• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Issue Lots of ongoing issues with the default Comode ModSecurity ruleset

Bitpalast

Plesk addicted!
Plesk Guru
It's not a bug, but it's a bit annoying.:On Obsidian no day passes on which we don't get a call or support ticket from a customer who is blocked by fail2ban because his website offended some Comodo basic ModSecurity rule. We have seen it on Wordpress websites frequently when customers simply use the Wordpress editor, we've also seen it in shop systems. We have also seen it in Nextcoud installations.

It is always these two rules:
210710
214930
and sometimes a third, that may vary.

So basically one can say: If these are not added to the exception list of the "Web Application Firewall" icon, most customers will sooner or later run into problems with accessing their sites, because they will be blocked by fail2ban responding to ModSecurity 403 blocks in the webserver log files. It might be a good idea for Plesk staff to check into these rules and consider disabling them by default. It's not feasible to have rules in place who frequently act against their own website operators.

The same issues are not occuring with the Atomic basic rule set on Onyx systems.
 
This seems to be a bigger issue than what we originally thought. We are now also seeing it on other software, for example Shopware. It's always rules 210710 and 214930.
 
Last edited:
We are facing the exact same issues with the two rules 210710 and 214930 on a new Plesk server. Many legitimate requests are being blocked. We just updated a couple of days ago from an older Plesk version where ModSecurity was not enabled.
 
Now reported in
because its just too much support cases and trouble for customers.
 
Back
Top