Skip to content

cPanel confirmed - Modsecurity incompatibility with Mod_ruid2 #1334

@meutrei

Description

@meutrei

cPanel confirm the incompatibility between Modsecurity2 and mod_ruid2 on Easyapache 4 with default cPanel package.
They wait Modsecurity team to solve this bug!

The cPanel team confirm that the problem is on Modsecurity side:
cPanel Facebook: https://goo.gl/EAHjFX
cPanel forum: https://goo.gl/0vm2f7

As long as mod_ruid2 is the only easy solution available for Centos 7.x against symlink attacks can Modsecurity to solve this incompatibilities with mod_ruid2?

Errors are related to permissions(so must be an easy fix for Modsecurity)

[Wed Feb 15 05:00:21.491873 2017] [:error] [pid 20211] [client 66.xxx.xxx.xxx] ModSecurity: Geo Lookup: Failed to lock proc mutex: Permission denied [hostname "www.example.com"] [uri "/hazo/yglx.php"] [unique_id "WKPSVS9n@Qre-tOcMOWD-AAAAAM"]
[Wed Feb 15 05:00:21.661856 2017] [:error] [pid 20211] [client 66.xxx.xxx.xxx] ModSecurity: collection_store: Failed to access DBM file "/var/cpanel/secdatadir/ip": Permission denied [hostname "www.example.com"] [uri "/index.php"] [unique_id "WKPSVS9n@Qre-tOcMOWD-AAAAAM"]

cPanel V.62 with Easyapache 4 & default package

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions