Skip to main content

Mod_Security Broke My Wordpress!

Comments

3 comments

  • cPanelMichael
    Hello :) The rules you referenced are not added to the default Mod_Security rules that cPanel provides. Are you sure you are not using a set of third-party rules or have not entered custom rules manually? Note that you can find the default rules listed under "Default Configuration" in "WHM Main >> Plugins >> Mod Security". Thank you.
    0
  • feldon27
    Yep, through some sleuthing, I've confirmed that these were added by my webhost. :( Thank you for your patience with my rant.
    0
  • quizknows
    I've used a lot of modsec rules to stop WP brute force, but those ones don't really make that much sense to me. It looks like they're trying to avoid logins where "wp-submit" or "action" are null. Most of the brute force traffic I've analysed has these properly set anyway. Perhaps the rules are erroneous, out-dated, or your login method wasn't specifying those variables. They should audit those rules for functionality with the latest versions of WP (Assuming you're running the latest version). For what it's worth, I tested these rules with my WP installs of the latest version and they do not cause any problems. If you're running an out-dated version, that might explain it.
    0

Please sign in to leave a comment.