store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Fri May 24, 2013 8:03 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 
Author Message
 Post subject: mod_security
Unread postPosted: Sun Nov 23, 2008 7:49 pm 
Offline
New Forum User
New Forum User

Joined: Thu Nov 13, 2008 1:49 pm
Posts: 3
i'm getting this error when making update while in admin of a php web site. i'm told its mod security and i should change it for the domain only
SecFilterEngine Off
SecFilterScanPOST Off

i have look for step by step instruction and can't find anything clear

cent 5.2 plesk 8.6 ASL


> Forbidden
>
> You don't have permission to access /adm-misc.php on this server


Top
 Profile  
 
 Post subject: What do you see in your modsecurity audit logs
Unread postPosted: Sun Nov 23, 2008 8:23 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Or if you are running ASL, what do you see in the alert GUI?

Its most likely a false positive, if you post the false positive here we can put out an update today for the rules.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: mod_security
Unread postPosted: Sun Nov 23, 2008 8:35 pm 
Offline
New Forum User
New Forum User

Joined: Thu Nov 13, 2008 1:49 pm
Posts: 3
i'm very new to this so if you could tell where to get this info or run the report


thank you


Top
 Profile  
 
 Post subject: False positives
Unread postPosted: Sun Nov 23, 2008 9:06 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
If your are running ASL, just go into the ASL GUI and click on the event that is blocking access to your application. Then you can press the "Report False Positive" button and it will be sent directly to support for resolution. We generally have these issues resolved the same day and during normal business hours we try to get them done within a few hours.

If you are not running ASL you need to find your audit_log file, which is normally in /var/log/httpd.

Then simply paste the modsecurity event here for us to look at.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject:
Unread postPosted: Tue Jan 06, 2009 1:17 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
I dont think you are able to turn it off on a domain, and if you can then IMO you shouldnt be able to.

I know that I dont want a single one of my customers turning it off, and then finding out later that we got hacked cause they did so.


Top
 Profile  
 
 Post subject:
Unread postPosted: Tue Jan 06, 2009 2:43 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
In plesk a customer should not be able to turn it off for a domain as the vhost.conf file should still be owned by root, but yes that would be BAD BAD BAD if a user could do that. If anyone is running a version of Plesk that does allow that let us know. :-)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject:
Unread postPosted: Tue Jan 06, 2009 2:48 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
There are some tools out there (for a fee) that offer the ability to customers to edit the vhost.conf file directly in plesk. Outside of third party tools like that I cant imagine any plesk install instances where it would be able to be modified by the customer - at least anything after 7.5

Ive also seen lots of people try to put those directives in an htaccess file to turn it off and thankfully that doesnt work either :)


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Jan 07, 2009 4:18 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Yeah I wouldnt install any tool that lets a user do that. Youre basically giving them free reign for all your domains if you do that, because a customer could basically make themselves authoritative for all the domains.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group