Skip to main content

mod_ruid2 error

Comments

5 comments

  • Eduart Milushi
    Aswell im having these error for mod_security [Tue Jul 22 06:56:52.274390 2014] [:error] [pid 11157] [client ***.***.***.*] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^apache.*perl" against "REQUEST_HEADERS:User-Agent" required. [file "/usr/local/apache/conf/modsec2.user.conf"> [line "59"> [id "1234123429"> [msg "Request Indicates an automated program explored the site"> [severity "NOTICE"> [hostname "domain.com"> [uri "/gag/e21Ptfg"> [unique_id "U85DdLhrkvIAACuVRQ8AAAAC"> [Tue Jul 22 06:21:40.884009 2014] [:error] [pid 1511] [client ***.***.***.*] ModSecurity: Audit log: Failed to create subdirectories: /usr/local/apache/logs/modsec_audit/shomtek/20140722/20140722-0621 (Read-only file system) [hostname "domain.com"> [uri "/gag/JUNoSmr"> [unique_id "U847NLhrkvIAAAXnDYkAAAAa">
    [COLOR="silver">- - - Updated - - - Please if someone have any suggestions i will really appreciate it cuz i'm having a lot of problems when having more than 1000 user online :( the server take about 30 sec or more to load but the ram and other physic parameters are good
    0
  • cPanelMichael
    Hello :) Could you let us know the permission/ownership values on the directory that's referenced in the error message from your initial post? Also, your second post indicates a Read-only file system. Can you create new files on each partition? EX: touch /usr/testfile123
    Thank you.
    0
  • Eduart Milushi
    [quote="cPanelMichael, post: 1692282">Hello :) Could you let us know the permission/ownership values on the directory that's referenced in the error message from your initial post? Also, your second post indicates a Read-only file system. Can you create new files on each partition? EX: touch /usr/testfile123
    Thank you.
    Hi there, Thnx for the replay. The permission for the folder are as below Device: 902h/2306d Inode: 50334845 Links: 14 Access: (0711/drwx--x--x) Uid: ( 0/ rootuser) Gid: ( 514/ cpaneluser) I dint understand your second answer :( I typed on ssh ' touch /usr/testfile123 ' and then try to cd on that directory and i got this ' /usr/testfile123: Not a directory ' [COLOR="silver">- - - Updated - - - As well im having this error and when the website has more than 1000 vsits at one time it need more than 30 sec to load :( [Tue Jul 22 10:42:21.022249 2014] [:error] [pid 5207] [client 213.207.57.239] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:(?:type\\\\b\\\\W*?\\\\b(?:text\\\\b\\\\W*?\\\\b(?:j(?:ava)?|ecma|vb)|application\\\\b\\\\W*?\\\\bx-(?:java|vb))script|c(?:opyparentfolder|reatetextrange)|get(?:special|parent)folder|iframe\\\\b.{0,100}?\\\\bsrc)\\\\b|on(?:(?:mo(?:use(?:o(?:ver|ut)|down|move|up)|ve)| ..." at REQUEST_HEADERS:Cookie. [file "/usr/local/apache/conf/modsec2.user.conf"> [line "120"> [id "1234123449"> [msg "Cross-site Scripting (XSS) Attack"> [data "
    0
  • Eduart Milushi
    The folder is /virtfs/ and the permissions are as follow: Access: (0711/drwx--x--x) Uid: ( 0/ rootuser) Gid: ( 514/ cpaneluser) and for the second answer i didn't understand it very well, but i have typed on ssh touch /usr/testfile123
    and nothing happened then i try to cd to that and i got this /usr/testfile123: Not a directory
    [COLOR="silver">- - - Updated - - - i'm receiving this error as well: [Tue Jul 22 10:42:21.022249 2014] [:error] [pid 5207] [client ***.***.**.***] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:(?:type\\\\b\\\\W*?\\\\b(?:text\\\\b\\\\W*?\\\\b(?:j(?:ava)?|ecma|vb)|application\\\\b\\\\W*?\\\\bx-(?:java|vb))script|c(?:opyparentfolder|reatetextrange)|get(?:special|parent)folder|iframe\\\\b.{0,100}?\\\\bsrc)\\\\b|on(?:(?:mo(?:use(?:o(?:ver|ut)|down|move|up)|ve)| ..." at REQUEST_HEADERS:Cookie. [file "/usr/local/apache/conf/modsec2.user.conf"> [line "120"> [id "1234123449"> [msg "Cross-site Scripting (XSS) Attack"> [data "
    0
  • cPanelMichael
    Hello :) Please feel free to open a support ticket if you want us to take a closer look. You can post the ticket number here so we can update this thread with the outcome. Thank you.
    0

Please sign in to leave a comment.