LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > Litespeed and Modsecurity

Reply
 
Thread Tools Display Modes
  #1  
Old 01-21-2013, 12:47 PM
sahostking sahostking is offline
New Member
 
Join Date: Jan 2013
Location: Cape Town, South Africa
Posts: 7
Default Litespeed and Modsecurity

Hi fellas,

Ive recently installed litespeed and enabled modsecurity. I'm currently testing with the delayed atomic rules which is free but I seem to get the error when using them:

mod_security: Access denied with code 406, [Rule: '' ''] [severity "WARNING"] [MatchedString ""]

All websites go down.

If I remove it then all works again. If I change from litespeed to apache and try it again with the rules all works fine.

Very strange. any ideas?
__________________
Website-Web Hosting-Reseller Hosting
Reply With Quote
  #2  
Old 01-28-2013, 12:25 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,339
Quote:
Originally Posted by sahostking View Post
Hi fellas,

Ive recently installed litespeed and enabled modsecurity. I'm currently testing with the delayed atomic rules which is free but I seem to get the error when using them:

mod_security: Access denied with code 406, [Rule: '' ''] [severity "WARNING"] [MatchedString ""]

All websites go down.

If I remove it then all works again. If I change from litespeed to apache and try it again with the rules all works fine.

Very strange. any ideas?
Likely the rules are not supported in LSWS. pm the rules or your server temp root access for us to look further if you like.
Reply With Quote
  #3  
Old 03-01-2013, 02:35 AM
sahostking sahostking is offline
New Member
 
Join Date: Jan 2013
Location: Cape Town, South Africa
Posts: 7
I like to figure these things out myself as I am the admin of these servers that get this issue.

I would just like to know what rules do you recommend we use ? I would like even basic mod security rules if any.

I current tried these which give me those issues:

http://updates.atomicorp.com/channels/rules/delayed/

Delayed free rules I've tested with.

Any other rules I should use instead?
__________________
Website-Web Hosting-Reseller Hosting
Reply With Quote
  #4  
Old 03-01-2013, 11:05 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,339
you can narrow down the rule in question and we can give you suggestion more specifically.
Reply With Quote
  #5  
Old 03-13-2013, 05:48 PM
lancelot lancelot is offline
New Member
 
Join Date: Mar 2013
Posts: 4
Default Which version ruleset

What is the suggested version to use for the gotroot rule sets at "https://updates.atomicorp.com/channels/rules/delayed/"? Should we use the "modsec-2.5" or the "modsec-2.7" ruleset? I am not sure which one is more compatible or have been tested with.
Reply With Quote
  #6  
Old 03-13-2013, 09:46 PM
NiteWave NiteWave is online now
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,226
I'd recommend to use latest rulesets.

mod_security is our upstream and keeps updating frequently. so we're lag with them almost all the time. But 1st, I don't think mod_security is all of security; 2nd, one fact I know of, when I log in our customers' server, I see quite a lot of them installed mod_security and litespeed at the same time as WHM(cPanel) plug-in, they are using latest gotroot rulesets I believe. litespeed improve mod_security compatibility mainly base on customer's feedback. As an example in latest 4.2.2, "Improved mod_security compatibility with gotroot ruleset."

ruleset may update everyday, but engine may not. software mainly care about the engine. as a result of long time communication between our customers and us, following wiki page is out to address the compatibility issue:
http://www.litespeedtech.com/support..._compatibility

in general, latest ruleset is safe to use. for those mod_security directives which litespeed not support, the rules are just ignored and next rules are picked up to be processed. if it breaks litespeed, please report us and you please fall back to a previous ruleset.

So far, I've not heard of a user case, because of latest mod_security ruleset not support yet, the server has been compromised or hacked or any big loss.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 10:33 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.