{"id":641,"date":"2018-03-05T02:24:15","date_gmt":"2018-03-05T02:24:15","guid":{"rendered":"http:\/\/orissawebhosting.in\/blog\/?p=641"},"modified":"2019-07-01T15:08:19","modified_gmt":"2019-07-01T15:08:19","slug":"how-to-check-website-attacks-in-modsecurity-whm","status":"publish","type":"post","link":"https:\/\/orissawebhosting.in\/blog\/how-to-check-website-attacks-in-modsecurity-whm\/","title":{"rendered":"How to Check Website Attacks in ModSecurity WHM"},"content":{"rendered":"<h4>Check website attacks in ModSecurity\u00a0WHM<\/h4>\n<p>ModSecurity is already installed with WHM but you need to configure it before it can start working properly.<\/p>\n<p>Once configured login to your WHM panel.\u00a0\u00a0Click \u2018ModSecurity Configuration\u2019 with in Security Center.<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-643 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod11.jpg\" alt=\"\" width=\"1360\" height=\"570\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod11.jpg 1360w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod11-300x126.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod11-768x322.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod11-1024x429.jpg 1024w\" sizes=\"(max-width: 1360px) 100vw, 1360px\" \/><\/p>\n<\/div>\n<p>By default the\u00a0hundred of modsecurity rules are default enabled in the WHM by\u00a0ModSecurity\u2122 Vendors.<\/p>\n<p>If you want to know the Rules list &gt;&gt;\u00a0Security Center &gt;&gt; ModSecurity\u2122 Tools &gt;&gt; Rules List<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-644 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod22.jpg\" alt=\"\" width=\"1170\" height=\"289\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod22.jpg 1170w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod22-300x74.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod22-768x190.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod22-1024x253.jpg 1024w\" sizes=\"(max-width: 1170px) 100vw, 1170px\" \/><\/p>\n<\/div>\n<p>Once clicked you can see the numerous rules sets.<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-645 size-large\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod33-1024x424.jpg\" alt=\"\" width=\"640\" height=\"265\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod33-1024x424.jpg 1024w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod33-300x124.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod33-768x318.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod33.jpg 1151w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/p>\n<\/div>\n<p><strong>Test rule and view the logs<\/strong><\/p>\n<p>For example &#8211; Someone perform any vulnerability scripts, plugins or themes if the modsecurity rule ID matches the strings in Rules, it will\u00a0block the web request and report to the logs.<\/p>\n<p>The website through error as &#8220;404 page not found&#8221; like below.<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-646 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod44.jpg\" alt=\"\" width=\"1222\" height=\"635\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod44.jpg 1222w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod44-300x156.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod44-768x399.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod44-1024x532.jpg 1024w\" sizes=\"(max-width: 1222px) 100vw, 1222px\" \/><\/p>\n<\/div>\n<p>As you can see in the image below that the attack we just simulated is logged inside WHM, just click \u2018ModSecurity Tools\u2019 under security center and you can see all the attack logs. You can see following details about the attack:<\/p>\n<ul>\n<li>URL For the web attack.<\/li>\n<li>How was this request handled.<\/li>\n<li>Which rule this attack matched against.<\/li>\n<\/ul>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-648 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod55-1.jpg\" alt=\"\" width=\"1112\" height=\"448\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod55-1.jpg 1112w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod55-1-300x121.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod55-1-768x309.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod55-1-1024x413.jpg 1024w\" sizes=\"(max-width: 1112px) 100vw, 1112px\" \/><\/p>\n<\/div>\n<p><strong>How to white list the ModSecurity rule ID<\/strong><\/p>\n<p>First you have install the plugin\u00a0&#8220;ConfigServer ModSecurity Control&#8221; in WHM panel by using below steps.<\/p>\n<p>Download and install cmc\u00a0&#8220;ConfigServer ModSecurity Control&#8221;<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<pre>cd \/usr\/src\nrm -fv \/usr\/src\/cmc.tgz\nwget http:\/\/download.configserver.com\/cmc.tgz\ntar -xzf cmc.tgz\ncd cmc\nsh install.sh\nrm -Rfv \/usr\/src\/cmc*<\/pre>\n<\/div>\n<p>Login to WHM and scroll to the bottom of the left hand menu and you should see &#8220;ConfigServer ModSecurity Control&#8221;<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-675 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod444.jpg\" alt=\"\" width=\"1102\" height=\"123\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod444.jpg 1102w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod444-300x33.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod444-768x86.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod444-1024x114.jpg 1024w\" sizes=\"(max-width: 1102px) 100vw, 1102px\" \/><\/p>\n<\/div>\n<p>You can add ModSecurity rule ID numbers that you want to be globally disabled.<\/p>\n<p>Alternatively, you can disable rules on a per cPanel account or per domain basis by selecting a user.<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-652 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod2.jpg\" alt=\"\" width=\"1318\" height=\"551\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod2.jpg 1318w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod2-300x125.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod2-768x321.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod2-1024x428.jpg 1024w\" sizes=\"(max-width: 1318px) 100vw, 1318px\" \/><\/p>\n<\/div>\n<p>Else If you wants whitelist the rule ID for particular domain name, Follow the below Steps<\/p>\n<p>Click the domain name &#8220;orissawebtesting.com&#8221; &gt;&gt; Modify user whitelist &gt;&gt; It will redirects to another page.<\/p>\n<p>There enter the rule Id Which you wants to enable it &gt;&gt; Click &#8220;Save whitelist for all orissawebtest domains.<\/p>\n<p>Once you clicked, it take some time for REBUILDING and RESTARTING the Apache.<\/p>\n<div class=\"eds-animate  \" data-eds-entry-animation=\"jello\" data-eds-entry-delay=\"0\" data-eds-entry-duration=\"1.0\" data-eds-entry-timing=\"linear\" data-eds-exit-animation=\"\" data-eds-exit-delay=\"\" data-eds-exit-duration=\"\" data-eds-exit-timing=\"\" data-eds-repeat-count=\"1\" data-eds-keep=\"yes\" data-eds-animate-on=\"scroll\" data-eds-scroll-offset=\"75\">\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-676 size-full\" src=\"http:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod6-1.jpg\" alt=\"\" width=\"1333\" height=\"315\" srcset=\"https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod6-1.jpg 1333w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod6-1-300x71.jpg 300w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod6-1-768x181.jpg 768w, https:\/\/orissawebhosting.in\/blog\/wp-content\/uploads\/2018\/03\/mod6-1-1024x242.jpg 1024w\" sizes=\"(max-width: 1333px) 100vw, 1333px\" \/><\/p>\n<\/div>\n<p>Once Apache Restarted &gt;&gt; You can see the success message as above &gt;&gt; Now all done.<\/p>\n<p>Now your website will load fine and you can perform the back-end processes.<\/p>\n<p>Now that you can know the step whitelist the ModSecurity rule ID.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Check website attacks in ModSecurity\u00a0WHM ModSecurity is already installed with WHM but you need to configure it before it can start working properly. Once configured login to your WHM panel.\u00a0\u00a0Click \u2018ModSecurity Configuration\u2019 with in Security Center. By default the\u00a0hundred of modsecurity rules are default enabled in the WHM by\u00a0ModSecurity\u2122 Vendors. If you want to know the Rules list &gt;&gt;\u00a0Security Center &gt;&gt; ModSecurity\u2122 Tools &gt;&gt; Rules List Once clicked you can see the numerous rules sets. Test rule and view the logs For example &#8211; Someone perform any vulnerability scripts, plugins&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/641"}],"collection":[{"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/comments?post=641"}],"version-history":[{"count":9,"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/641\/revisions"}],"predecessor-version":[{"id":1080,"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/posts\/641\/revisions\/1080"}],"wp:attachment":[{"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/media?parent=641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/categories?post=641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/orissawebhosting.in\/blog\/wp-json\/wp\/v2\/tags?post=641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}