Skip to main content

Main IP doing attacks on websites

Comments

2 comments

  • quizknows
    You may want to check the modsec audit log, (/usr/local/apache/logs/modsec_audit.log) as this may be a false positive. Anomaly based rules can be tricky.
    0
  • cPanelMichael
    The mod-sec is detecting attacks on the websites from the main ip of the server

    Hello :) Were you able to review the /usr/local/apache/logs/modsec_audit.log file for additional information? Thank you.
    0

Please sign in to leave a comment.