BUG: ModSecurity kills posting in this forum?!

Community support forums for the free/delayed modsecurity rules feed. There is no such thing as a bad question here as long as it pertains to using the delayed modsecurity rules feed. Newbies feel free to get help getting started or asking questions that may be obvious.
Azurel
Forum User
Forum User
Posts: 7
Joined: Fri Apr 24, 2020 5:17 am
Location: Germany

BUG: ModSecurity kills posting in this forum?!

Unread post by Azurel »

Hi, I tried multiple times to submit a new topic about ModSecurity with a example-line from a error_log and this forum/server ban me for few hours. Thats very strange!

I have upload the line as txt-file https://file.io/rzn7ssaO
I use CentOS 7.7 with Plesk Obsidian 18.0.26 and have in error_log this entries:

See linked file

Without the query string, however, this is not very helpful to be able to look up what the attack was or even to be able to change some of your parameters because false positive.
Is there a setting to add query string behind [uri ...]?
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: BUG: ModSecurity kills posting in this forum?!

Unread post by mikeshinn »

It looks like youre using the unsupported free rules, is that correct?
Azurel
Forum User
Forum User
Posts: 7
Joined: Fri Apr 24, 2020 5:17 am
Location: Germany

Re: BUG: ModSecurity kills posting in this forum?!

Unread post by Azurel »

Yes I test modsecurity currently with comodo and atomicorp free rules set. Have the atomicorp subscription version more information in logfiles? Can you show me a example, please? ;)
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: BUG: ModSecurity kills posting in this forum?!

Unread post by mikeshinn »

Certainly, the supported rules provide a lot more information and support is provided for any issues the same day the issue is reported, updates for false positives for example are provided the same day they are reported, our goal is provide any update within an hour.
Post Reply