• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question ModSecurity with Comodo; Where report false-positive?

Azurel

Silver Pleskian
Server operating system version
AlmaLinux 8.8 (Sapphire Caracal)
Plesk version and microupdate number
18.0.56 #3
In Plesk ModSecurity use Comodo for rules; Does anyone know if and where you can report false-positives to Comodo?

And does anyone know where I can view the pattern for a rule? Is there a general overview? Unfortunately, the modsec_audit.log only contains an excerpt of the pattern.
 
The rule definitions for ModSecurity rule IDs can be found in separate files in the following directories:
- For Comodo: /etc/<apache webserver directory>/modsecurity.d/rules/comodo_free/*.conf
- For Atomic for Linux: /var/asl/rules/modsec/50_plesk_basic_asl_rules.conf
- For Windows: /var/asl/rules/modsec/windows/50_plesk_basic_asl_rules.conf
 
Thank you. The path for me was /etc/httpd/conf/modsecurity.d/rules/comodo_free/

Get this rules any updates? Because all rules are from 2023-03-08 same time.
 
Is Comodo dead or at least that ModSecurity is no longer supported? I haven't found a way to report false-positives yet. Some of the rules, especially with URI parameters, had banned hundreds of visitors in the past, because wrong detection.
 
Back
Top