Author Topic: OWASP Latest  (Read 97 times)

0 Members and 1 Guest are viewing this topic.

Offline
*
OWASP Latest
« on: October 15, 2025, 02:59:00 PM »
We switched from Comodo to OWASP Latest as I read Comodo WAF no longer received updates.  Now when Aacron runs we are seeing this error:

PHP Warning:  file_get_contents(/usr/local/apache/modsecurity-owasp-latest/rules/rules.dat): failed to open stream: No such file or directory in /usr/local/cwpsrv/htdocs/resources/admin/include/cron.php on line 0
--2025-10-15 03:46:04--  http://static.cdn-cwp.com/files/apache/mod-security/modsecurity-owasp-latest.zip


I am not seeing rules.dat in /usr/local/apache/modsecurity-owasp-latest/rules. Will the cron.daily resolve this at next run or do I need to so something further.

Thank you all for your help!

Online
*****
Re: OWASP Latest
« Reply #1 on: October 15, 2025, 05:23:27 PM »
Please update Mod Security to the latest version and OWASP to the latest ruleset using Starburst's guides. I have followed them and don't have the referenced /usr/local/apache/modsecurity-owasp-latest/rules/rules.dat file on any of my servers.

https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-12-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-running-cwp-and-apache-on-almalinux-9/

Offline
*
Re: OWASP Latest
« Reply #2 on: October 15, 2025, 07:06:42 PM »
We are running Almalinux 8. Doesn't CWP have a way to make sure it is the latest version with updated rulesets as stated?
OWASP latest (Latest version with automatic updates)

Offline
*****
Re: OWASP Latest
« Reply #3 on: October 15, 2025, 07:12:45 PM »
Comodo WAF has been dead for over a year now.

OWASP doesn't automatically update, even though it says it does.
The ModSecurity version installed by default by CWP is 2.9.6 and is incompatible with the new OWASP CRS rulesets.

Offline
*
Re: OWASP Latest
« Reply #4 on: October 15, 2025, 07:25:35 PM »
Ok, thank you. What exactly do I need to do? I'm sorry, I'm a little lost on this one.

Offline
*****
Re: OWASP Latest
« Reply #5 on: October 15, 2025, 08:24:40 PM »
@overseer post the 2 links you need to follow.
It's mostly cut & paste in the CLI.

Offline
*
Re: OWASP Latest
« Reply #6 on: October 15, 2025, 08:51:04 PM »
Ok. Same for Almalinux 8? I just saw the Alma9 in the link.

Offline
*****
Re: OWASP Latest
« Reply #7 on: October 15, 2025, 09:59:39 PM »
Ok. Same for Almalinux 8? I just saw the Alma9 in the link.
Yes, it is the same for AL8.