Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8018305
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 4, 20262026-06-04T21:06:03+00:00 2026-06-04T21:06:03+00:00

I installed mod_security with an apache server, and now it’s blocking only ie7/8/9 browser.

  • 0

I installed mod_security with an apache server, and now it’s blocking only ie7/8/9 browser. (I can browse the web with firefox/chromium/etc)

The logs say:

Message: String match within "Proxy-Connection Lock-Token Content-Range Translate via if" at REQUEST_HEADERS_NAMES:Connection. [file "/etc/apache2/mod_security/modsecurity_crs_30_http_policy.conf"] [line "99"] [id "960038"] [msg "HTTP header is restricted by policy"] [data "Connection"] [severity "WARNING"] [tag "POLICY/HEADER_RESTRICTED"] [tag "POLICY/FILES_NOT_ALLOWED"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/12.1"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/12.1"]
Message: Access denied with code 403 (phase 2). [file "/etc/apache2/mod_security/modsecurity_crs_49_enforcement.conf"] [line "25"] [msg "Anomaly Score Exceeded (score 20): Common SPAM/Email Harvester crawler"]
Action: Intercepted (phase 2)
Stopwatch: 1337888078594451 2694 (918 2353 -)
Producer: ModSecurity for Apache/2.5.12 (http://www.modsecurity.org/); core ruleset/2.0.6.
Server: Apache

And the rule id “960038” is:

SecRule REQUEST_HEADERS_NAMES "@within %{tx.restricted_headers}""phase:2,t:none,pass,nolog,auditlog,msg:'HTTP header is restricted by policy',id:'960038',tag:'POLICY/HEADER_RESTRICTED',tag:'POLICY/FILES_NOT_ALLOWED',tag:'WASCTC/WASC-21',tag:'OWASP_TOP_10/A7',tag:'PCI/12.1',tag:'WASCTC/WASC-15',tag:'OWASP_TOP_10/A7',tag:'PCI/12.1',severity:'4',logdata:'%{matched_var}',setvar:'tx.msg=%{rule.msg}',setvar:tx.anomaly_score=+%{tx.warning_anomaly_score},setvar:tx.policy_score=+%{tx.warning_anomaly_score},setvar:tx.%{rule.id}-POLICY/HEADERS_RESTRICTED-%{matched_var_name}=%{matched_var}"

I have one main question and two other derived from the first:

  • How do I know what this rule makes?
    • Is it safe to ignore this rule?
    • Is there any way to modify the rule in order to allow ie to navigate the web?
  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-04T21:06:05+00:00Added an answer on June 4, 2026 at 9:06 pm
    1. Answering Your First Question Mod-Security provide us a very
      detailed documentation about the syntax of its Rule Language and
      following is the link to its documentation. ModSecurity Rule Language

    2. TX is for user defined variable tx.restricted_headers it defines
      your HTTP policy like

      SecAction “phase:1,t:none,nolog,pass,setvar:’tx.restricted_headers=/Proxy-Connection/ /Lock-Token/ /Content-Range/ /Translate/ /via/ /if/'”
      for more detailed information refer this HTTP Policy

    3. The Rule you have mentioned above is not blocking but it is
      incrementing a numerial value maintained against suspicious header
      name as mentioned in the HTTP policy i explained above.

    4. The Rule that is blocking IE as seen from the logs mentioned

      Message: Access denied with code 403 (phase 2). [file “/etc/apache2/mod_security/modsecurity_crs_49_enforcement.conf”] [line “25”] [msg “Anomaly Score Exceeded (score 20): Common SPAM/Email Harvester crawler”]

    You can modify the anomaly score threshold or can change your HTTP policy.The Rule you have mentioned is correct and don’t need to be commented.I hope you get my point

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

i read mod_rewrite module installed in my Apache server! to implement clean url. My
I am currently hosting 2 web applications on the same Apache server. Let's just
I have an Apache HTTP server with mod_h264_streaming module installed. It works fine for
Just installed and configured mod_python 3.2.8 on a CentOS 5 (Apache 2.2.3) server with
I have an Apache 2 installation on Debian with mod_ssl installed. The server private
The company I work for has recently installed a Apache staging server which uses
I have mod_python installed on my server, but if I want to acceses a
I installed in the past numexpr successfully on many machine. But now I just
I installed my rails-app via Passenger on my apache but I'm getting a strange
I'm trying to get mod_mono built and installed so I can start learning and

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.