mod_security Whats your config?

I'm having a hard time with mod_security, I installed it on a web server and cant configure it right.

I have the following set.

Code:
<IfModule mod_security.c>
SecFilterEngine On
SecFilterCheckURLEncoding On
SecFilterForceByteRange 0 255
SecAuditEngine RelevantOnly
SecAuditLog /var/log/httpd/audit_log
SecFilterScanPOST On
SecFilterDefaultAction "deny,log,status:406"

SecFilter /boot
# SecFilter /bin
SecFilter /dev
#SecFilter /etc
SecFilter /initrd
SecFilter /lib
SecFilter /lost+found
SecFilter /misc
SecFilter /mnt
SecFilter /proc
SecFilter /root
SecFilter /sbin
SecFilter /scripts
SecFilter /tmp
# SecFilter /usr
SecFilter /usr/local/apache
#SecFilter /usr/local/cpanel
SecFilter /usr/local/mysql
SecFilter /var

SecFilter /bin/cc
SecFilter /bin/gcc

SecFilter "\.\./"
SecFilter "<[[:space:]]*script"
#SecFilter "<(.|\n)+>"
SecFilter "delete[[:space:]]+from"
SecFilter "insert[[:space:]]+into"
SecFilter "select.+from"

#SecFilterSelective "HTTP_USER_AGENT|HTTP_HOST" "^$"

</IfModule>
Forums/Webmail few others break, has any have a solid config to share?

When i turn it off everything works fine.

Thank you.

 

 

 

 

Top