• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Issue ModSecurity: Access denied with code 403 (phase 2) FALSE POSITIVE

mdde

Regular Pleskian
Hi,
i had this some while ago, where I excluded a ModSec Rule.
But this OVIOUSLY is not working.
I must say - i am very annoyed.
As my last Post regarding Mailbox Outgoing Control is NOT working and no answer.
Now I find another Problem on another Server and gues what: NOT WORKING.

So the clear things out:
Last year a setup a Rule: 340748 which should be excluded.
This is 8 Month ago oder something like that. Meanwhile there where Updates and Restarts of Server.
So assuming that Fact: The exclude Rule never worked?

Please see Screenshot. I assume - if i insert a RULE "340748" which should be excluded - it should not be possible - that a Customer gets Banned via Fail2ban from that.
Right?
It does ban!!!!!

What am I missing?

‪Debian 8.10‬
Produkt Plesk Onyx
Version 17.5.3 Update #37
 

Attachments

  • Bildschirmfoto 2018-01-18 um 11.14.33.jpg
    Bildschirmfoto 2018-01-18 um 11.14.33.jpg
    121.7 KB · Views: 9
  • Bildschirmfoto 2018-01-18 um 11.11.41.png
    Bildschirmfoto 2018-01-18 um 11.11.41.png
    1.3 MB · Views: 11
Back
Top