store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 1:19 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 
Author Message
 Post subject: mod_security and ISPmanager
Unread postPosted: Mon Jul 25, 2011 10:14 pm 
Offline
Forum User
Forum User

Joined: Mon Jul 25, 2011 5:15 pm
Posts: 7
Location: Atlanta
It appears that because ISPmanager is called via '/manager/ispmgr', the entry for '<LocationMatch /manager/>' in 10_asl_rules.conf is causing some requests to fail, i.e., when trying to edit files in ISPmanager's File Manager, you get "You don't have permission to access /manager/ispmgr on this server.".

So, a) is there a way to preempt that Location entry with one that is specifically for '/manager/ispmgr' that is then ignored/permitted, and b) in this case the report of the problem was with a file editor, so is there another section we should be looking that might be interfering?

Thanks,
roho


Top
 Profile  
 
 Post subject: Re: mod_security and ISPmanager
Unread postPosted: Tue Jul 26, 2011 12:20 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
LocationMatch is used to exclude rules, or to change rules. So it sounds like you may have a false positive. Could you send us the audit payload for that event?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group