Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Enable and Disable ModSecurity Rules in DirectAdmin

This guide explains ModSecurity and shows how to turn it on or off, or skip one rule that blocks your site by mistake.

DirectAdmin2 min read8 steps8 screenshots

What is ModSecurity?

ModSecurity is a security guard for your website. It sits in front of your site and checks each request. If a request looks like an attack, it blocks it. A web application firewall, or WAF, is the general name for this kind of guard.

The guard follows rules. Each rule has a number called an ID. Sometimes a rule blocks a real visitor by mistake. This is called a false alarm. You might then see a 403 Forbidden error when saving a post or uploading a file.

Warning: turning off protection makes your site easier to attack. Only turn off the single rule that causes trouble.

Find which rule blocked you

  1. Log in to DirectAdmin.
  2. Open the error log. Look under Site Summary / Statistics / Logs and click Error Log.
  3. Look for lines that mention ModSecurity.
    Screenshot: Look for lines that mention ModSecurity .
    Screenshot: Look for lines that mention ModSecurity .
  4. Find the text [id "123456"]. The number is the rule ID.

Turn off one rule for your site

  1. Open File Manager and go to public_html.
  2. Make a backup copy of .htaccess.
  3. Edit the file and add:
<IfModule mod_security2.c>
    SecRuleRemoveById 123456
</IfModule>

Replace 123456 with your own rule ID. This removes only that rule for your site. Some servers do not allow this in .htaccess. If so, ask support.

  1. Click Save and test again.
    Screenshot: Click Save and test again.

Turn ModSecurity off for a whole site

Use this only for a short test:

<IfModule mod_security2.c>
    SecRuleEngine Off
</IfModule>

This switches the guard off for that folder. Remove the lines when you finish.

For server owners

This needs root access. ModSecurity is installed with CustomBuild, the server software tool of DirectAdmin:

Screenshot: This needs root access. ModSecurity is installed with CustomBuild, the server software too
Screenshot: This needs root access. ModSecurity is installed with CustomBuild, the server software too
cd /usr/local/directadmin/custombuild
./build set modsecurity yes
./build modsecurity

The first line sets the option to yes. The second installs it. Use no in the first line to turn it off, then run the build again. Plans may add rule sets, so check what you use.

Screenshot: The first line sets the option to yes. The second installs it. Use no in the first line to
Tip: Ask Hostvento first if you are not sure. Open a ticket at the support page and include the rule ID.

Quick recap

  • ModSecurity guards your site with numbered rules.
  • Find the rule ID in the error log.
    Screenshot: Find the rule ID in the error log.
  • Disable one rule with SecRuleRemoveById in .htaccess.
    Screenshot: Disable one rule with SecRuleRemoveById in .htaccess.
  • Turn the whole guard off only for short tests.