Linux and mod_security

We’ll likely be moving back to the mod_security layer again on linux servers on top of the running as CGI. Just too many people have outdated apps and refuse to update. We can’t update everyone, we cna’t force them to update, but we get the blame for all hacks that happen on their WP, Joomla, mambo, and other php sites.

Do you let clients know if one of their sites was the source of an attack? I have one client who hosts with us (but we do not maintain their site) with an old version of Joomla. They keep getting hacked and I can’t get them to update. We’ve actually given them until the end of March to move off of our servers because they are a PITA in many ways and we don’t want to deal with them anymore.