Skip to main content

Older mod_security ruleset still active

Comments

3 comments

  • Bdzzld
    Very strange no one replied to this thread as... Found the solution myself by replacing /usr/local/apache/conf/modsec2.user.conf with an empty file and then restarting httpd.
    0
  • Infopro
    Not the best way to solve an issue with a specific rule I don't think. Each rule should have an ID, that ID can be whitelisted. Or, in that file you replaced completely, you could have simply remarked out the specific rule with, #
    0
  • Bdzzld
    @Infopro : I agree, but the rules in that file were remnants of a time when mod_security rules were added via an editor window. These days they 've all been replaced (and updated!) by the OWASP ModSecurity Core Rule Set.
    0

Please sign in to leave a comment.