This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
16
Mod_Security / Re: atomic crop. free waf rules set
« on: January 31, 2026, 04:43:23 PM »
once i update mod security to v 2.9.12 do i have to do any further configuration in cwp pro to use the latest updated version of OWASP waf rules ? or cwp will update and use OWASF rules automatically?
17
Mod_Security / Re: MOD SECURITY issue on new CWP PRO INSTALLATION
« on: January 31, 2026, 04:41:25 PM »
no i am taking about this :
https://atomicorp.com/free-modsecurity-rules/
https://atomicorp.com/free-modsecurity-rules/
18
Mod_Security / Re: MOD SECURITY issue on new CWP PRO INSTALLATION
« on: January 30, 2026, 05:01:45 PM »
i think cwp should consider integrating atomic crop. free waf rules in cwp panel so everyone can benifit using it . manual installation and configuration have too many errors and conflicts as cwp got custom configuration only cwp panel admins knows best.
19
Mod_Security / Re: MOD SECURITY issue on new CWP PRO INSTALLATION
« on: January 30, 2026, 04:58:57 PM »
my cwp pro is stuck at comodo waf v 1.240 i tried many times to update to v 1.241 manually by replacing the waf rules files but it revert back to v. 1.240 most probably due to cwp automatic update cron job.
i tried to switch to OWASP latest but as you said it had too many false positives and even after fine tuning i am not able to keep my hosted website unblocked.
i want to try atomic crop free waf rules as i heard they are good and atleast updates once a month and have lesser false positives? have you tried it? any suggestions
i tried to switch to OWASP latest but as you said it had too many false positives and even after fine tuning i am not able to keep my hosted website unblocked.
i want to try atomic crop free waf rules as i heard they are good and atleast updates once a month and have lesser false positives? have you tried it? any suggestions
20
Mod_Security / atomic crop. free waf rules set
« on: January 30, 2026, 04:47:32 PM »
hello,
does anyone know how to safely install free version of atomic crop. free waf rules set in cwp pro? i am currently using comodo waf rules but as you all know its discontinued in 2024 but they were the best with minimum false positives.
i tried to use OWASP Latest instead in my cwp pro but it has got so many false positives and blocks all my hosted website even after fine tuning. comodo waf rules works just fine but outdated
i was wondering if someone have used atomic crop. free waf rules as i can see its reviews are good so i wanna try it instead of comodo waf rules. atleast atomic crop. free rules are updated once a month or so ... have anyone tried it ? would appretiate if someone can post step by step guide to install atomic crop. free waf rules instead of currently installed comodo waf rules in my cwp pro to avoid conflits on a live server. thanks ..
does anyone know how to safely install free version of atomic crop. free waf rules set in cwp pro? i am currently using comodo waf rules but as you all know its discontinued in 2024 but they were the best with minimum false positives.
i tried to use OWASP Latest instead in my cwp pro but it has got so many false positives and blocks all my hosted website even after fine tuning. comodo waf rules works just fine but outdated

i was wondering if someone have used atomic crop. free waf rules as i can see its reviews are good so i wanna try it instead of comodo waf rules. atleast atomic crop. free rules are updated once a month or so ... have anyone tried it ? would appretiate if someone can post step by step guide to install atomic crop. free waf rules instead of currently installed comodo waf rules in my cwp pro to avoid conflits on a live server. thanks ..
21
CentOS-WebPanel Bugs / Re: [CRITICAL] Multiple CWP Servers Infected – Arbitrary PHP Code Execution via Publ
« on: September 05, 2025, 01:04:17 PM »
i understand that is for the future prevention but what to do with the current infection . should i delete the below two file manually from all sites public_html directories ?
defauit.php
nbpafebaef.jpg
defauit.php
nbpafebaef.jpg
22
CentOS-WebPanel Bugs / Re: [CRITICAL] Multiple CWP Servers Infected – Arbitrary PHP Code Execution via Publ
« on: September 05, 2025, 08:32:37 AM »🛑 What I Found
On my server, inside /home/username/public_html/public/ and /home/username/public_html/, I found two suspicious files:
• nbpafebaef.jpg – Contains PHP code despite the .jpg extension:
<?php echo md5("gewafwaef1");die;?>
• defauit.php – A PHP script with a misleading name (looks like “default.php”).
i also found these two files in my public_html folder, what should i do with them should i deleted them both? how to make sure there is no other similar exploit?
23
Mod_Security / Re: issues while switching from comodo waf to OWASP latest waf
« on: September 02, 2025, 08:02:17 AM »
how can i use the OWASP Latest (latest version with automatic updates) option in CWP mod security? i enabled it and its detecting threats means its triggering WAF rules but only showing warning in log file not blocking threats ? how to set it up for blocking threats which its already detecting and can be seen as warning in log file.
24
Mod_Security / issues while switching from comodo waf to OWASP latest waf
« on: September 02, 2025, 12:33:20 AM »
hello,
when i select OWASP latest waf rules for mod security it only shows warning for threats seen in logs below , but when i choose comodo waf rules it blocks threats straight away ? where i can set OWASP rules to not only detect threats and give warning but blocks straight away ? where is this settings?
see the logs below :-
[Tue Sep 02 02:16:30.470800 2025] [:error] [pid 3863547:tid 3863552] [client 172.68.242.3:46086] [client 172.68.242.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY3Xq8tK4SCYBVQOmR2VAAAAMM"]
[Tue Sep 02 02:05:50.982678 2025] [:error] [pid 3863547:tid 3863573] [client 172.71.124.61:61906] [client 172.71.124.61] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY03q8tK4SCYBVQOmR1sgAAANg"]
[Tue Sep 02 02:04:17.831963 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831915 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831837 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831787 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831733 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831671 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831585 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:cf_clearance. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -1756771434-1.2.1.1- found within REQUEST_COOKIES:cf_clearance: E4AZPOvWWFn9LaMl2sMYYsLsva7GlacW0uTj4ygxzpM-1756771434-1.2.1.1-fQtJQaEGGv_DFtXO7FTSU22Ad_KLVssWMNrweQ85LktxYvfqYPHaniQWL1yjQ9_rCVQXnD9b3gVBRk_UTN5o2B_8uiXoLlRQO5q.SWPn_wm.t.zD2Of_OYECae16l67oovKxUR7b6XMbK.b3cqZfPuobsZM..sm5qaWvzSLSc5vwFFLbw_LrqKnx8Z.XrgKHj4Ge7HZC6V4EpW9hYkSncup0fsahDpc9XzNdUYg3.qc"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/100 [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831472 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||cpg=https://bedrive.sws.net.pk/?foo=http% found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831412 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||uip=(none)| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831352 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831302 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831227 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831109 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
when i select OWASP latest waf rules for mod security it only shows warning for threats seen in logs below , but when i choose comodo waf rules it blocks threats straight away ? where i can set OWASP rules to not only detect threats and give warning but blocks straight away ? where is this settings?
see the logs below :-
[Tue Sep 02 02:16:30.470800 2025] [:error] [pid 3863547:tid 3863552] [client 172.68.242.3:46086] [client 172.68.242.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY3Xq8tK4SCYBVQOmR2VAAAAMM"]
[Tue Sep 02 02:05:50.982678 2025] [:error] [pid 3863547:tid 3863573] [client 172.71.124.61:61906] [client 172.71.124.61] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||bedrive.sws.net.pk|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?test=%2Fetc%2Fhost"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bedrive.sws.net.pk"] [uri "/"] [unique_id "aLY03q8tK4SCYBVQOmR1sgAAANg"]
[Tue Sep 02 02:04:17.831963 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831915 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =1|| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831837 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831787 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =typein|| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831733 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831671 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: =2025-09- found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/4"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831585 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){3})" at REQUEST_COOKIES:cf_clearance. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1560"] [id "942421"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)"] [data "Matched Data: -1756771434-1.2.1.1- found within REQUEST_COOKIES:cf_clearance: E4AZPOvWWFn9LaMl2sMYYsLsva7GlacW0uTj4ygxzpM-1756771434-1.2.1.1-fQtJQaEGGv_DFtXO7FTSU22Ad_KLVssWMNrweQ85LktxYvfqYPHaniQWL1yjQ9_rCVQXnD9b3gVBRk_UTN5o2B_8uiXoLlRQO5q.SWPn_wm.t.zD2Of_OYECae16l67oovKxUR7b6XMbK.b3cqZfPuobsZM..sm5qaWvzSLSc5vwFFLbw_LrqKnx8Z.XrgKHj4Ge7HZC6V4EpW9hYkSncup0fsahDpc9XzNdUYg3.qc"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/100 [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com
[Tue Sep 02 02:04:17.831472 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_session. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||cpg=https://bedrive.sws.net.pk/?foo=http% found within REQUEST_COOKIES:sbjs_session: pgs=1|||cpg=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831412 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_udata. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =1|||uip=(none)| found within REQUEST_COOKIES:sbjs_udata: vst=1|||uip=(none)|||uag=Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:142.0) Gecko/20100101 Firefox/142.0"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831352 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_first: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831302 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =typein|||src=(direct)| found within REQUEST_COOKIES:sbjs_current: typ=typein|||src=(direct)|||mdm=(none)|||cmp=(none)|||cnt=(none)|||trm=(none)|||id=(none)|||plt=(none)|||fmt=(none)|||tct=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831227 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_first_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_first_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com[Tue Sep 02 02:04:17.831109 2025] [:error] [pid 3862841:tid 3862843] [client 172.71.82.121:44854] [client 172.71.82.121] ModSecurity: Warning. Pattern match "((?:[~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>][^~!@#\\\\$%\\\\^&\\\\*\\\\(\\\\)\\\\-\\\\+=\\\\{\\\\}\\\\[\\\\]\\\\|:;\\"'\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98`<>]*?){8})" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "1384"] [id "942420"] [msg "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (
"] [data "Matched Data: =2025-09-02 00:04:12||| found within REQUEST_COOKIES:sbjs_current_add: fd=2025-09-02 00:04:12|||ep=https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com|||rf=(none)"] [severity "WARNING"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [tag "paranoia-level/3"] [hostname "bedrive.sws.net.pk"] [uri "/wp-content/uploads/2023/05/spa-girl-5.png"] [unique_id "aLY0gUYRr8i8nLke5Yyl5wAAAMA"], referer: https://bedrive.sws.net.pk/?foo=http%3A%2F%2Fwww.example.com25
CentOS 9 Problems / Re: not able to login to admin panel after password restart
« on: August 22, 2025, 12:30:23 AM »
ISSUE RESOLVED

To fix the CWP/cPanel login issue after a password change on AlmaLinux 9, you need to access the server via SSH and use the passwd command with the correct username, such as passwd root, to ensure the password change is applied correctly to the system and CWP. Additionally, you may need to disable a specific line in /etc/login.defs and restart services to resolve incompatibility issues with CWP on AlmaLinux 9, especially after a fresh installation.
1. Use SSH to Access Your Server
Connect to your AlmaLinux 9 server using an SSH client.
2. Reset the Password Using passwd
Execute the passwd command, replacing root with the appropriate username (e.g., passwd root or passwd cwp_user).
Enter the new password twice when prompted.
3. Apply a CWP-Specific Fix
Edit /etc/login.defs:
Open the file using nano /etc/login.defs.
Comment out the line SHA_CRYPT_MAX_ROUNDS 5000 by adding a # at the beginning.
after commenting above line change password again using SSH command #passwd root and you are all done.
Restart CWP Services:
Run sh /usr/local/cwpsrv/htdocs/resources/scripts/restart_cwpsrv.sh or similar commands to restart the CWP services.
Enjoy

26
CentOS 9 Problems / not able to login to admin panel after password restart
« on: August 21, 2025, 11:33:46 PM »
hello, i changed root password and since then i am not able to login to admin cwp panel its giving login failed. i am able to login fine via SSH and even tried to change password again from SSH using passwd root but still not able to login to cwp admin panel at https://cpanel.sws.net.pk:2087
i am using almalinux 9 and its updated. can somebody suggest me how to fix cwp admin panel login .
Regards,
Zeej
i am using almalinux 9 and its updated. can somebody suggest me how to fix cwp admin panel login .
Regards,
Zeej
27
Suggestions / kindly update comodo waf rules as its outdated since long
« on: February 17, 2025, 11:17:07 AM »
kindly update comodo waf rules as its outdated since long , its not updated anymore in CWP Pro.
28
Suggestions / Re: :):):) Comodo WAF rules update required :):):)
« on: January 24, 2025, 01:37:53 PM »
why comodo waf rules are not updated automatically in CWP Pro like it was updating before. since long its not updated?
29
Suggestions / Re: :):):) Comodo WAF rules update required :):):)
« on: November 16, 2024, 06:29:50 PM »
yes it worked after disabling SecRuleRemoveById 218500 but comodo waf rules keep switching back to 1.240 after a while automatically. i do update to 1.241 and it showed for a while but revert back to 1.240
30
Suggestions / Re: :):):) Comodo WAF rules update required :):):)
« on: November 16, 2024, 03:11:50 AM »
[Sat Nov 16 04:08:49.493070 2024] [:error] [pid 1333365:tid 1333386] [client 182.183.59.223:63036] [client 182.183.59.223] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(\\\\!\\\\=|\\\\&\\\\&|\\\\|\\\\||>>|<<|>=|<=|<>|<=>|xor|rlike|regexp|isnull)|(?:not\\\\s+between\\\\s+0\\\\s+and)|(?:is\\\\s+null)|(like\\\\s+null)|(?
?:^|\\\\W)in[+\\\\s]*\\\\([\\\\s\\\\d\\"]+[^()]*\\\\))|(?:xor|<>|rlike(?:\\\\s+binary)?)|(?:regexp\\\\s+binary))" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-old/base_rules/modsecurity_crs_41_sql_injection_attacks.conf"] [line "70"] [id "981319"] [rev "2"] [msg "SQL Injection Attack: SQL Operator Detected"] [data "Matched Data: || found within REQUEST_COOKIES:sbjs_current_add: fd=2024-11-16 02:48:21|||ep=https://fizascollection.co.uk/|||rf=(none)"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "8"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "fizascollection.co.uk"] [uri "/favicon.ico"] [unique_id "ZzgMwaSdHEb44HSsRSRFyAAAAEA"], referer: https://fizascollection.co.uk/
[Sat Nov 16 04:08:48.967452 2024] [:error] [pid 1333365:tid 1333390] [client 182.183.59.223:63036] [client 182.183.59.223] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(\\\\!\\\\=|\\\\&\\\\&|\\\\|\\\\||>>|<<|>=|<=|<>|<=>|xor|rlike|regexp|isnull)|(?:not\\\\s+between\\\\s+0\\\\s+and)|(?:is\\\\s+null)|(like\\\\s+null)|(?
?:^|\\\\W)in[+\\\\s]*\\\\([\\\\s\\\\d\\"]+[^()]*\\\\))|(?:xor|<>|rlike(?:\\\\s+binary)?)|(?:regexp\\\\s+binary))" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-old/base_rules/modsecurity_crs_41_sql_injection_attacks.conf"] [line "70"] [id "981319"] [rev "2"] [msg "SQL Injection Attack: SQL Operator Detected"] [data "Matched Data: || found within REQUEST_COOKIES:sbjs_current_add: fd=2024-11-16 02:48:21|||ep=https://fizascollection.co.uk/|||rf=(none)"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "8"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "fizascollection.co.uk"] [uri "/"] [unique_id "ZzgMwKSdHEb44HSsRSRFxwAAAEI"]
?:^|\\\\W)in[+\\\\s]*\\\\([\\\\s\\\\d\\"]+[^()]*\\\\))|(?:xor|<>|rlike(?:\\\\s+binary)?)|(?:regexp\\\\s+binary))" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-old/base_rules/modsecurity_crs_41_sql_injection_attacks.conf"] [line "70"] [id "981319"] [rev "2"] [msg "SQL Injection Attack: SQL Operator Detected"] [data "Matched Data: || found within REQUEST_COOKIES:sbjs_current_add: fd=2024-11-16 02:48:21|||ep=https://fizascollection.co.uk/|||rf=(none)"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "8"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "fizascollection.co.uk"] [uri "/favicon.ico"] [unique_id "ZzgMwaSdHEb44HSsRSRFyAAAAEA"], referer: https://fizascollection.co.uk/[Sat Nov 16 04:08:48.967452 2024] [:error] [pid 1333365:tid 1333390] [client 182.183.59.223:63036] [client 182.183.59.223] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(\\\\!\\\\=|\\\\&\\\\&|\\\\|\\\\||>>|<<|>=|<=|<>|<=>|xor|rlike|regexp|isnull)|(?:not\\\\s+between\\\\s+0\\\\s+and)|(?:is\\\\s+null)|(like\\\\s+null)|(?
?:^|\\\\W)in[+\\\\s]*\\\\([\\\\s\\\\d\\"]+[^()]*\\\\))|(?:xor|<>|rlike(?:\\\\s+binary)?)|(?:regexp\\\\s+binary))" at REQUEST_COOKIES:sbjs_current_add. [file "/usr/local/apache/modsecurity-owasp-old/base_rules/modsecurity_crs_41_sql_injection_attacks.conf"] [line "70"] [id "981319"] [rev "2"] [msg "SQL Injection Attack: SQL Operator Detected"] [data "Matched Data: || found within REQUEST_COOKIES:sbjs_current_add: fd=2024-11-16 02:48:21|||ep=https://fizascollection.co.uk/|||rf=(none)"] [severity "CRITICAL"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "8"] [tag "OWASP_CRS/WEB_ATTACK/SQL_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "fizascollection.co.uk"] [uri "/"] [unique_id "ZzgMwKSdHEb44HSsRSRFxwAAAEI"]