• Resolved honeybaobao

    (@honeybaobao)


    Hi everyone,

    I have a dedicated Server by OVH Kimsufi, with Plesk and debian 9, the server and plesk looks fine. But the website is unstable.

    I mean, I access, and I work on the theme or install the plugin and then crash, wait a few hours or minutes and then fine again.

    I use the theme 7, I have elementor pro, Jetpack, Akismet, contact form7, Woocommerce, W3 Total cache, Really simple SSL and more plugin.

    I guess it’s not hardware, because if I connect on plesk during the time the Site is crashed there is not problem.

    Could be website problem ? Database Problem ? Both of them ? or Plesk and WordPress it’s not the right Cocktail ?

    I did Manually setup for WordPress

    The server is very strong configuration so not hardware problem

    Thanks for your help

Viewing 6 replies - 1 through 6 (of 6 total)
  • Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    When you say it crashes, what do you mean? Are there error messages?

    Thread Starter honeybaobao

    (@honeybaobao)

    Hi Sterndata,

    I mean in fact can not load the website, can not access, and unfortunately no error number or type

    This problem is really annoying, because it’s since a long time and I tought it was always plugin or oder matter but I find out it’s not that

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    Check your server logs. Otherwise, we have no data on which to base any decisions. Is your MySQL server crashing? Check the apache/nginx/php logs, /var/log/messages (or whatever debian uses), and any other log files you can locate.

    Thread Starter honeybaobao

    (@honeybaobao)

    I found this log come very often on the server

    [client 192.0.101.226] ModSecurity: Warning. Match of "pm AppleWebKit Android" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/apache2/modsecurity.d/rules/owasp_modsecurity_crs_3-plesk/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1268"] [id "920300"] [rev "3"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "www.cedricstrainsim.com"] [uri "/"] [unique_id "XwMAEX8AAQEAAFrWzNMAAABV"]

    This one too `Error
    139.59.43.75
    403
    POST /wp-login.php HTTP/1.0`

    [client 79.142.76.206] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .resources/ .resx/ .sql/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/apache2/modsecurity.d/rules/owasp_modsecurity_crs_3-plesk/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1075"] [id "920440"] [rev "2"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "cedricstrainsim.com"] [uri "/db_dump.sql"] [unique_id "XwLy-H8AAQEAAFrWzLsAAABR"]

    [client 79.142.76.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/modsecurity.d/rules/owasp_modsecurity_crs_3-plesk/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "57"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cedricstrainsim.com"] [uri "/db_dump.sql"] [unique_id "XwLy-H8AAQEAAFrWzLsAAABR"]

    This is these type of error come often in the Log in the morning when I was working on the Website but the first log come often even now on this time

    But I saw sometimes come out the 403 errors too

    Moderator Steven Stern (sterndata)

    (@sterndata)

    Volunteer Forum Moderator

    Mod_security is a bear to get working correctly with WordPress. You might want to disable that apache module and see if the problem goes away. If so, then either leave it off or do a lot of googling on “mod_secure wordpress rules”.

    Thread Starter honeybaobao

    (@honeybaobao)

    Looks fine and the logs now only show Statut 200 so I guess it’s resolved

    Thanks a lot for your precious time and help Sterndata

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Website unstable on Dedicated Server Kimsufi’ is closed to new replies.