31
CentOS-WebPanel Bugs / Re: OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by overseer on September 12, 2026, 10:34:53 PM »He's making a subtle suggestion to switch to the latest OWASP CRS:
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-to-4-27-0-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-14-running-cwp-and-apache-on-almalinux-8-9/
Then you don't have to keep looking over your shoulder (but do keep updating the rulesets from time to time).
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-to-4-27-0-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-14-running-cwp-and-apache-on-almalinux-8-9/
Then you don't have to keep looking over your shoulder (but do keep updating the rulesets from time to time).
32
CentOS-WebPanel Bugs / Re: OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by adrianofnatal on September 12, 2026, 08:32:26 PM »Hi Starburst
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
33
Information / Re: The impact of AI tools and our commitment to CWP
« Last post by geodim on September 12, 2026, 07:32:44 PM »Nice to see that you still "hold the line" on the security front
34
CentOS-WebPanel Bugs / Re: OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by Starburst on September 12, 2026, 12:37:02 PM »Now if someone would write a KB article on how to upgrade your ModSecurity & OWASP CRS ruleset... 

35
CentOS-WebPanel Bugs / OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by adrianofnatal on September 12, 2026, 02:31:49 AM »Hi all!
Just a contribution here, after a day breaking my head!
The OWASP rules was notworking, showing only warnings in logs, nothing was blocked.
Before check file orders, configurations, I notice 2 things:
1. The slide that enables modsecurity for each domain was on (green) but no created modsecurity.conf file with SecRuleEngine On. Just Off and On the slide and file was created.
2. The directory /usr/local/apache/conf.d/modsecurity-owasp-latest/rules have 2 files .conf.example. One of those is the MORE IMPORTANT file, REQUEST-901-INITIALIZATION.conf.example. Just copy this file to REQUEST-901-INITIALIZATION.conf
Reload your apache and it's working.
Just a contribution here, after a day breaking my head!
The OWASP rules was notworking, showing only warnings in logs, nothing was blocked.
Before check file orders, configurations, I notice 2 things:
1. The slide that enables modsecurity for each domain was on (green) but no created modsecurity.conf file with SecRuleEngine On. Just Off and On the slide and file was created.
2. The directory /usr/local/apache/conf.d/modsecurity-owasp-latest/rules have 2 files .conf.example. One of those is the MORE IMPORTANT file, REQUEST-901-INITIALIZATION.conf.example. Just copy this file to REQUEST-901-INITIALIZATION.conf
Reload your apache and it's working.
36
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by adrianofnatal on September 12, 2026, 01:22:51 AM »Here does not run scheduled backups.
Just run once manually when you created, after this, never run, manual or scheduled.
Just run once manually when you created, after this, never run, manual or scheduled.
37
CSF Firewall / Re: CSF analyzer
« Last post by Emilius on September 11, 2026, 10:07:37 PM »The bigger question for me is why functionality like this isn't built into CSF itself.
On a busy server, csf.deny can grow very quickly with individual IPs, including multiple addresses from the same /24 or /64. Automatically consolidating those entries into temporary subnet blocks and cleaning up old entries seems like a natural firewall maintenance feature.
I originally wrote this script because I wanted to keep the deny list small and manageable without making blocks permanent. It would be nice to see something similar implemented directly in CSF one day.
On a busy server, csf.deny can grow very quickly with individual IPs, including multiple addresses from the same /24 or /64. Automatically consolidating those entries into temporary subnet blocks and cleaning up old entries seems like a natural firewall maintenance feature.
I originally wrote this script because I wanted to keep the deny list small and manageable without making blocks permanent. It would be nice to see something similar implemented directly in CSF one day.
38
CSF Firewall / Re: CSF analyzer
« Last post by Emilius on September 11, 2026, 10:04:08 PM »Yeah, that was just a typo when I originally named it. I noticed it later but never bothered fixing it since the script was already posted and in use. 😄
39
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by Martins-phpbb on September 11, 2026, 07:09:46 PM »No you have to submit the password every day for it to run.
40
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by overseer on September 11, 2026, 07:03:45 PM »Any change with the recent update?
Recent Posts