{"id":8576,"date":"2026-05-28T09:56:34","date_gmt":"2026-05-28T07:56:34","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=8576"},"modified":"2026-06-15T01:47:46","modified_gmt":"2026-06-14T23:47:46","slug":"how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/","title":{"rendered":"How to Disable a Specific ModSecurity Rule in the .htaccess File"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">ModSecurity is a web application firewall (WAF) that protects websites against common attacks such as SQL injection, cross-site scripting (XSS), and malicious requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In some cases, legitimate actions within your application may trigger false positives and cause requests to be blocked. Instead of disabling ModSecurity completely, you should disable only the problematic rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/#Before_You_Begin\" >Before You Begin<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/#Step_1_Connect_to_Your_Hosting_Account\" >Step 1: Connect to Your Hosting Account<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/#Step_2_Edit_the_htaccess_File\" >Step 2: Edit the .htaccess File<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/#Step_3_Test_Your_Website\" >Step 3: Test Your Website<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/#Avoid_Disabling_ModSecurity_Entirely\" >Avoid Disabling ModSecurity Entirely<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-a-specific-modsecurity-rule-via-the-htaccess-file\/#Need_Help\" >Need Help?<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Before_You_Begin\"><\/span>Before You Begin<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-4038094604\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Disabling security rules reduces your website&#8217;s protection. Only disable a rule if you have identified it as the source of the issue and understand the associated risks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To find the rule ID that is causing the problem, check:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your website&#8217;s error logs<\/li>\n\n\n\n<li>ModSecurity audit logs<\/li>\n\n\n\n<li>The error message returned by your hosting provider<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A typical ModSecurity error contains a rule ID similar to:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ModSecurity: Access denied with code 403 (phase 2).\nMatched phrase ...<\/code><\/pre>\n\n\n<p>[id &#8220;123456&#8221;]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this example, the rule ID is <code>123456<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_1_Connect_to_Your_Hosting_Account\"><\/span>Step 1: Connect to Your Hosting Account<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use SSH or an FTP client to connect to your hosting account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Navigate to the directory containing the <code>.htaccess<\/code> file, usually:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public_html\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">or your application&#8217;s document root.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_2_Edit_the_htaccess_File\"><\/span>Step 2: Edit the <code>.htaccess<\/code> File<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Open the <code>.htaccess<\/code> file with your preferred text editor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Add the following directive, replacing <code>123456<\/code> with the actual rule ID:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;IfModule mod_security2.c&gt;\n    SecRuleRemoveById 123456\n&lt;\/IfModule&gt;\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If your server uses LiteSpeed, you can also use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;IfModule LiteSpeed&gt;\n    SecRuleRemoveById 123456\n&lt;\/IfModule&gt;\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">To disable multiple rules, separate the IDs with spaces:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;IfModule mod_security2.c&gt;\n    SecRuleRemoveById 123456 789012 345678\n&lt;\/IfModule&gt;\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Save the file after making your changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_3_Test_Your_Website\"><\/span>Step 3: Test Your Website<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repeat the action that previously triggered the ModSecurity error.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the issue has been resolved and the website works correctly, the selected rule was responsible for the false positive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the error persists, review your logs again to identify any additional rule IDs that may need adjustment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Avoid_Disabling_ModSecurity_Entirely\"><\/span>Avoid Disabling ModSecurity Entirely<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Disabling the entire ModSecurity engine is strongly discouraged because it removes an important layer of protection from your website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Avoid using directives such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SecRuleEngine Off\nSecRequestBodyAccess Off\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">These settings disable security checks globally and can expose your application to attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Only consider disabling ModSecurity completely if instructed by your hosting provider or support team.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Need_Help\"><\/span>Need Help?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you cannot identify the problematic rule ID, contact our support team and provide:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The exact error message<\/li>\n\n\n\n<li>The date and time of the failed request<\/li>\n\n\n\n<li>The affected URL<\/li>\n\n\n\n<li>Your IP address<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This information will help administrators locate the relevant ModSecurity log entries and recommend the safest solution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[25],"manual_kb_tag":[718,1626,4586,6637,7154,7155,7156,7157,7158,7159],"class_list":["post-8576","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-hosting","manual_kb_tag-htaccess-file","manual_kb_tag-htaccess","manual_kb_tag-false-positives","manual_kb_tag-web-application-firewall","manual_kb_tag-modsecurity","manual_kb_tag-disable-modsecurity-rule","manual_kb_tag-disable-specific-rule","manual_kb_tag-remove-rule-by-id","manual_kb_tag-modsecurity-audit-logs","manual_kb_tag-modsecurity-error-logs"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":5,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8576\/revisions"}],"predecessor-version":[{"id":8577,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/8576\/revisions\/8577"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=8576"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=8576"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=8576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}