- Plesk for Linux
- Plesk for Windows
ModSecurity is installed and enabled in Tools & Settings > Web Application Firewall (ModSecurity) > Web application firewall mode > On.
A website hosted in Plesk fails to load or site is slow. It is not possible to perform operations on the website such as manage WordPress, access webmail, access
robots.txtfile and the following error might be displayed in the browser:
CONFIG_TEXT: 403 Forbidden
CONFIG_TEXT: 500 Internal Server Error
CONFIG_TEXT: Service Unavailable. The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later.
CONFIG_TEXT: HTTP Error 403.0 - ModSecurity Action
Site Preview may not work with one of the errors above.
A ModSecurity error message like below appears on the Logs page in Plesk at Domains > example.com > Logs or in Event Viewer > Application log:
CONFIG_TEXT: ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/modsecurity.d/rules/owasp_modsecurity_crs_3-plesk/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "57"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "example.com"] [uri "/robots.txt"] [unique_id "XPsROH8AAQEAABEiZFcAAABC"]
CONFIG_TEXT: ModSecurity: Warning. Match of "eq 0" against "&TX:PY_SCAN_FINISH" required. [file "/etc/apache2/modsecurity.d/rules/custom/000_i360_0.conf"] [line "182"] [id "77350128"] [msg "IM360 WAF: Scan time results||Py start:3542||Py finish:3555||Py time:13||Py duration:||Lua start:||Lua finish:||Lua time:||Lua duration:||T:APACHE||"] [severity "NOTICE"] [tag "service_i360"] [tag "noshow"] [hostname "example.com"] [uri "/"] [unique_id "Yz0dUZoB5aMQj0uRrk52CQAAAA0"]
- Some content may be missing (like images or some scripts not working properly) or domain's functionality may not work properly.
- Unable to delete plugin inside Wordpress dashboard:
CONFIG_TEXT: <!DOCTYPE html> 403 Forbidden html
Server Error 403 Forbidden You do not have permission to access this document
- If the website is using Cloudflare, the following error might be shown:
PLESK_INFO: Error 521
Web server is down
ModSecurity Web Application Firewall is enabled with a very restrictive (strict) ruleset such as OWASP, Comodo, or a custom ruleset like Imunify360. Hence, some operations on the websites are blocked.
If you are sure that it is false-positive detection, contact ruleset developers:
Reporting to Atomicorp https://wiki.atomicorp.com/wiki/index.php/Reporting_False_Positives
Alternatively, consider one of the following options:
Switch to the Atomic ModSecurity ruleset: Log in to Plesk GUI > Tools & Settings > Web Application Firewall (ModSecurity) > Settings > Atomic Standard > Click OK to apply the changes.
It's worth noting the free Atomic list wont get this fix/update until next month, right?
I'm having trouble using Plesk 12.5 UI to Switch off the Rule by ID. Is the correct ID format "[id "340465"]"?
After updating to the $200/yr paid Atomic list this issue is resolved. I think otherwise i would've had to wait 30 days for the free delayed updates to be deployed to me.
@Tony issue should be fixed by running abovementioned command
I am still getting the problem, it all started after i installed modsecurity in extensions, now my website resources are getting consumend and getting above error as well as xmlrpc thing. What would be appropriate solution for this as I am thinking would there be any conflict between wordpress security plugin and plesk modsecurity
Please sign in to leave a comment.