LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-16-2012, 08:03 AM   #1
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Rep: Reputation: 22
Need some help with mod_security


I have a CentOS 6.2 server with a website on it. I just installed mod_security. It seems to work OK (well the site does!), but I'm getting some strange error messages in my logs : -

ModSecurity: Failed to access DBM file "/etc/httpd/logs//global":

ModSecurity: Failed to access DBM file "/etc/httpd/logs//ip": Permission denied

I'm by no means a Linux 'expert', I can find my way around, but I have NO idea what a // means in a path, or why I'm getting these messages.

Can someone please advise me (in simple language) how to fix this?
 
Old 01-16-2012, 08:22 AM   #2
ranelson
LQ Newbie
 
Registered: Jan 2005
Posts: 8

Rep: Reputation: 0
//

hello,

// = /

you normally see this when a script is missing a variable for a path.

x/y/$z/test where $z=''

ModSecurity is trying to access two DBM files in /etc/httpd/logs/

They are ether missing or the file and or directory permissions are wrong
 
Old 01-16-2012, 08:28 AM   #3
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Original Poster
Rep: Reputation: 22
Well neither file exists. or are they folders? What should the permissions be if I create them or is there some other way to create them? Mod_security is a part of the CentOS repositories, because I installed it with yum. Why didn't it create all the folders / files it should have done - bug perhaps?
 
Old 01-17-2012, 04:05 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by baldur2630 View Post
Why didn't it create all the folders / files it should have done - bug perhaps?
Apparently an ongoing issue, see https://bugzilla.redhat.com/show_bug.cgi?id=569360.



As for
Quote:
damned script kiddies. They are just hammering this server, 24 x 7 and taking up most of my bandwidth.
(I mean https://www.centos.org/modules/newbb...35325&forum=59)
Hammering maybe but as long as the server returns ^3xx or ^4xx return codes that's OK: they're going nowhere with their incessant scanning.
OTOH it's highly doubtful they exhaust your bandwidth (do some accounting and show?) but you could (temporarily) rate-limit traffic, see here and there.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mod_security pradeep.goodTUX Linux - Security 1 12-17-2009 02:31 AM
mod_security kingtas Linux - Security 4 01-20-2008 04:53 PM
mod_security shafey Linux - Security 2 12-22-2007 08:33 AM
mod_security problem bytez Linux - Security 2 10-01-2006 08:09 PM
mod_security ridertech Linux - Security 1 09-01-2004 05:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration