Weird one I noticed today is that none of my mod security rules are being blocked anymore? I have LF_MODSEC set to 3. Is there something else I'm missing?
For eg.
[Mon Sep 29 16:14:09.069556 2014] [:error] [pid 982245:tid 140548245526272] [client 96.47.226.20] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:\\\\sexec\\\\s+xp_cmdshell)|(?:[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98]\\\\s*?!\\\\s*?[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98\\\\w])|(?:from\\\\W+information_schema\\\\W)|(?:(?:(?:current_)?user|database|schema|connection_id)\\\\s*?\\\\([^\\\\)]*?)|(?:[\\"'`\\xc2\\xb4\\xe2 ..." at ARGS:cat. [file "/var/cpanel/cwaf/rules/cwaf_02.conf"] [line "335"] [id "211650"] [msg "COMODO WAF: Detects MSSQL code execution and information gathering attempts"] [data "Matched Data: union all select found within ARGS
[Mon Sep 29 16:14:11.747844 2014] [:error] [pid 982245:tid 140548140627712] [client 96.47.226.20] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:\\\\sexec\\\\s+xp_cmdshell)|(?:[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98]\\\\s*?!\\\\s*?[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98\\\\w])|(?:from\\\\W+information_schema\\\\W)|(?:(?:(?:current_)?user|database|schema|connection_id)\\\\s*?\\\\([^\\\\)]*?)|(?:[\\"'`\\xc2\\xb4\\xe2 ..." at ARGS:cat. [file "/var/cpanel/cwaf/rules/cwaf_02.conf"] [line "335"] [id "211650"] [msg "COMODO WAF: Detects MSSQL code execution and information gathering attempts"] [data "Matched Data: union all select found within ARGS
[Mon Sep 29 16:14:13.762123 2014] [:error] [pid 982173:tid 140548088178432] [client 96.47.226.20] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:\\\\sexec\\\\s+xp_cmdshell)|(?:[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98]\\\\s*?!\\\\s*?[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98\\\\w])|(?:from\\\\W+information_schema\\\\W)|(?:(?:(?:current_)?user|database|schema|connection_id)\\\\s*?\\\\([^\\\\)]*?)|(?:[\\"'`\\xc2\\xb4\\xe2 ..." at ARGS:cat. [file "/var/cpanel/cwaf/rules/cwaf_02.conf"] [line "335"] [id "211650"] [msg "COMODO WAF: Detects MSSQL code execution and information gathering attempts"] [data "Matched Data: union all select found within ARGS
[Mon Sep 29 16:14:16.620415 2014] [:error] [pid 982279:tid 140548193076992] [client 96.47.226.20] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:\\\\sexec\\\\s+xp_cmdshell)|(?:[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98]\\\\s*?!\\\\s*?[\\"'`\\xc2\\xb4\\xe2\\x80\\x99\\xe2\\x80\\x98\\\\w])|(?:from\\\\W+information_schema\\\\W)|(?:(?:(?:current_)?user|database|schema|connection_id)\\\\s*?\\\\([^\\\\)]*?)|(?:[\\"'`\\xc2\\xb4\\xe2 ..." at ARGS:cat. [file "/var/cpanel/cwaf/rules/cwaf_02.conf"] [line "335"] [id "211650"] [msg "COMODO WAF: Detects MSSQL code execution and information gathering attempts"] [data "Matched Data: union all select found within ARGS