How to view and/or tune ModSecurity Rule hits?

So,  you have discovered something is not quite working right on your site? 

We run ModSecurity rules on all accounts to protect from hackers/crackers around the world being able to exploit your site by known means.  The rulesets are updated regularly so if you notice something used to work and now does not ModSecurity is an option to check out. 

So how do we do this?

When logged into your account on DirectAdmin find the ModSecurity widget in the Advanced Settings section. 

ModSecutrity Logo

Once you enter the ModSecurity settings page you will see

ModSec Settings

Showing you the status of ModSecurity "SecRuleEngine" and listing any disabled rules. ps. We do not recommend disabling ModSecurity entirely by setting it to off.

To see recent ModSecurity rule hits click the Log tab.

ModSecurity Log

In this case ModSecurity rightly denied an external visitor access to the .env file .

If interested in finding out what that file is about follow the link above to a commonly used framework. But would contain goodies such as database credentials, host and application configuration.  Eeek!

To see all the information recorded for the entry hover the mouse over the Rule ID.

Rule Popup

Ok, you have seen the rules being hit.  You have discovered one which is actually blocking normal behaviour for your application. 

To correct that simply click on the "+" icon then "Skip Rule". 

This will then disable the rule for your domain. 

 

 

  • ModSecurity, Security
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How to select PHP Version for my domain?

Our servers run CloudLinux and have the PHP Version Selector available in DirectAdmin .To change...

How To create an email account

This article aims to show you how to go about creating an email account using the DirectAdmin...

How to issue a LetsEncrypt SSL Certificate for a domain

So,  your account has been setup your website looks good and you are wondering how do I get the...

How do I whitelist an email address from spam filtering?

If you have arrived at this article you are likely not receiving an email from a particular...