• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question WAF ModSecurity Rules?

safemoon

Regular Pleskian
Server operating system version
Ubuntu 24.04.4 LTS
Plesk version and microupdate number
Plesk Obsidian Web Host Edition Version 18.0.80 Update #6
Hi All,

I have servers running with Comodo Ruleset WAF (Free), but i do get some false positives.
On my servers im running many different custom php applications and static websites.

What could i do to still be protected but not getting false positives and random blocks?

Some actions that are triggering (in my custom php apps):
- login as user
- login as another admin
- font files or icon libraries i.e simple line icons
- woff and ttf files

Are there any better rulesets or any other wafs? I never tried atomic or owasp, owasp only once but even the webmail is not working with it on.

I need a plug and play solution without too much time detecting what causes false positives tuning etc, if possible!
 
I cannot really recommend a specific ruleset. Frankly, the possibility of getting false positive with any of them is very real. OWASP is usually more restrictive, so it's probably not the best option.
 
Back
Top