Due to the recent issue with insecure PHP mail forms being flooded with mail injections (http://forums.dathorn.com/showthread.php?t=1986) we've gone ahead and have installed mod_security on cpanel04, cpanel05, and cpanel08. Right now it is simply setup to filter out basic mail injections and nothing more. If you notice any problems please submit a trouble ticket to let us know.
If no real problems arise, mod_security will be installed on the remaining servers as well. At some point we will also begin adding more rules to prevent other common PHP script exploits.
Up to this point I've been fairly reluctant in running mod_security but now there aren't many other options remaining and I do realize that this is probably long overdue. If this works out, it will be of great assistance to us all.
If no real problems arise, mod_security will be installed on the remaining servers as well. At some point we will also begin adding more rules to prevent other common PHP script exploits.
Up to this point I've been fairly reluctant in running mod_security but now there aren't many other options remaining and I do realize that this is probably long overdue. If this works out, it will be of great assistance to us all.
Comment