How To Disable Mod Security

Have you ever tried to make a post in WordPress, Xenforo, or some other content management system only to get a 500 internal server error?

 

I was chatting on Skype yesterday with one of my friends (and Name Hero customers) who was having this issue over and over.

 

First off, I can relate as I’ve experienced this for nearly a decade now, and always wanted to pull my hair out troubleshooting the issue.

 

You need to disable Mod Security

 

After spending HOURS troubleshooting this many years ago, I discovered it was Mod Security blocking it.

 

More specifically, some word processing programs such as Microsoft Word insert ambiguous characters into your text which when pasted into WordPress (or similar) can create the error as Mod Security considers it a threat.

 

You can do this by logging into cPanel, searching for, and then clicking on ModSecurity:

 

 

You can then disable it for the domain in question or for your entire cPanel account:

 

 

If you administer your server (i.e. on a VPS) you can login to Web Host Manager -> ModSecurity Tools and you can disable the one rule causing the issue (if you don’t want to disable Mod Security all together).

 

This works as well, but sometimes you’ll find there are multiple rules creating the issue. In a lot of cases it’s just as easy to disable it all together.

 

If you must do that, it's best to contact support, have us look though some logs for your IP address and see exactly which rule is causing the issue. The short fix is just turning off mod_security. But mod_security is GREAT for protecting your website. So contact us and we can examine logs to determine which rule needs to be whitelisted. That way you can still enjoy 'behind the scenes' protection.

 

How to keep your website secure

 

Mod Security acts as a web application firewall blocking your site from many hacking / exploit attempts. If you decide to disable it you need to make SURE you regularly change your passwords (using strong ones) as well as keep your software updated.

 

This means regularly updating WordPress (when updates are available) as well as all your plugins, themes, etc. Running older versions of software is the number one reason websites get hacked. Also using insecure passwords without strong characters!

 

If you have any questions or issues with this, feel free to reach out and our team can ensure your website is secured!

  • 0 Korisnici koji smatraju članak korisnim
Je li Vam ovaj odgovor pomogao?

Vezani članci

How To Add An Addon Domain In cPanel

Setting Up Addon Domains in cPanel The quick and short answer is:   Log into cPanel on the...

How To Fix The "Your IP Address Has Changed" Error In cPanel

If you've ever tried to log into cPanel and gotten the "Your IP address has changed" error it can...

How To Forward A Domain To Another Domain

One thing we encourage here at alttrixcloud is that you register multiple TLDs for your brand....

How To Setup 301 Redirects In cPanel

The HTTP response status code 301 Moved Permanently is used for permanent URL redirection,...

How To Correctly 301 Redirect Your Domain

Ever decide to pickup and move your website to a new domain?   What about buying a similar...