Control Web Panel
WebPanel => CentOS-WebPanel Bugs => Topic started by: adrianofnatal on September 12, 2026, 02:31:49 AM
-
Hi all!
Just a contribution here, after a day breaking my head!
The OWASP rules was notworking, showing only warnings in logs, nothing was blocked.
Before check file orders, configurations, I notice 2 things:
1. The slide that enables modsecurity for each domain was on (green) but no created modsecurity.conf file with SecRuleEngine On. Just Off and On the slide and file was created.
2. The directory /usr/local/apache/conf.d/modsecurity-owasp-latest/rules have 2 files .conf.example. One of those is the MORE IMPORTANT file, REQUEST-901-INITIALIZATION.conf.example. Just copy this file to REQUEST-901-INITIALIZATION.conf
Reload your apache and it's working.
-
Now if someone would write a KB article on how to upgrade your ModSecurity & OWASP CRS ruleset... :-X
-
Hi Starburst
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
-
He's making a subtle suggestion to switch to the latest OWASP CRS:
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-to-4-27-0-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-14-running-cwp-and-apache-on-almalinux-8-9/
Then you don't have to keep looking over your shoulder (but do keep updating the rulesets from time to time).
-
Hi Starburst
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
Actually, No, it doesn't updated automatically. Even thought that's what it says in the panel.