11
Mod_Security / Re: Updated Comodo WAF Rules (2025/2026) for CWP & WordPress - Community Feedback
« Last post by sminozzi on February 12, 2026, 01:09:09 PM »Thanks for the feedback and for your honesty. Since my sites are WordPress-based, I developed two plugins (anti-hacker and anti-bot) that work in synergy with ModSecurity, CSF, and Fail2ban.
I’m actually very pleased with the results of this setup, so I’ll stick with the Comodo rules for a while longer. I only offered them because I see many people still using the version from two years ago, and I believe moving to an updated ruleset is a step forward.
I wanted to help because I see so many people online trying to destroy things and very few helping to build them. Modestly, I’m just trying to balance the scales a bit. It’s a small contribution, but it was what I could do.
I’m actually very pleased with the results of this setup, so I’ll stick with the Comodo rules for a while longer. I only offered them because I see many people still using the version from two years ago, and I believe moving to an updated ruleset is a step forward.
I wanted to help because I see so many people online trying to destroy things and very few helping to build them. Modestly, I’m just trying to balance the scales a bit. It’s a small contribution, but it was what I could do.
12
Other / Re: CWP Forums constantly down
« Last post by Starburst on February 12, 2026, 11:03:27 AM »Yes, I have already reported the problem to José, it is due to an old and no longer updated version of SMF. I suggested to José that he switch to PHPBB, which is much more robust and much better in this regard.
phpBB is good, but SMF 2.1.6 seemed better IMO, but I got out voted for another project. :/
sysadmin.help is finally live.
Feel free to post here & there.
13
PHP Selector / Re: Support for PHP 8.4
« Last post by Starburst on February 12, 2026, 11:00:29 AM »The guide at:
https://www.alphagnu.com/topic/615-install-latest-version-of-php-84-php-switcher-in-cwp-control-web-panel-el89-almalinux-89/
Is for both AlmaLinux 8 and 9.
If you are running either of those you should not have to 'tweat' any paths.
Some modules where retired when PHP 8.4 was released, like IMAP in 8.4, that now need to be loaded via PECL.
https://www.alphagnu.com/topic/615-install-latest-version-of-php-84-php-switcher-in-cwp-control-web-panel-el89-almalinux-89/
Is for both AlmaLinux 8 and 9.
If you are running either of those you should not have to 'tweat' any paths.
Some modules where retired when PHP 8.4 was released, like IMAP in 8.4, that now need to be loaded via PECL.
14
PHP Selector / Re: Support for PHP 8.4
« Last post by Wonder on February 12, 2026, 10:37:30 AM »https://www.alphagnu.com/topic/614-how-to-add-custom-php-fpm-84-85-support-to-cwp-on-almalinux-9x/
https://www.alphagnu.com/topic/615-install-latest-version-of-php-84-php-switcher-in-cwp-control-web-panel-el89-almalinux-89/
https://www.alphagnu.com/topic/616-install-latest-version-of-php-85-php-switcher-in-cwp-control-web-panel-el89-almalinux-89/
As always, thanks for your messages.
I'm here because I need to install PHP 8.4 on CWP 8 / AlmaLinux 8. The links provided are for CWP9/Alma9 (I'm interested in php-fmp). I've spent all day tweaking the paths so that it's 8 instead of 9, but I still can't install modules or I'm getting other errors. Is there any way to install PHP 8.4 correctly on CWP 8?
Thanks
PS: Sorry about the previous post; I quoted the wrong one, didn't see it, and now I can't edit it.
15
PHP Selector / Re: Support for PHP 8.4
« Last post by Wonder on February 11, 2026, 11:53:01 PM »José Manuel had indicated to me that PHP 8.4 and PHP 8.5 were coming in the next major update.
As always, thanks for your messages.
I've come here because I need to install PHP 8.4 on CWP 8 / AlmaLinux 8. These links are for CWP9/Alma9 (I'm interested in php-fmp), and I've spent all day tweaking the paths so that it's 8 instead of 9, but I still can't install modules or I'm getting other errors. Is there any way to install PHP 8.4 correctly on CWP 8?
Thanks
16
Mod_Security / Re: Updated Comodo WAF Rules (2025/2026) for CWP & WordPress - Community Feedback
« Last post by Starburst on February 11, 2026, 08:40:41 PM »The OWASP CRS Ruleset is the best to use, and is free, and using their other half ModSecurity, it is easy to disable any rules needed.
17
Mod_Security / Re: Updated Comodo WAF Rules (2025/2026) for CWP & WordPress - Community Feedback
« Last post by overseer on February 11, 2026, 02:46:57 PM »Hi Bill, thanks for your efforts -- any contribution is valuable. I for one will have to pass though -- I can't have my servers' security depend on one person's lone efforts no matter how noble the intent. I've been making the latest OWASP rulesets work (omitting a list of false positives) and it is generally stable. Wish Comodo wouldn't have lost their identity and their product direction, but had to cope and life goes on!
18
Mod_Security / Updated Comodo WAF Rules (2025/2026) for CWP & WordPress - Community Feedback
« Last post by sminozzi on February 11, 2026, 02:10:34 PM »Hi everyone,
Since the official Comodo free ruleset hasn't been updated in over two years, I decided to take action. I have manually created an updated ruleset (2025/2026) to handle modern threats, specifically focusing on the new wave of AI scrapers and aggressive bots that cause unnecessary CPU/RAM drain.
I’ve been testing these rules on several high-traffic WordPress environments, and so far, the results are great: zero false positives in the admin area and significantly lower server load.
You can check out the updated rules and the documentation on my GitHub here:
https://github.com/sminozzi/SBB-WAF-Rules
Please feel free to test them out—I’m very open to feedback and suggestions if you see anything that could be improved!
Please note that there is no automatic installer for these updates. You will need the technical skills to manually replace the necessary files in your ModSecurity directories. Since environments can vary, I cannot provide individual support for the installation process. I highly recommend performing a full backup of your current rules before making any changes.
If you have any feedback or suggestions on how to improve these rules, please let me know. I'm always looking for ways to refine the protection and would love to hear about your experience with them.
Best regards,
Bill
Since the official Comodo free ruleset hasn't been updated in over two years, I decided to take action. I have manually created an updated ruleset (2025/2026) to handle modern threats, specifically focusing on the new wave of AI scrapers and aggressive bots that cause unnecessary CPU/RAM drain.
I’ve been testing these rules on several high-traffic WordPress environments, and so far, the results are great: zero false positives in the admin area and significantly lower server load.
You can check out the updated rules and the documentation on my GitHub here:
https://github.com/sminozzi/SBB-WAF-Rules
Please feel free to test them out—I’m very open to feedback and suggestions if you see anything that could be improved!
Please note that there is no automatic installer for these updates. You will need the technical skills to manually replace the necessary files in your ModSecurity directories. Since environments can vary, I cannot provide individual support for the installation process. I highly recommend performing a full backup of your current rules before making any changes.
If you have any feedback or suggestions on how to improve these rules, please let me know. I'm always looking for ways to refine the protection and would love to hear about your experience with them.
Best regards,
Bill
19
Updates / Re: Roundcube vulnerability
« Last post by Starburst on February 11, 2026, 02:01:52 PM »20
Updates / Re: Roundcube vulnerability
« Last post by overseer on February 11, 2026, 11:58:43 AM »Just to affirm Starburst's previous guide to update Roundcube in light of the current vulnerability:
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/update-roundcube-webmail-to-version-1-5-11-in-cwp-on-almalinux-8-9/
or follow Sandeep's guide here:
https://www.alphagnu.com/topic/33-update-cwp-roundcube-mail-version-158-%E2%80%93-control-web-panel/
Simply update the Roundcube version number to 1.5.13 in the directions and download links and you will obtain a CWP-compatible LTS version of Roundcube, safe from the latest CVE.
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/update-roundcube-webmail-to-version-1-5-11-in-cwp-on-almalinux-8-9/
or follow Sandeep's guide here:
https://www.alphagnu.com/topic/33-update-cwp-roundcube-mail-version-158-%E2%80%93-control-web-panel/
Simply update the Roundcube version number to 1.5.13 in the directions and download links and you will obtain a CWP-compatible LTS version of Roundcube, safe from the latest CVE.
Recent Posts