cPanel ModSecurity False Positives & Missing Data...
Hi,
My server runs the following ModSecurity Rules:
- Imunify360 LiteSpeed Rule Set (Minimized ModSec Ruleset)
- COMODO ModSecurity LiteSpeed Rule Set
- OWASP ModSecurity Core Rule Set V3.0
- I'd like to be able to re-enable the above ruleset if I could get those false positives fixed with the providers.
- 17350
- 210380
- 210492
- 25178
- 28292
- 60050
- 62100
- 941100
- 941160
-
Hello Ryan, Ruleset publishers will have contact instructions for issues with false positives. For Imunify360 rules, contact Imunify360 support There should not be a situation in which the hits are not listed in the UI. Please use the link in my signature to open a ticket with our staff, so we can investigate that condition further. 0 -
Hi, Did you check your link regarding Comodo? It's for their standalone WAF, not the integrated rulesets within WHM/cPanel. I can't find a report location online without posting to their forums and I would rather not post the contents publically Thanks 0 -
@RyanR - could you make a ticket with our team so we can check that? 0 -
@RyanR - could you make a ticket with our team so we can check that?
Hi Rex, I did submit a ticket and I'm still trying to recreate it because I can't get it to happen again -_-0 -
Just like when you take a car to the mechanic............... If you could post the ticket number here I can follow along and make sure this thread stays updated. 0 -
Just like when you take a car to the mechanic............... If you could post the ticket number here I can follow along and make sure this thread stays updated.
1. Ticket ID: 94321305 2. Did You/David have a link/resource for submitting to Comodo? I still haven't found one. 3. As for the ModSecurity log issue, it was happening to nearly every single 403 false positive and I was having to search the logs with grep until I found ModSecurity ModSecurity had it's own log reader... I wonder if one of the updates since has fixed it for me.0 -
Thanks for providing that ticket number - I'm following along there in case that has any more updates in the future. I'm not seeing a specific point of contact for a ModSec issue on their end when I looked just now. However, they do have a thread here that they are actively monitoring that has been open for several years: 0
Please sign in to leave a comment.
Comments
7 comments