I have ModSecurity installed and enabled for scanning and blocking but it does not block anything. Tried different rule sets including basic and paid Atomic and Comodo. Rule sets are downloaded fine to /etc/httpd/conf/modsecurity.d/rules/. It does write to modsec_audit.log but doesn't give 403 to anything. When try to test it with foo.php?foo= apache gives normal 404 not 403 as it should. Tried to reinstall module from plesk but it didn't help. Any suggestion?
edit: I found out what was the issue. After one of the Plesk updates security2.conf file was removed from /etc/httpd/conf.d and it was replaced by 00_mod_security.conf and because of that none of the rule sets was included in apache config. 00_mod_security.conf looks for rule sets in /etc/https/modsecurity.d/ and security2.conf looks in /etc/httpd/conf/modsecurity.d/ where they actually are. I have CrashPlan setup on the server so I was able to go back in time and look what was changed. It happened on 06/12/14 so it would be nice if some of the Plesk's developers checked what update caused that.
edit: I found out what was the issue. After one of the Plesk updates security2.conf file was removed from /etc/httpd/conf.d and it was replaced by 00_mod_security.conf and because of that none of the rule sets was included in apache config. 00_mod_security.conf looks for rule sets in /etc/https/modsecurity.d/ and security2.conf looks in /etc/httpd/conf/modsecurity.d/ where they actually are. I have CrashPlan setup on the server so I was able to go back in time and look what was changed. It happened on 06/12/14 so it would be nice if some of the Plesk's developers checked what update caused that.
Last edited: