• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

Issue Lots of ongoing issues with the default Comode ModSecurity ruleset

Bitpalast

Plesk addicted!
Plesk Guru
It's not a bug, but it's a bit annoying.:On Obsidian no day passes on which we don't get a call or support ticket from a customer who is blocked by fail2ban because his website offended some Comodo basic ModSecurity rule. We have seen it on Wordpress websites frequently when customers simply use the Wordpress editor, we've also seen it in shop systems. We have also seen it in Nextcoud installations.

It is always these two rules:
210710
214930
and sometimes a third, that may vary.

So basically one can say: If these are not added to the exception list of the "Web Application Firewall" icon, most customers will sooner or later run into problems with accessing their sites, because they will be blocked by fail2ban responding to ModSecurity 403 blocks in the webserver log files. It might be a good idea for Plesk staff to check into these rules and consider disabling them by default. It's not feasible to have rules in place who frequently act against their own website operators.

The same issues are not occuring with the Atomic basic rule set on Onyx systems.
 
This seems to be a bigger issue than what we originally thought. We are now also seeing it on other software, for example Shopware. It's always rules 210710 and 214930.
 
Last edited:
We are facing the exact same issues with the two rules 210710 and 214930 on a new Plesk server. Many legitimate requests are being blocked. We just updated a couple of days ago from an older Plesk version where ModSecurity was not enabled.
 
Now reported in
because its just too much support cases and trouble for customers.
 
Back
Top