Skip to main content

Advice on enabling the cPanel/OWASP-CRS Mod Security Rule Set

Comments

8 comments

  • cPRex Jurassic Moderator
    Hey there! I believe the "This rule set is no longer updated" entry is an error in the documentation, so I'll get that updated soon. That is the default rule set we encourage people to use, and it definitely gets updates. You can't install the rules themselves using EasyApache, only the mod_security2 Apache module.
    0
  • sneader
    Thanks @cPRex! To be clear, the docs say you can install them using EasyApache, so that is another correction that needs to be made, I think? So, the right thing to do is to install the rules using WHM > ModSecurity" Vendors, then in the same panel, click "ON" under Enabled, correct? We already have installed the mod_security2 Apache module via WHM EasyApache 4 interface, and have "Process the rules" enabled under ModSecurity" Configuration (since we have a working ModSec config already -- we are just adding new rules). If I'm missing anything, let me know! :) - Scott
    0
  • cPRex Jurassic Moderator
    That all sounds correct to me :D
    0
  • sneader
    @cPRex, there is another page of documentation that ALSO says that installing the rules via WHM means you will never get any updates (they are OLD rules). It says you must install rules via RPM to get updates. Here is that page: in the table. [COLOR=rgb(184, 49, 47)]This rule set is not currently updated.
  • To install the newer version, you must install the ea-modsec2-rules-owasp-crs RPM in the Additional Packages section of WHM"s
  • 0
  • sneader
    @cPRex, I have another question... when OWASP is enabled via WHM > ModSecurity" Vendors, the rules that get loaded all say "OWASP ModSecurity Core Rule Set ver.3.0.2" at the top. However, if we go to the OWASP CRS website, it says "Current version: 3.3.0 " July 1, 2020". Can you tell me why we are getting these old rules? The OWASP CRS website also says they have "Application-specific exclusions for WordPress Core and Drupal" but I see nothing like that in our current rules. And, boy, we sure need it. These rules are blocking legitimate WordPress stuff left and right. We've disabled the OWASP CRS rules until we can get clarification from cPanel about the proper way to enable these rules AND get current rules and updates. - Scott
    0
  • cPRex Jurassic Moderator
    The team is investigating these options per the documentation request I opened earlier. I don't have any updates just yet, but I'll be sure to post them when I do!
    0
  • CrazySerb
    I am curious to see how and where is that possible to set up, the "Application-specific exclusions for WordPress Core and Drupal" ...
    0
  • cPRex Jurassic Moderator
    I obviously never heard anything back from the team two years ago when this was originally posted as I never replied. I'm also not familiar with any certain set of rules, but there was some good discussion in this thread recently about ModSec and WordPress:
    0

Please sign in to leave a comment.