Page 1 of 1

Typo3 Fileadmin mod_evasive false positive

Posted: Mon Oct 21, 2013 6:55 am
by BruceLee
Hi guys,

like always Typo3 sucks :)
Fileadmin listing leads to a blacklisting due to mod_evasive since a lot of files are in the directory. the rule triggered is: https://www.atomicorp.com/wiki/index.php/HIDS_60205
How to get this running in a secure manner? Setting higher limit only "works" depending on dir size/ amount of files. Other dir needs another higher limit bacause of more files. In the end I would have to set so high that mod_evasive would be annuled.

How can I keep it secure but not have the customers blacklisting. Right now Typo3 is unusable due to that.
Thanks a lot.

Re: Typo3 Fileadmin mod_evasive false positive

Posted: Mon Oct 21, 2013 10:25 am
by scott
If you look at the Solutions section on https://www.atomicorp.com/wiki/index.php/HIDS_60205 the 3 options are covered there in detail.

Re: Typo3 Fileadmin mod_evasive false positive

Posted: Mon Oct 21, 2013 11:29 am
by BruceLee
thanks a lot. Only tweaking of mod_evasive left. Option 2 is not working due to DHCP Carrier IP. Option 3 is a no-go for me :)