mod_security rule to ignore a false positive ... assistance

Re: mod_security rule to ignore a false positive ... assistance

by Andreas Giesen -
Number of replies: 1
It would be really helpful to get to some understanding of what exceptions are needed to run Moodle with modsecurity activated. To say "this is an Apache problem" would mean to have to completely dig into how modsecurity works etc. etc. 

I saw, that there are exception-sets for several programs like Wordpress, Joomla ... already "built in" with the Modsecurity-config (in Plesk) - would it not make sense to work together and generate sth. like that for Moodle? A set of exceptions that should mostly cover the basic needs of any Moodle admin to get Moodle running without disabling modsecurity altogether?


Edit: It seems, in Plesk I can just enter IDs for exceptions.... I found these two IDs for the profile-pages and for plugin-uninstalls: 

242994
240210

Are these IDs specific for a system or will the same rule give the same ID on any system? If the latter is the case, it should be relatively easy to at least make a collection for others to find.... 
In reply to Andreas Giesen

Re: mod_security rule to ignore a false positive ... assistance

by Carlos del Río -

That two IDs worked for me.

Moodle Version 4.0.1+

Thanks!