Jump to content


- - - - -

ModSecurity


  • You cannot reply to this topic
3 replies to this topic

#1 Valona

    Junior Member

  • Members
  • PipPip
  • 10 posts

Posted 14 November 2010 - 04:50 PM

Hello Cartika Team

Has been about 3 weeks that I am having difficulties viewing the website and most of its own functions are not working anymore. Below is some of the ERROR Logs.

[Sun Nov 14 17:47:42 2010] [error] [client 76.74.193.134] ModSecurity: Access denied with code 403 (phase 2). Pattern match "[\\w\\-_.]*(?:casino|roulette).*\\.[a-z]{2,}" at REQUEST_HEADERS:Referer. [file "/hsphere/shared/apache2/conf/modsecurity.d/30_asl_antispam_referrer.conf"] [line "163"] [id "300084"] [rev "3"] [msg "Atomicorp.com - FREE UNSUPPORTED DELAYED FEED - WAF Rules: Referrer Spam: Gambling"] [severity "CRITICAL"] [hostname "mydomain.com"] [uri "/mydomain/templates/cleancss/img/xml.gif"] [unique_id "TOB1HkMWhwUAABhkYjMAAABP"]

[Sun Nov 14 17:38:50 2010] [crit] [client XXX.XXX.XXX.XXX] (13)Permission denied: /hsphere/local/home/mydomain/mydomain.com/mydomain/templates/cleancss/css/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable, referer: http://www.mydomain.com/mydomain/

Image JPEG example
[Sun Nov 14 17:38:51 2010] [error] [client XXX.XXX.XXX.XXX] ModSecurity: Failed to access DBM file "/var/asl/data/msa/global": No such file or directory [hostname "mydomain.com"] [uri "/mydomain.com/templates/cleancss/img/JPG-Image.jpg"] [unique_id "TOBzC0MWhwUAAAsFS40AAAA@"]

Any help is very much appreciated.

Valona

#2 CH-Justin

    Member

  • Validating
  • PipPip
  • 27 posts

Posted 14 November 2010 - 04:56 PM

Hi Valona,

This is because we utilize mod_security2 with various premium rulesets. This is to help ensure protection of the server and clients data.

Only we can remove mod_security2 rules -- please submit a ticket with the copy/pastes above (it appears you've taken the domain out of the logs here) to support@cartikahosting.com and we will get these removed for you promptly.

#3 Valona

    Junior Member

  • Members
  • PipPip
  • 10 posts

Posted 14 November 2010 - 05:33 PM

Hello CH-Justin

I sent an email with domains affected by modsecurity.
If you need more information, let me know.

Thanks

Valona

#4 CH-Justin

    Member

  • Validating
  • PipPip
  • 27 posts

Posted 14 November 2010 - 05:39 PM

Hi Valona,

I received these domains to my personal e-mail however I will need steps to reproduce the mod_security2 error (I received only domains to my e-mail account). Please supply this information to support@cartikahosting.com (our helpdesk) and we will get this looked at promptly.

Thank you for your continued business.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

© 2012 Cartika Hosting. All rights reserved