LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > Mod_security isnt working : Joomla sites are getting hacked ?

Reply
 
Thread Tools Display Modes
  #1  
Old 04-20-2008, 08:16 AM
vivek vivek is offline
Senior Member
 
Join Date: Jan 2008
Posts: 275
Default Mod_security isnt working : Joomla sites are getting hacked ?

Hello

I have a good set of Mod_security 1.9 rules. But when I swap the webserver, ie, when I run Apache , I will get lot of IP block mails from the firewall. From that, I can see the IP address as well as the domain name. But when I switch to litespeed, it is not working with mod security rules. and not reporting the errors in error_log file such that the CSF can read it.

Recently one of my client's site which was a Joomla site, got hacked. I checked the account and found 10 copies of c99.php files as well as a file called sniper.php files. ClamAV antivirus found this as trojans.

Why c99 and snipper codes worked with litespeed+modsec ? I am sure it will not work in the case of apache+modsec

My question is , Why litespeed isnt processing modsec.conf ?
I know the the old version of lsws worked with modsec, but why the new version isnt working with it?

I am using enterprise version since 3+ months now.

My server is handling around 300 http connections ( 500+ on peak time )
I am sure litespeed isnt working with modesec+CSF because when I change to apache, I can see it apache is working fine with those set of rules.

Vivek
Reply With Quote
  #2  
Old 04-20-2008, 06:15 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
We need more specific information to investigate this.
The Request URL and security rule that should work but not.
We can try it on your server with mod_security log enabled.
Reply With Quote
  #3  
Old 04-20-2008, 07:39 PM
vivek vivek is offline
Senior Member
 
Join Date: Jan 2008
Posts: 275
Quote:
Originally Posted by mistwang View Post
We need more specific information to investigate this.
The Request URL and security rule that should work but not.
We can try it on your server with mod_security log enabled.
PMed you the server login. Please check it.

Regards
Vivek
Reply With Quote
  #4  
Old 04-20-2008, 07:56 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Please send me an example URL along with the mod_security rule that should block it. However, it has not been blocked in your server environment, and we can reliably reproduce it on your server, then I will start investigate.

Without those information, I don't know where to start.
Reply With Quote
  #5  
Old 04-20-2008, 08:32 PM
vivek vivek is offline
Senior Member
 
Join Date: Jan 2008
Posts: 275
Quote:
Originally Posted by mistwang View Post
Please send me an example URL along with the mod_security rule that should block it. However, it has not been blocked in your server environment, and we can reliably reproduce it on your server, then I will start investigate.

Without those information, I don't know where to start.
Hello

I just uploaded a c99 script to my account. I can see litespeed is not working with modsec in this case.

I changed to apache and it blocked the script.

PMing you the details.

Vivek
Reply With Quote
  #6  
Old 04-21-2008, 08:39 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
checking it now.
Reply With Quote
  #7  
Old 04-21-2008, 10:32 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
OK, find a problem with handling "SecFilter" directive, the request URI has not been checked. Uploaded 3.3.11 release package, and it works properly now.

If you find any other issue mod_security rules, please let us know.
Reply With Quote
  #8  
Old 04-21-2008, 11:19 AM
vivek vivek is offline
Senior Member
 
Join Date: Jan 2008
Posts: 275
Quote:
Originally Posted by mistwang View Post
OK, find a problem with handling "SecFilter" directive, the request URI has not been checked. Uploaded 3.3.11 release package, and it works properly now.

If you find any other issue mod_security rules, please let us know.
Thank you
I think there are also some other rules other than secFilter, which arent working. I will let you know when I get more info.

Vivek
Reply With Quote
  #9  
Old 04-28-2008, 10:51 PM
vivek vivek is offline
Senior Member
 
Join Date: Jan 2008
Posts: 275
secFilter is not working again,

Litespeed Web Server Enterprise v4.0b1 :
Reply With Quote
  #10  
Old 04-28-2008, 11:18 PM
anewday anewday is offline
Senior Member
 
Join Date: Nov 2007
Location: New York
Posts: 723
Hope George didn't forget to apply all bugfixes (from 3.3 versions) to the beta, I'm waiting for beta2 to test it.

Last edited by anewday; 04-28-2008 at 11:21 PM..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 11:57 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.