This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Pages: [1] 2
1
Suggestions / php 8.4 & 8.5
« on: June 22, 2026, 08:20:24 PM »
hello,
kindly integrate php 8.4 and 8.5 in cwp pro as many latest php scripts and apps requires php 8.4 or php 8.5 . thanks
Regards,
Zeej
kindly integrate php 8.4 and 8.5 in cwp pro as many latest php scripts and apps requires php 8.4 or php 8.5 . thanks
Regards,
Zeej
2
CentOS 9 Problems / mysql update
« on: February 05, 2026, 10:30:15 PM »
hello,
mysql is not updating in almalinux 9.7 automatically from cwp panel? how to get mysql updates automatically within cwp panel?
Regards,
Zee
mysql is not updating in almalinux 9.7 automatically from cwp panel? how to get mysql updates automatically within cwp panel?
Regards,
Zee
3
PHP / how to install and configure relay extension for php-fpm83 in cwp
« on: February 05, 2026, 11:33:25 AM »
hello,
can someone guide me how to install and configure relay extension for php-fpm83 in cwp for redis cache server. i have already installed redis cache server and its working perfectly fine. just want to install and configure relay extension with the per-requsits json, igbinary, and msgpack ,
i cant find them on php-fpm selector options these extensions.
Regards,
Zee
can someone guide me how to install and configure relay extension for php-fpm83 in cwp for redis cache server. i have already installed redis cache server and its working perfectly fine. just want to install and configure relay extension with the per-requsits json, igbinary, and msgpack ,
i cant find them on php-fpm selector options these extensions.
Regards,
Zee
4
CentOS 9 Problems / ClamAV issue in user panel
« on: February 02, 2026, 01:58:47 PM »
clamAV is installed and running in cwp admin panel and successfully running scan but under user panel it shows clamav not installed contact administrator. this happened after i migrated my cwp panel from centos 7 to almalinux 9 . it seems like some permission issue for user panel after restoring from cwp complete backup to almalinux 9 server.
does any one know how to fix this issue?
i already tried to rebuild mail server by selecting clamav/amavis option but it says already installed and running.
does any one know how to fix this issue?
i already tried to rebuild mail server by selecting clamav/amavis option but it says already installed and running.
5
Mod_Security / atomic crop. free waf rules set
« on: January 30, 2026, 04:47:32 PM »
hello,
does anyone know how to safely install free version of atomic crop. free waf rules set in cwp pro? i am currently using comodo waf rules but as you all know its discontinued in 2024 but they were the best with minimum false positives.
i tried to use OWASP Latest instead in my cwp pro but it has got so many false positives and blocks all my hosted website even after fine tuning. comodo waf rules works just fine but outdated
i was wondering if someone have used atomic crop. free waf rules as i can see its reviews are good so i wanna try it instead of comodo waf rules. atleast atomic crop. free rules are updated once a month or so ... have anyone tried it ? would appretiate if someone can post step by step guide to install atomic crop. free waf rules instead of currently installed comodo waf rules in my cwp pro to avoid conflits on a live server. thanks ..
does anyone know how to safely install free version of atomic crop. free waf rules set in cwp pro? i am currently using comodo waf rules but as you all know its discontinued in 2024 but they were the best with minimum false positives.
i tried to use OWASP Latest instead in my cwp pro but it has got so many false positives and blocks all my hosted website even after fine tuning. comodo waf rules works just fine but outdated

i was wondering if someone have used atomic crop. free waf rules as i can see its reviews are good so i wanna try it instead of comodo waf rules. atleast atomic crop. free rules are updated once a month or so ... have anyone tried it ? would appretiate if someone can post step by step guide to install atomic crop. free waf rules instead of currently installed comodo waf rules in my cwp pro to avoid conflits on a live server. thanks ..
6
Mod_Security / issues while switching from comodo waf to OWASP latest waf
« on: September 02, 2025, 12:33:20 AM »
hello,
when i select OWASP latest waf rules for mod security it only shows warning for threats seen in logs below , but when i choose comodo waf rules it blocks threats straight away ? where i can set OWASP rules to not only detect threats and give warning but blocks straight away ? where is this settings?
see the logs below :-
[Tue Sep 02 02:16:30.470800 2025] [:error] [pid 3863547:tid 3863552] [client 172.68.242.3:46086] [client 172.68.242.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY3Xq8tK4SCYBVQOmR2VAAAAMM"]
[Tue Sep 02 02:05:50.982678 2025] [:error] [pid 3863547:tid 3863573] [client 172.71.124.61:61906] [client 172.71.124.61] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY03q8tK4SCYBVQOmR1sgAAANg"]
[Tue Sep 02 02:04:17.831963 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831915 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831837 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831787 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831733 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831671 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831585 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:cf_clearance. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -1756771434-1.2.1.1- found within REQUEST_COOKIES:cf_clearance: E4AZPOvWWFn9LaMl2sMYYsLsva7GlacW0uTj4ygxzpM-1756771434-1.2.1.1-fQtJQaEGGv_DFtXO7FTSU22Ad_KLVssWMNrweQ85LktxYvfqYPHaniQWL1yjQ9_rCVQXnD9b3gVBRk_UTN5o2B_8uiXoLlRQO5q.SWPn_wm.t.zD2Of_OYECae16l67oovKxUR7b6XMbK.b3cqZfPuobsZM..sm5qaWvzSLSc5vwFFLbw_LrqKnx8Z.XrgKHj4Ge7HZC6V4EpW9hYkSncup0fsahDpc9XzNdUYg3.qc"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/100 [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831472 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||cpg=https://bedrive.sws.net.pk/?foo=http% found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831412 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||uip=(none)| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831352 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831302 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831227 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831109 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
when i select OWASP latest waf rules for mod security it only shows warning for threats seen in logs below , but when i choose comodo waf rules it blocks threats straight away ? where i can set OWASP rules to not only detect threats and give warning but blocks straight away ? where is this settings?
see the logs below :-
[Tue Sep 02 02:16:30.470800 2025] [:error] [pid 3863547:tid 3863552] [client 172.68.242.3:46086] [client 172.68.242.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY3Xq8tK4SCYBVQOmR2VAAAAMM"]
[Tue Sep 02 02:05:50.982678 2025] [:error] [pid 3863547:tid 3863573] [client 172.71.124.61:61906] [client 172.71.124.61] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY03q8tK4SCYBVQOmR1sgAAANg"]
[Tue Sep 02 02:04:17.831963 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831915 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831837 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831787 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831733 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831671 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831585 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:cf_clearance. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -1756771434-1.2.1.1- found within REQUEST_COOKIES:cf_clearance: E4AZPOvWWFn9LaMl2sMYYsLsva7GlacW0uTj4ygxzpM-1756771434-1.2.1.1-fQtJQaEGGv_DFtXO7FTSU22Ad_KLVssWMNrweQ85LktxYvfqYPHaniQWL1yjQ9_rCVQXnD9b3gVBRk_UTN5o2B_8uiXoLlRQO5q.SWPn_wm.t.zD2Of_OYECae16l67oovKxUR7b6XMbK.b3cqZfPuobsZM..sm5qaWvzSLSc5vwFFLbw_LrqKnx8Z.XrgKHj4Ge7HZC6V4EpW9hYkSncup0fsahDpc9XzNdUYg3.qc"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/100 [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831472 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||cpg=https://bedrive.sws.net.pk/?foo=http% found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831412 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||uip=(none)| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831352 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831302 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831227 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831109 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com7
CentOS 9 Problems / not able to login to admin panel after password restart
« on: August 21, 2025, 11:33:46 PM »
hello, i changed root password and since then i am not able to login to admin cwp panel its giving login failed. i am able to login fine via SSH and even tried to change password again from SSH using passwd root but still not able to login to cwp admin panel at https://cpanel.sws.net.pk:2087
i am using almalinux 9 and its updated. can somebody suggest me how to fix cwp admin panel login .
Regards,
Zeej
i am using almalinux 9 and its updated. can somebody suggest me how to fix cwp admin panel login .
Regards,
Zeej
8
Suggestions / kindly update comodo waf rules as its outdated since long
« on: February 17, 2025, 11:17:07 AM »
kindly update comodo waf rules as its outdated since long , its not updated anymore in CWP Pro.
9
Suggestions / :):):) Comodo WAF rules update required :):):)
« on: November 12, 2024, 01:18:25 PM »
hello,
kindly update comodo waf rules for mod security in cwp as new version waf rules have many fixes for known issues. its pending since long to update .
Regards,
Zee
kindly update comodo waf rules for mod security in cwp as new version waf rules have many fixes for known issues. its pending since long to update .
Regards,
Zee
10
Mod_Security / MOD SECURITY issue on new CWP PRO INSTALLATION
« on: September 08, 2024, 05:49:43 PM »
hello,
i have recently installed CWP pro on a new Almalinux 9,everything is working fine but when i install MOD Security all the websites goes down and give below error: when i uninstall MOD Security all sites start working fine. what could be wrong ? and how to fix it any suggestions plz
Unable to connect
An error occurred during a connection to 38.242.244.140.
The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer’s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the web.
i have recently installed CWP pro on a new Almalinux 9,everything is working fine but when i install MOD Security all the websites goes down and give below error: when i uninstall MOD Security all sites start working fine. what could be wrong ? and how to fix it any suggestions plz
Unable to connect
An error occurred during a connection to 38.242.244.140.
The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer’s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the web.
11
SSL / ssl for ftp
« on: May 17, 2021, 11:38:41 AM »
hello,
ssl for my domain is showing 56 days left in cwp pro and have valid SSL installed for all services i.e. mail, webmail, ftp, cpanel , but when i conntect to ftp via ftp client (filezilla) , it shows certificate expired. see the below snapshot for reference. kindly suggest me how to fix this ssl expiry message issue.
ssl for my domain is showing 56 days left in cwp pro and have valid SSL installed for all services i.e. mail, webmail, ftp, cpanel , but when i conntect to ftp via ftp client (filezilla) , it shows certificate expired. see the below snapshot for reference. kindly suggest me how to fix this ssl expiry message issue.
12
Mod_Security / modsecurity not updated in cwp pro
« on: August 06, 2020, 12:30:02 AM »
hello,
current version installed for modsecurity in cwp pro is : 1.230 but the latest version released for ModSecurity is 3.0.4 (Jan 13, 2020).
how to get it updated in cwp pro?
Regards,
ZeejDeej
current version installed for modsecurity in cwp pro is : 1.230 but the latest version released for ModSecurity is 3.0.4 (Jan 13, 2020).
how to get it updated in cwp pro?
Regards,
ZeejDeej
13
Softaculous / magento issue after installation
« on: August 03, 2020, 10:38:33 AM »
hello,
i have successfully installed magento via softaculous but its not showing up css/images/page format correctly. can anyone suggest me how to fix this issue. i am using cwp pro and running nginx/varnish/apache as web server configuration.
https://test.esoftware.pk/
https://test.esoftware.pk/admin
admin panel also showing text only
kindly suggest how to configure magento 2 on cwp pro
Regards,
ZeejDeej
i have successfully installed magento via softaculous but its not showing up css/images/page format correctly. can anyone suggest me how to fix this issue. i am using cwp pro and running nginx/varnish/apache as web server configuration.
https://test.esoftware.pk/
https://test.esoftware.pk/admin
admin panel also showing text only
kindly suggest how to configure magento 2 on cwp pro
Regards,
ZeejDeej
14
DNS / DNS server failed to load
« on: June 16, 2020, 12:35:33 AM »
hello,
i am having issues with dns server , its giving following error while loading. kindly suggest how to fix these errors.
there are two main errors i see due to which dns server is not loading the zone file.
/var/named/esoftware.pk.db:36: file does not end with newline
what does this means? and how to end with newline?
zone esoftware.pk/IN: has no NS records
when i try to add NS record in dns zone file it gives error , (there is some error with configuration, please check and update)
also i am not able to add A record for ns1 and ns2 to point to my server IP
-- Unit named.service has begun starting up.
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone localhost.localdomain/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone localhost/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone 0.in-addr.arpa/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: /var/named/esoftware.pk.db:36: file does not end with newline
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone esoftware.pk/IN: has no NS records
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone esoftware.pk/IN: not loaded due to errors.
Jun 15 15:59:16 server.esoftware.pk bash[26011]: _default/esoftware.pk/IN: bad zone
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns1.esoftware.pk/IN: loaded serial 2020061400
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns2.esoftware.pk/IN: loaded serial 2020061400
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns1.test-domain.com/IN: loaded serial 2013071600
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns2.test-domain.com/IN: loaded serial 2013071600
Jun 15 15:59:16 server.esoftware.pk systemd[1]: named.service: control process exited, code=exited status=1
Jun 15 15:59:16 server.esoftware.pk systemd[1]: Failed to start Berkeley Internet Name Domain (DNS).
-- Subject: Unit named.service has failed
i am having issues with dns server , its giving following error while loading. kindly suggest how to fix these errors.
there are two main errors i see due to which dns server is not loading the zone file.
/var/named/esoftware.pk.db:36: file does not end with newline
what does this means? and how to end with newline?
zone esoftware.pk/IN: has no NS records
when i try to add NS record in dns zone file it gives error , (there is some error with configuration, please check and update)
also i am not able to add A record for ns1 and ns2 to point to my server IP
-- Unit named.service has begun starting up.
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone localhost.localdomain/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone localhost/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone 1.0.0.127.in-addr.arpa/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone 0.in-addr.arpa/IN: loaded serial 0
Jun 15 15:59:16 server.esoftware.pk bash[26011]: /var/named/esoftware.pk.db:36: file does not end with newline
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone esoftware.pk/IN: has no NS records
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone esoftware.pk/IN: not loaded due to errors.
Jun 15 15:59:16 server.esoftware.pk bash[26011]: _default/esoftware.pk/IN: bad zone
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns1.esoftware.pk/IN: loaded serial 2020061400
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns2.esoftware.pk/IN: loaded serial 2020061400
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns1.test-domain.com/IN: loaded serial 2013071600
Jun 15 15:59:16 server.esoftware.pk bash[26011]: zone ns2.test-domain.com/IN: loaded serial 2013071600
Jun 15 15:59:16 server.esoftware.pk systemd[1]: named.service: control process exited, code=exited status=1
Jun 15 15:59:16 server.esoftware.pk systemd[1]: Failed to start Berkeley Internet Name Domain (DNS).
-- Subject: Unit named.service has failed
15
CentOS Configuration / monit alert -- Upload bytes exceeded public
« on: May 26, 2020, 11:13:24 AM »
what does this alert means? any idea
Upload bytes exceeded Service public
Date: Mon, 25 May 2020 11:08:23
Action: alert
Host: server.baringslaw.group
Description: total upload 1.0 GB matches limit [upload rate > 1 GB in last 1 hour]
Your faithful employee,
Monit
Upload bytes exceeded Service public
Date: Mon, 25 May 2020 11:08:23
Action: alert
Host: server.baringslaw.group
Description: total upload 1.0 GB matches limit [upload rate > 1 GB in last 1 hour]
Your faithful employee,
Monit
Pages: [1] 2
