Mod Security Causing ADMIN-AJAX.PHP 403 Errors — CyberPanel - WebHosting Control Panel for OpenLiteSpeed
CyberHosting

Mod Security Causing ADMIN-AJAX.PHP 403 Errors

Hi, I started getting 403 errors from admin-ajax.php, and I traced it down to Mod Security. When I disable mod security, the error goes away.

I installed the OWASP rules pack.

Are the any specific rules I need to use to prevent this?

Thanks!
Tagged:
Tagged:

Comments

  • I just noticed that Cyberpanel doesn't include the OWASP WordPress rules that were added in v3.0 as found here:

    https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.0/master/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf

    Is there a reason these rules weren't added? Can I add them manually, or willl you add them in an update?

    Thanks!
  • Thank you. If I want to add the WordPress rules I linked to above, where should I put the file?
  • Thanks I'll try it
  • @harvey any progress with modsecurity and 403
  • @opencode Nothing yet, still looking into it. I'll update here if I make any progress
  • I uncommented Rule REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf in /usr/local/lsws/conf/modsec/owasp/crs-setup.conf (Around line 300) and I had to reset my server, and it seems to be working.

    @hennaboy Why isn't this rule visible on the MODSECURITY RULES PACKAGES page?
  • Also, I noticed that the modsec log at /usr/local/lsws/logs/modsec.log is 8.5GB! Does this log not get cleared? Do I have to delete it manually? @hennaboy
  • @harvey any update?
  • @inside83 I tried playing around with it for a while, even enabling the WordPress rules pack, but I was never able to get it to work correctly. Also, I wasn't really able to understand the logs to see which rules were triggered so I can disable them. For now I turned off ModSec.
Sign In or Register to comment.
CyberPanel Discord

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!