Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Modsecurity Tools hitlist is empty / not working

Discussion in 'Security' started by menathor, Apr 30, 2018.

  1. menathor

    menathor Registered

    Joined:
    Apr 5, 2016
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Australia
    cPanel Access Level:
    Website Owner
    Hi guys

    For some reason my WHM -> "Modsecurity Tools" hitlist is not working / always empty. I know modsecurity is working because hits are recorded correctly in /usr/local/apache/logs/modsec_audit.log. I don't run any WAF apps- all my rules are installed via WHM -> "Modsecurity Vendors". I've tried rules from multiple vendors and same result- they work, are logged in modsec_audit.log but the hitlist doesn't work.

    Any ideas on how I could fix this?

    Cheers!
     
  2. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    2,721
    Likes Received:
    186
    Trophy Points:
    143
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Hello @menathor

    This could caused by a few things. If you're able to access the server via CLI can you please run the following and provide me with the output?

    Code:
    grep skipmodseclog /var/cpanel/cpanel.config
    
    Code:
    grep -i modsec_audit /usr/local/cpanel/logs/tailwatchd_log |tail -n5
    
    Where is the Audit log being output to (i.e. where are you finding it)

    Is there data in /usr/local/apache/conf/modsec2.user.conf
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. dstana

    dstana Well-Known Member

    Joined:
    Jul 6, 2016
    Messages:
    51
    Likes Received:
    7
    Trophy Points:
    8
    Location:
    Phoenix, AZ
    cPanel Access Level:
    Root Administrator
    I'm having this same problem and I can provide outputs from those:

    Code:
    grep skipmodseclog /var/cpanel/cpanel.config
    
    skipmodseclog=0
    
    
    grep -i modsec_audit /usr/local/cpanel/logs/tailwatchd_log |tail -n5
    
    [9772] [2018-05-29 11:48:53 -0700] [Cpanel::TailWatch] [INFO] /etc/apache2/logs/modsec_audit.log opened with inode 1561
    [9772] [2018-05-29 11:48:53 -0700] [Cpanel::TailWatch] [INFO] Restored /etc/apache2/logs/modsec_audit.log (size:0) to 0 (requested 0)
    [9772] [2018-05-29 11:48:53 -0700] [Cpanel::TailWatch] [INFO] Caught up /etc/apache2/logs/modsec_audit.log to 0
    [9772] [2018-05-29 11:48:53 -0700] [Cpanel::TailWatch] [INFO] Restoring /etc/apache2/logs/modsec_audit.log to catch up position 0
    [9772] [2018-05-29 11:48:53 -0700] [Cpanel::TailWatch] [INFO] Restored /etc/apache2/logs/modsec_audit.log to position 0
    
    And for me, /usr/local/apache/conf/modsec2.user.conf doesn't exist.
     
  4. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    2,721
    Likes Received:
    186
    Trophy Points:
    143
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Hi @dstana


    This shows that your modsec_audit.log has nothing in it which is why you wouldn't see any hits. Do you have any rulesets besides the OWASP ruleset that comes default? Have you made customizations to the configuration? Based on what you provided the modsec_audit log is enabled and empty since this populates the hits list it may be that you haven't had any matches.


    Thanks!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. dstana

    dstana Well-Known Member

    Joined:
    Jul 6, 2016
    Messages:
    51
    Likes Received:
    7
    Trophy Points:
    8
    Location:
    Phoenix, AZ
    cPanel Access Level:
    Root Administrator
    One of the rules we had in place got modified, fixing that resolved the issue.
     
    cPanelLauren likes this.
  6. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    2,721
    Likes Received:
    186
    Trophy Points:
    143
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    Hi @dstana

    I'm happy to hear that you were able to identify and resolve the issue! Thanks for letting us know as well.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice