Search results

  1. I

    Whitelist include

    Hello, I'd like to suggest a feature to implement whitelist includes since CDN provider services is using IP addresses which is getting updated and thats though to add them individually to each server Currently the Whitelist input is comma separated which is not so user friendly specially when...
  2. I

    lsphp ENV vars

    Hello, Recently I added a php extension that gathers information from environment vars such as REMOTE_ADDR and HTTP_USER_AGENT but from $ENV not $SERVER vars seems that lsphp doesn't handle such variables which is Apache style ENV vars thus the extension is fully compatible with Apache but...
  3. I

    Cloudlinux LVE support in lsws 5

    Hello, Seems that LVE support has been broken in the new version Tried all LVE, CageFS and CageFS without suExec options but didn't work properly Looking forward to hear from you Re,
  4. I

    4.1 lsphp CPU usage

    Hello Cause of an issue with older 4.1 reported here we're stayed with 4.0 for a long time on my high-end 64 and 80 core servers Now we decided to upgrade to 4.1 which its been announced to be fixed another weird thing is occurring! While its running with about 50% CPU idle with 4.0.20...
  5. I

    4.0 vs 4.1

    Hi, Currently I've 2 major issues with 4.1 which forced me to stay with 4.0 1st is well known bug litespeed process 100% CPU usage which is ocurring very randomly on busy servers and unfortunately all 4.1 series are affected by this issue, however aimed to be addressed in recent 3 builds but...
  6. I

    [solved] 4.1.5 php suExec issue

    Hi after upgrading to 4.1.5 just found that some scripts are executed under nobody group which leads to sessions files to be stored with nobody user at tmpdir also directories needs to be 777 word writable in order to php to have write access there while suExec/suphp is enabled PS: there...
  7. I

    htpasswd auth

    Hi there, Its long time that customers are reporting that cPanel password protection feature doesn't work properly at my cPanel/Litespeed servers I've double checked my self and couldn't make it working It returns 401 for correct password here is configurations: .htaccess: AuthType...
  8. I

    [solved] Anti-DDoS whitelist

    Hey there, That would be nice to allow specified IP addresses to don't be measured for DDoS limitations on some servers local loopback got blocked due to heavy requests to the webserver therefore some cronjobs and functions wont work properly besides, some IP addresses are shared on...
  9. I

    lsws failed to start

    Hi there, Its 2nd time that I'm facing an unexpected odd behavior for litespeed it was down for many hours and auto-restart and 503 auto fix didn't make that online just found bellow error at my email: Attempts to create new directories or files whose filenames begin with numbers have...
  10. I

    Wrong cache hit

    Hi there, I'm seeing a very unexpected and unknown act by Litespeed cache feature Here is my cache Policy config: <cache> <storage> <cacheStorePath>/dev/shm/lswscache</cacheStorePath> <maxCacheObjSize>102400</maxCacheObjSize> </storage> <cachePolicy>...
  11. I

    lsphp issue

    Hi there, Today i've upgraded one of servers to 4.1RC5 to use AIO support which fixes IO bottleneck and CPU is more utilized after that which is greatly appreciated All websites now works like a charm and it really boosts! But after few hours all php processes has been stopped working and...
  12. I

    php5 directives in httpd.conf

    Hi there, after upgrading to 4.0.17 it seems php5_admin_value is not working properly while php_admin_value works fine Here is VH php directives which doesn't set open_basedir value <IfModule concurrent_php.c> php4_admin_value open_basedir...
  13. I

    mod sec request body scan

    Dear George, However it make decrease performances, but we would like to have this option available in LSWS Indeed its up to us which enable or disable this option and it can be disabled by default Would you please let me know if its possible or maybe already in your todo list? Regards
  14. I

    [Resolved] Turn off ModSecurity directives in htaccess

    Hi there, It seems that ModSecurity it could be disabled in htaccess using this directive: SecFilterEngine Off Well, It means an attacker can easily bypass modsec rules using htaccess file Tested myself and it's possible to disable and bypass modsec rules by htaccess, and to me, its a...
  15. I

    MIME Type could not be changed in 4.0.12

    Dear George, When we upgraded to 4.0.12, custom mime type is not possible anymore All the MIME Types are default, and when i modify that it will not affect, while in the previous versions it was working properly Please take a look in it PS: We expect you to care more to avoid such problems...
  16. I

    [RESOLVED] "No Symlink" Bypass security bug

    Hi there Today i found that "Follow Symbolic Link" set to "No" or "If Owner Match" its not disabling Symlink as its expected to disable whole symlinks For example the symlink2 linked to fakesymlink/../../../../../../../../../../../../../../..//home/user/public_html/ which fakesymlink is...
  17. I

    RemoveHandler

    It seems RemoveHandler directive is not implemented in LiteSpeed, yet I want to disable CGI scripts globally to improve server security, but if i disable that using Options -ExecCGI it would be enabled using htaccess with the same Options method Is it possible to implement RemoveHandler...
  18. I

    LSWS/IE odd issue!

    Hi I didnt see any odd bug with LSWS like this before! in a vBulletin forum when i try to edit some large posts, edit form returns 503 Service Unavailable error in Internet Explorer, but no any error with another browsers! I tried same exact time/user/cookie and it seems not jumpy to me, all...
  19. I

    4.0 Gold?

    Hi there I was surfing for some mod_sec rules and features and suddenly noticed about LSWS 4.0 released yesterday, March 17 here in the Release Log but its not announced in Portal or News forum yet Just want to know is this Gold/Final release or its still in beta/RC state? BTW appreciated a...
  20. I

    GeoIP issue with Apache VHosts

    Hi, There is something wrong with IP GeoLocation and Apache loaded VHosts in Litespeed ent. GeoIP Server Variables works in Virtual Hosts which added in Litespeed manually but Apache VHosts IP GeoLocation option is enabled in global settings but still doesnt work properly Seems bug to me, or...
Top