ModSecurity blocking queries in phpMyAdmin

AhmetBas

Verified User
Joined
Oct 28, 2020
Messages
48
Hi,

If we enable Modsecurity:
Code:
cd /usr/local/directadmin/custombuild
./build update
./build set modsecurity yes
./build set modsecurity_ruleset "comodo"
./build modsecurity
./build modsecurity_rules
./build rewrite_confs

If we open phpMyAdmin we are seeing this warning:

Screenshot 2021-12-06 at 11.24.23.png


and want to execute queries through phpMyAdmin, we are seeing that our queries are being blocked by the Modsecurity rules.

[Wed Dec 01 22:02:14.616495 2021] [:error] [pid 1220500:tid 140472020371200] [client :61424] [client ] ModSecurity: Access denied with code 403 (phase 2). Found 1 byte(s) in ARGS:sql_query outside range: 1-255. [file "/usr/local/cwaf/rules/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||server.example.com|F|3"] [data "ARGS:sql_query=DELETE FROM `example` WHERE `value` LIKE '\\x000168%'"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "server.example.com"] [uri "/phpMyAdmin/index.php"] [unique_id "Yafi1l4AJaCgpaVIoTz_QwABjiw"]

How can we prevent this?
 
Back
Top