Control Web Panel

Security => Mod_Security => Topic started by: gilliard on May 27, 2016, 10:19:45 PM

Title: Access Error
Post by: gilliard on May 27, 2016, 10:19:45 PM
Hello I can not access the page after I installed mod_security, put a folder in the account and will not appear ... :'( :'( :'( :'( :'(

http://imgur.com/v0PeP9q
Title: Re: Access Error
Post by: Sandeep on May 28, 2016, 05:25:51 AM
check the apache error log and find your ip, their will be a ID which you have to whitelist.
Title: Re: Access Error
Post by: gilliard on May 28, 2016, 07:52:53 PM
I did not understand, what to do?
where I find the logs?
Title: Re: Access Error
Post by: Sandeep on May 29, 2016, 06:25:08 AM
I did not understand, what to do?
where I find the logs?
/usr/local/apache/logs
Title: Re: Access Error
Post by: gilliard on May 29, 2016, 04:10:51 PM
okay, what should I look for?
Title: Re: Access Error
Post by: gilliard on May 29, 2016, 04:13:11 PM
Found it:

linhasmart.tk"] [uri "/"] [unique_id "V0necn8AAAEAABpbW@cAAAAG"]
"linhasmart.tk"] [uri "/"] [unique_id "V0n2AH8AAAEAABoPTEgAAAAF"]
Title: Re: Access Error
Post by: Sandeep on May 29, 2016, 07:10:20 PM
Not this one id will be like this id:200000
Title: Re: Access Error
Post by: gilliard on May 29, 2016, 07:52:05 PM
This
[id "970013"]
Title: Re: Access Error
Post by: gilliard on May 29, 2016, 07:53:57 PM
[Sun May 29 15:49:36 2016] [error] [client 186.209.253.230] ModSecurity: Access denied with code 403 (phase 4). Pattern match "(?:<(?:TITLE>Index of.*?<H|title>Index of.*?<h)1>Index of|>\\\\[To Parent Directory\\\\]<\\\\/[Aa]><br>)" at RESPONSE_BODY. [file "/usr/local/apache/modsecurity-crs/base_rules/modsecurity_crs_50_outbound.conf"] [line "136"] [id "970013"] [rev "2"] [msg "Directory Listing"] [data "Matched Data: <title>Index of /</title>\\x0a </head>\\x0a <body>\\x0a<h1>Index of found within RESPONSE_BODY: <!DOCTYPE HTML PUBLIC \\x22-//W3C//DTD HTML 3.2 Final//EN\\x22>\\x0a<html>\\x0a <head>\\x0a  <title>Index of /</title>\\x0a </head>\\x0a <body>\\x0a<h1>Index of /</h1>\\x0a<ul></ul>\\x0a</body></html>\\x0a"] [severity "ERROR"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/LEAKAGE/INFO_DIRECTORY_LISTING"] [tag "WASCTC/WASC-13"] [tag "OWASP_TOP_10/A6"] [tag "PCI/6.5.6"] [hostname "linhasmart.tk"] [uri "/"] [unique_id "V0tH0H8AAAEAABpbXDEAAAAG"]
Title: Re: Access Error
Post by: pixelpadre on May 29, 2016, 09:29:13 PM
check the apache error log and find your ip, their will be a ID which you have to whitelist.

White listing his IP address works also.
Title: Re: Access Error
Post by: gilliard on May 29, 2016, 09:31:33 PM
I'm not understanding what you have to do
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 12:01:20 AM
Add it in  Disabled Rules --> /usr/local/apache/conf/mod_sec_disabled_rules.conf  (you can just click the link in the mod security section)
Add the rule id in the file SecRuleRemoveById  [the rule id you found] and click save changes.
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 12:28:19 AM
Like this?

http://imgur.com/6cHuji9
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 01:52:01 AM
Yes
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 01:58:41 AM
It works, but the folder does not appear ... something is missing?

http://imgur.com/bWD1hzW
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 02:24:30 AM
We don't give support for websites. If you have question regarding cwp you can ask.
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 02:28:17 AM
yes, it is not a website is only a folder
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 09:09:59 AM
yes, it is not a website is only a folder

where did you put the  folder please specify the path

you need to upload all files to /home/username/public_html/
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 12:46:46 PM
Yes, just have a folder

http://imgur.com/ZNseciA
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 01:04:27 PM
Yes, just have a folder

http://imgur.com/ZNseciA
Pm me the server's root password and IP
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 01:12:41 PM
I sent a private message
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 01:33:45 PM
Problem resolved
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 01:47:40 PM
Amazing! Thank you, what was the problem?
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 01:50:36 PM
Amazing! Thank you, what was the problem?

.htaccess was placed in wrong location

and permission issues
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 02:04:12 PM
Okay, great job, thank you.

Another doubt, I can use external mail server as zimbra?
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 02:06:20 PM
Okay, great job, thank you.

Another doubt, I can use external mail server as zimbra?
I never tried it but their is a guide :
https://wiki.zimbra.com/wiki/CentOS_6.3_and_Zimbra_8_Install_Guide
Title: Re: Access Error
Post by: gilliard on May 30, 2016, 02:12:45 PM
Yes, I already installed zimbra so do not know how to configure cwp panel to direct emails to him.
Title: Re: Access Error
Post by: Sandeep on May 30, 2016, 04:02:04 PM
Yes, I already installed zimbra so do not know how to configure cwp panel to direct emails to him.
is this custom request?
you need to contact cwp support team for custom requests.