Mod_security and scan of port 443

Operating System & Version
CentOS v7.9.2009
cPanel & WHM Version
cPanel & WHM v102.0.26

cPRex

Jurassic Moderator
Staff member
Oct 19, 2014
15,285
2,434
363
cPanel Access Level
Root Administrator
Hey there! Even though the files may not exist on your server, someone can still make a request for them that ModSecurity will block. For example, I could visit https://cpanel.net/totally-random-url.jpg and get a 404 error, but if I try and make an odd request it's possible our security tools would detect that. I believe that is what is happening in this case since the requester is trying various common hidden directory names to see if they can access anything on your site.
 

khnaz35

Member
Jan 27, 2023
11
0
1
Malaysia
cPanel Access Level
Root Administrator
Thanks for the reply how do i get rid of this requester (show him/her middle finger) ? Because no matter what they are still eating up my system memory/bandwidth and when it comes to real user they are facing time out on the server.
 

khnaz35

Member
Jan 27, 2023
11
0
1
Malaysia
cPanel Access Level
Root Administrator
Currently i am seeing about 2000 hits under ModSecurity™ Tools »Hits List , so i don't think so its possible to block them one by one.
Is there anyway i can download this list and block them ? or what is the best way to get rid of these ips
 
Last edited by a moderator:

ejsolutions

Well-Known Member
Jan 6, 2013
86
36
68
cPanel Access Level
Root Administrator
I'll regurgitate my default setting for CSF, hopefully for the benefit of others..
csf --profile apply protection_high
csf --profile apply disable_alerts
<-- stops your server spamming your default email with every single alert.
.. manually change a select few alerts, such as console access ..
csf -r