LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Feedback/Feature Requests > [Resolved] Turn off ModSecurity directives in htaccess

Reply
 
Thread Tools Display Modes
  #1  
Old 02-07-2010, 02:50 AM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Default [Resolved] Turn off ModSecurity directives in htaccess

Hi there,

It seems that ModSecurity it could be disabled in htaccess using this directive:
Code:
SecFilterEngine Off
Well, It means an attacker can easily bypass modsec rules using htaccess file
Tested myself and it's possible to disable and bypass modsec rules by htaccess, and to me, its a very big security hole

I found here that its possible to disable htaccess support for ModSecurity during compile:

Quote:
If you do not trust your users (e.g. running in a web hosting environment) then you should never allow them access to ModSecurity. The .htaccess facility is useful for limited administration control decentralisation, keeping ModSecurity configuration with the application code. But it is not meant to be used in situations when the users may want to subvert the configuration. If you are running a hostile environment you should turn off the .htaccess facility completely by custom-compiling ModSecurity with the -DDISABLE_HTACCESS_CONFIG switch.
Now im asking for a feature to disable/enable ModSec rules support inside htaccess files to be implemented in LSWS admin console

Regards.

Last edited by NiteWave; 10-02-2010 at 10:20 PM..
Reply With Quote
  #2  
Old 02-07-2010, 08:51 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
add to our to do list.
Reply With Quote
  #3  
Old 09-08-2010, 07:20 PM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Quote:
Originally Posted by mistwang View Post
add to our to do list.
Any update ?
Reply With Quote
  #4  
Old 10-02-2010, 10:34 AM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,216
now in 4.0.17, mod_security directive in .htaccess can be disabled, configuration is at server level, in admin console. please download and test ... not formally release yet but may be soon.
Reply With Quote
  #5  
Old 10-02-2010, 11:58 AM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Quote:
Originally Posted by NiteWave View Post
now in 4.0.17, mod_security directive in .htaccess can be disabled, configuration is at server level, in admin console. please download and test ... not formally release yet but may be soon.
Special thanks
tested and its working properly

Regards
Reply With Quote
  #6  
Old 11-25-2010, 12:37 PM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Hi there

I'm using apache/cPanel httpd.conf
How to disable mod_security directives support in .htaccess ?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 06:16 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.