Skip to main content

Disabling several mod_security rules due to 403 response to POST request?

Comments

6 comments

  • cPanelMichael
    Hello @orvn, Can you browse to WHM >> ModSecurity" Vendors and verify if there's a specific third-party rule-set that's enabled on this system? For instance, are you using the OWASP rule-set? Thank you.
    0
  • orvn
    Hello @orvn, Can you browse to WHM >> ModSecurity" Vendors and verify if there's a specific third-party rule-set that's enabled on this system? For instance, are you using the OWASP rule-set? Thank you.

    Yes, so it says I have the OWASP ModSecurity Core Rule Set V3.0 (SpiderLabs OWASP curated ModSecurity) rule set with 17/22 enabled rules.
    0
  • rpvw
    You might like to have a look at the free
    0
  • cPanelMichael
    Yes, so it says I have the OWASP ModSecurity Core Rule Set V3.0 (SpiderLabs OWASP curated ModSecurity) rule set with 17/22 enabled rules.

    Hello @orvn, The OWASP rule set (like any custom ruleset) comes with a risk of false positives. We document a description of the specific rule groups along with instructions of what to do when you encounter a false positive at: OWASP ModSecurity CRS - cPanel Knowledge Base - cPanel Documentation If you want an easy way to only disable specific rules on individual accounts, the plugin noted in the previous post is indeed a useful tool to do this. Thank you.
    0
  • orvn
    Thanks! That type 1 error doc is really useful. Man, looking through some of these OWASP rules I feel very grateful of the time and thought you guys and all the folks at OWASP put into this production-quality stuff. Thanks for your hard work.
    0
  • cPanelMichael
    Hello @orvn, The OWASP ruleset should also improve once we integrate version 3.1 with cPanel & WHM. Take a look at the following feature request and submit a vote to show your support: Update ModSecurity Vendor OWASP to OWASP ModSecurity Core Rule Set (CRS) 3.1 Thanks!
    0

Please sign in to leave a comment.