mod_security
-
hi there!
we have been getting quite a few of these errors for awhile now, which are resulting in blocks of legitimate customers.
any ideas on what may be wrong and what we need to do to correct it? our sites are hosted on a vps and the admin with the hosting company believes that disabling mod_security rule 959006 might fix it. however, we thought it best to check with you instead and get your opinion.
thanks in advance.
[Thu Apr 11 10:50:24 2013] [error] [client 66.151.103.8] ModSecurity: Access denied with code 501 (phase 2). Pattern match “(?:\\\\b(?:(?:n(?:et(?:\\\\b\\\\W+?\\\\blocalgroup|\\\\.exe)|(?:map|c)\\\\.exe)|t(?:racer(?:oute|t)|elnet\\\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\\\.exe|echo\\\\b\\\\W*?\\\\by+)\\\\b|c(?:md(?:(?:32)?\\\\.exe\\\\b|\\\\b\\\\W*?\\\\/c)|d(?:\\\\b\\\\W*?[\\\\\\\\/]|\\\\W*?\\\\.\\\\.)|hmod.{0,40}? …” at REQUEST_COOKIES:eshopcart. [file “/usr/local/apache/conf/modsec2.user.conf”] [line “146”] [id “959006”] [msg “System Command Injection”] [data “|rm”] [severity “CRITICAL”] [tag “WEB_ATTACK/COMMAND_INJECTION”] [hostname “ourdomainnamehere.com”] [uri “/shopping-cart/cancelled-order”] [unique_id “UWbNsGyglDMAAGPydLQAAAAG”]
- The topic ‘mod_security’ is closed to new replies.