• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

modsecurity

  1. Jürgen_T

    Question Modsecurity - Apache or Nginx

    I’m planning to make a third attempt next week to install ModSecurity under Plesk. During the setup, there’s an option to choose whether ModSecurity should be applied to Nginx or Apache. Since I’m using Nginx as a reverse proxy in front of Apache, it’s unclear which option I should select.
  2. S

    Resolved ModSecurity exception rules disappear ??

    I created exception security rule IDs and the next day they disappeared. I have : Comodo (free) (ModSecurity 2.9) updated daily
  3. K

    Issue ModSecurity with nginx not working

    I have modsecurity setup with apache and it works. I tried to setup modSecurity with nginx but nothing happens when enabled. It looks like it's not activated at all. I tried enabled/disabled, report only all modes, nothing. I test it with some simple injection queries which are blocked when...
  4. Jürgen_T

    Issue Modsecurity works with Apache but error with nginx

    I just started to give modsecurity a second try but got this after re-installed it with plesk-installer. Starting with the configuration Nginx (Modsecurity 3.0) I get the following error: Changing the configuration from Nginx (Modsecurity 3.0) to Apache (Modesecurity 2.9) it starts without...
  5. T

    Issue ModSecurity and bad gateway 500 nginx

    Hello since last update i have much trouble with my plesk installation Every night turn my plesk all the engines off apache and nginx and my websites are not resolvable i get then nginx500 bad gateway. It's seems to have problems with ModSecurity because if i go to my plesk i see a error...
  6. Jürgen_T

    Resolved ModSecurity configuration files and directives remain on the server after its removal

    After some problems with Modsecurity I removed it using Plesk installer (web interface). This seemed to work and now it is indicated as removed However in /etc/nginx/conf.d/ modsecurity.conf still exists with the following content: So it says Modsecurity is on and receives the configuration...
  7. K

    Question modsecurity

    --0c650000-F-- HTTP/1.1 500 Internal Server Error --0c650000-H-- Message: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "C:\/Program Files (x86)/Plesk/ModSecurity/rules/modsecurity_crs-plesk/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1367"] [id "920320"] [msg "Missing User...
  8. H

    Question When can we get Apache supported Modsecurity v3x?

    Hi Forum, We are using the Apache server in our production environment. To use ModSecurity V3 (libmodsecurity), we need to use the ModSecurity-apache connector. This project is under development and not production-ready. The functionality is not complete, so we cannot use use with Apache HTTP...
  9. R

    Issue Modsecurity don't start

    I have a problem when i try to active mod security in my server, i have that error: Can not restart web server: apache_control_adapter[843803]: graceful restart failed, perform full restartapache_control_adapter[843803]: apache_action(graceful): invoke_httpd_action failed, trying second...
  10. A

    Issue Additional Apache directives doesn't work

    Hi, As the title says when I try to use some directive in my vhost this one doesn't work, unlike when I write it in the main file. main file would be... /var/www/vhosts/system/domain/conf/httpd.conf vhost files would be... /var/www/vhosts/system/domain/conf/vhost_ssl.conf and vhost.conf (I...
  11. G

    Question ModSecurity - is there a way to view the installation/enabled date?

    Hi, is there a way to get the date ModSecurity was installed/enabled? I see the log files, but it looks like there is only a week's worth and I installed/enabled it before then. It wasn't installed on my Plesk installation, so I installed and activated the same date..perhaps I can determine...
  12. B

    Question Disable WAF (ModSecurity) if using Immunify360?

    Just want to check before I go ahead with this The youtube video above suggests disabling WAF (ModSecurity) if using Immunify360. I have a plesk server with 50+ websites hosted for clients. Is this something that is actually recommended to do?
  13. A

    Resolved Unable to reinstall modsecurity after upgrade from Onyx to Obsidian

    In the process of upgrading to Obsidian, I had this conflict ; Exception: Failed to solve dependencies: plesk-modsecurity-configurator conflicts with mod_security-2.9.2-centos7.19091318.x86_64 I did remove mod_security thinking I would reinstall it after upgrade. Maybe I should have used the...
  14. H

    Issue Using atomic corp rules for modsecurity but updating page via elementor doesn't work and gives internal server error.

    Hey everyone i have enabled modesecurity for my website using atomic corp rules. but when I update something on website using elementor keeping modsec on it gives me internal server error. if I turn off modsec and update it works fine. but I want to resolve this with modsec on. your help will be...
  15. JerryTek101

    Resolved Apache + Nginx As Reverse Proxy Imunify360 Question

    My current setup is Apache + ModSecurity with imunify360 ruleset. I want to run Nginx as a reverse proxy for Apache. Will I have to switch Mod security from Apache WAF to Nginx WAF with Imunify360 ruleset or do I keep Modsecurity as Apache? Is that supported?
  16. N

    Resolved ModSecurity / WCF call / 403

    Hi, I have a WCF site, that can't be called when ModSecurity is on. Found the description below in the EventViewer. Can this be solved? [client 46.39.122.103] ModSecurity: Access denied with code 403 (phase 1). Pattern match...
  17. E

    Issue Website registration check not working with ubuntu 22

    When entering this option we do not see any records, even though we have configured the tool to launch automatically daily at 06:25 every 60 minutes. When trying to launch the manual check, the following error appears: logparser failed: ERROR: Failed to construct 'audit-modsec-with-ts' step...
  18. T

    Question Allow specific Content types in Mod Security

    When I activate ModSecurity I have a problem with content types: [msg "COMODO WAF: Request content type is not allowed by policy. Please update file userdata_wl_content_type.||app.domain.de|F|2"] [data "TX:0=application/merge-patch+json"] Where I find die file userdata_wl_content_type to add...
  19. WebHostingAce

    Issue ModSecurity with Atomic Basic Rule Set appear be not working

    Hi, I'm using ModSecurity with Atomic Basic Rule Set across number of servers. Recently I have noticed the ModSecurity is not responding to any of these test explained this is support article...
  20. J

    Question modsecurity enabled via plesk web, but off via ssh command line

    Hello everyone I'm just curious, i have enabled modsecurity on all my websites and i can see it's working in the log files. Today i happened to run: plesk bin nginx -s to get a list of all the modules installed and their status and found modsecurity shows as OFF: brotli on...
Back
Top