lsws 4.1.11 not support modsec rules?

Discussion in 'Bug Reports' started by DraCoola, Mar 16, 2012.

  DraCoola

    DraCoola

    I just wondering about why there so many modsec rules suddenly lost it functions while using litespeed.
    I had test it with a very simple rule for an example :

    SecRule REQUEST_URI "^/abc\.php$" "deny"
    As above rule expected, Apache bring 406 error page to access.
    But unfortunatelly, litespeed will still give us totaly freedom to access

    Is there any special way to write that just "REQUEST_URI denial" modsec rule with litespeed?
    Last edited: Mar 16, 2012
  mistwang

    mistwang

    does abc.php file exists? and the file need to be processed as a script.
    LiteSpeed ignore mod_sec for static files.
  DraCoola

    DraCoola

    yes abc.php is exist.
    the file is php file which have active script inside it.
  DraCoola

    DraCoola

    Force update 4.1.11 will fixed this modsec compatibily.
    Thank you, George!

