09 18:51:55 2015] [error] [client xxxx] ModSecurity: Geo Lookup: Failed to lock proc mutex: Identifier removed [hostname "xxxx"] [uri "/"] [unique_id "VNlIG8BjLFwAACp6PnUAAAAW"]
[Mon Feb 09 18:51:56 2015] [error] [client xxxx] ModSecurity: Rule processing failed. [hostname "xxxx"] [uri "xxxx"] [unique_id "VNlIHMBjLFwAACtGEKAAAAAJ"]
[Mon Feb 09 18:52:00 2015] [error] [client xxxx] ModSecurity: Rule processing failed. [hostname "xxxx"] [uri "xxxx"] [unique_id "VNlIIMBjLFwAACtKEY4AAAAL"]
[Mon Feb 09 18:52:01 2015] [error] [client xxxx] ModSecurity: Rule processing failed. [hostname "xxxx"] [uri "xxxx"] [unique_id "VNlIIcBjLFwAACviGXEAAAAG"]
[Mon Feb 09 18:52:01 2015] [error] [client xxxx] ModSecurity: Rule processing failed. [hostname "xxxx"] [uri "xxxx"] [unique_id "VNlIIcBjLFwAACviGXIAAAAG"]
I have a ticket open with cPanel - they cleared our custom whitelist but the errors persist, so they've escalated the ticket.
This is happening on all our servers - so I can't imaging we're the only ones having this issue...