Modsecurity 2.9.6 [Fix Security]
-
@ciao70 - I'll reply when I have something to share. 0 -
@cPRex I think I see some news posted 6 hours ago EA-10944: Update ea-modsec2-rules-owasp-crs from v3.3.2 to v3.3.4 Do you have any news on the official release via Easy apache of Modsecurity 2.9.6 and OWASP CRS 3.3.4? Thanks 0 -
That brings a new problem now: [root@host ~]# /usr/local/cpanel/scripts/modsec_vendor update --auto info [modsec_vendor] Updates are in progress for all of the installed ModSecurity vendors with automatic updates enabled. warn [modsec_vendor] The system could not add the vendor: The vendor metadata does not contain an entry for your version of ModSecurity, "2.9.6". The only versions of ModSecurity this rule set supports are "2.7.5", "2.7.7", "2.8.0", "2.9.0", "2.9.1", "2.9.2", "2.9.3", and "3.0.4". info [modsec_vendor] Restored modsec_cpanel_conf_datastore backup The system failed to update the vendor from the URL "https://files.imunify360.com/static/modsec/v2/meta_imunify360-full-litespeed.yaml": The vendor metadata does not contain an entry for your version of ModSecurity, "2.9.6". The only versions of ModSecurity this rule set supports are "2.7.5", "2.7.7", "2.8.0", "2.9.0", "2.9.1", "2.9.2", "2.9.3", and "3.0.4". warn [modsec_vendor] The system failed to update the vendor from the URL "https://files.imunify360.com/static/modsec/v2/meta_imunify360-full-litespeed.yaml": The vendor metadata does not contain an entry for your version of ModSecurity, "2.9.6". The only versions of ModSecurity this rule set supports are "2.7.5", "2.7.7", "2.8.0", "2.9.0", "2.9.1", "2.9.2", "2.9.3", and "3.0.4".
0 -
Our system was updated last night (~ 10pm GMT) and since paypal and Opayo/Sagepay transactions are failing for a mixture of reasons. Anyone else having problems? 0 -
Our system was updated last night (~ 10pm GMT) and since paypal and Opayo/Sagepay transactions are failing for a mixture of reasons. Anyone else having problems?
Hi, Do you use OWASP CRS?0 -
That brings a new problem now:
[root@host ~]# /usr/local/cpanel/scripts/modsec_vendor update --auto info [modsec_vendor] Updates are in progress for all of the installed ModSecurity vendors with automatic updates enabled. warn [modsec_vendor] The system could not add the vendor: The vendor metadata does not contain an entry for your version of ModSecurity, "2.9.6". The only versions of ModSecurity this rule set supports are "2.7.5", "2.7.7", "2.8.0", "2.9.0", "2.9.1", "2.9.2", "2.9.3", and "3.0.4". info [modsec_vendor] Restored modsec_cpanel_conf_datastore backup The system failed to update the vendor from the URL "https://files.imunify360.com/static/modsec/v2/meta_imunify360-full-litespeed.yaml": The vendor metadata does not contain an entry for your version of ModSecurity, "2.9.6". The only versions of ModSecurity this rule set supports are "2.7.5", "2.7.7", "2.8.0", "2.9.0", "2.9.1", "2.9.2", "2.9.3", and "3.0.4". warn [modsec_vendor] The system failed to update the vendor from the URL "https://files.imunify360.com/static/modsec/v2/meta_imunify360-full-litespeed.yaml": The vendor metadata does not contain an entry for your version of ModSecurity, "2.9.6". The only versions of ModSecurity this rule set supports are "2.7.5", "2.7.7", "2.8.0", "2.9.0", "2.9.1", "2.9.2", "2.9.3", and "3.0.4".
Hi, It seems your vendor does not support Modsecurity 2.9.60 -
Hi, Do you use OWASP CRS?
Yes, it is the ruleset causing the issues AFAIK, previously no problems at all.0 -
Yes, it is the ruleset causing the issues AFAIK
Check which rule is causing the problem. For example, I had to disable rule 920450: Restricted HTTP headers msg:'HTTP header is restricted by policy (%{MATCHED_VAR})0 -
Thank you, there are quite a few - but you have to work back from 949110 which is the one that does the dirty work. eg. for Opayo/Sagepay (amongst other codes) 920600 980130 This must be affecting quite a lot of people - assuming we aren't the only people with it switched on! 0 -
Same problems with paypal and opayo. Tracked the various triggers and had the following list: 920600 920420 980130 Added these as global exemptions. Did not work. We have to add exemptions for 949110 for the 2 call back scripts which I understand to be very bad. I would appreciate a solution that does not involve disabling 949110. 0 -
Same problems with paypal and opayo. Tracked the various triggers and had the following list: 920600 920420 980130 Added these as global exemptions. Did not work. We have to add exemptions for 949110 for the 2 call back scripts which I understand to be very bad. I would appreciate a solution that does not involve disabling 949110
Hi, If only those 3 rules are the problem, once disabled, they should no longer trigger 949110. Maybe there is some other rule to disable, but not 949110 and 980130 (these exclude the detection of many other rules)0 -
Hi, the modsec ruleset update yesterday also caused havoc to our payment system. The temporary solution was to disable the offending ruleset trigger ID : 920600 0 -
Hi, If only those 3 rules are the problem, once disabled, they should no longer trigger 949110. Maybe there is some other rule to disable, but not 949110 and 980130 (these exclude the detection of many other rules)
As I mentioned in my original post. These were the rules that were showing in the hitlist but disabling them and not 949110 did not work. I have tried again today and it does not work.0 -
As I mentioned in my original post. These were the rules that were showing in the hitlist but disabling them and not 949110 did not work. I have tried again today and it does not work.
These are the hits that occurred when I added the 3 rules to the exclusion of the script. You can see the top one is what happened when I removed the rules and added 949110 back. This is very serious and I cannot believe more people aren't affected.0 -
I don't know if I understood correctly, when you disable the 920600 rule you still have the problem? Once you deactivate a rule, it must be confirmed and published 0 -
Hello I have the same problem with 3-4 eshops under my hosting. After the upgrade to the newest version of mod security Paypal payments dont work. I had to disable it in these cpanels in order not to cause problems to my customers. Also Another problem is that when a customer tries to add new products with a name like "????????? ?????????? ????? 3XE15" When he writes something like 3XE15 in the title then the system locks his IP. I also had to disable it on that cpanel too 0 -
No, nothing yet. 0 -
So the Comodo ruleset for Litespeed has stopped working for good? Or is it temporary? 0 -
So the Comodo ruleset for Litespeed has stopped working for good? Or is it temporary?
The story is old, and it looks like it is over: Is this project dead?0
Please sign in to leave a comment.
Comments
57 comments