ModSecurity is a web application firewall (WAF) that protects websites against common attacks such as SQL injection, cross-site scripting (XSS), and malicious requests.
In some cases, legitimate actions within your application may trigger false positives and cause requests to be blocked. Instead of disabling ModSecurity completely, you should disable only the problematic rule.
Table of Contents
Before You Begin
Disabling security rules reduces your website’s protection. Only disable a rule if you have identified it as the source of the issue and understand the associated risks.
To find the rule ID that is causing the problem, check:
- Your website’s error logs
- ModSecurity audit logs
- The error message returned by your hosting provider
A typical ModSecurity error contains a rule ID similar to:
ModSecurity: Access denied with code 403 (phase 2).
Matched phrase ... [id “123456”]
In this example, the rule ID is 123456.
Step 1: Connect to Your Hosting Account
Use SSH or an FTP client to connect to your hosting account.
Navigate to the directory containing the .htaccess file, usually:
public_html/
or your application’s document root.
Step 2: Edit the .htaccess File
Open the .htaccess file with your preferred text editor.
Add the following directive, replacing 123456 with the actual rule ID:
<IfModule mod_security2.c>
SecRuleRemoveById 123456
</IfModule>
If your server uses LiteSpeed, you can also use:
<IfModule LiteSpeed>
SecRuleRemoveById 123456
</IfModule>
To disable multiple rules, separate the IDs with spaces:
<IfModule mod_security2.c>
SecRuleRemoveById 123456 789012 345678
</IfModule>
Save the file after making your changes.
Step 3: Test Your Website
Repeat the action that previously triggered the ModSecurity error.
If the issue has been resolved and the website works correctly, the selected rule was responsible for the false positive.
If the error persists, review your logs again to identify any additional rule IDs that may need adjustment.
Avoid Disabling ModSecurity Entirely
Disabling the entire ModSecurity engine is strongly discouraged because it removes an important layer of protection from your website.
Avoid using directives such as:
SecRuleEngine Off
SecRequestBodyAccess Off
These settings disable security checks globally and can expose your application to attacks.
Only consider disabling ModSecurity completely if instructed by your hosting provider or support team.
Need Help?
If you cannot identify the problematic rule ID, contact our support team and provide:
- The exact error message
- The date and time of the failed request
- The affected URL
- Your IP address
This information will help administrators locate the relevant ModSecurity log entries and recommend the safest solution.