LinqLOL
Basic Pleskian
Testing the mod_security functionality (in combination with the Atomic corp live rules) in active mode . Below some of my findings about the current state of mod_security in Plesk:
- On the manual page they are talking about /var/log/httpd/modsec_audit.log but the correct location is /var/log/modsec_audit
- Whats the best way to test if mod_security working? The prefered testing method with index.php?foo=http://www.foo.com/ does not trigger anything
- the modsec_audit is flooded (all request details are logged?) can the default logging level be lowered? I only want this filled when a request is blocked
- cli: it's not possible to change the update frequency (default = update disabled) with the server_pref cli tool
- how/where are my atomic corp logins stored? When I check /etc/asl.config I see "plesk_global_unpaid" as USERNAME