Skip to main content

ModSecurity SQL Injection

Comments

4 comments

  • mtindor
    Those particular rules in that ruleset are often triggered falsely. I'm not one to suggest that you disable the rules globally. Just be aware that when I ran that ruleset (one week, short test) that particular ruleset available in cPanel was full of rules that generated false positives and was pretty much useless in my mind unless one disables all of the rules generating false positives. And then if one disables the rules generating false positives, one likely increases the risk of something getting through that should have been blocked. I don't know how anyone runs that particular ruleset.
    0
  • adeyjones
    Thanks for your reply. I know very little about ModSecurity, my server support guys advised me to disable it for the affected account - what would you recommend in this case?
    0
  • mtindor
    Thanks for your reply. I know very little about ModSecurity, my server support guys advised me to disable it for the affected account - what would you recommend in this case?

    I'm not recommending anything. If you are going to run that ruleset, understand that those particular rules in the ruleset are very prone to false positives (especially on Wordpress sites, but not only with Wordpress sites). So you shouldn't be surprised if you have to disable those rules for some other site(s) down the road just to keep your sanity.
    0
  • cPRex Jurassic Moderator
    Thanks for the details, @mtindor ! @adeyjones - as mentioned, sometimes even a default ruleset will cause issues for a site. It may be necessary to disable those rules through WHM in order to get things working, but that's really up to you/your server admin to evaluate.
    0

Please sign in to leave a comment.