Hai perfettamente ragione mi sono dimenticato un 8 finale, in ogni caso se posso aiutarvi mettendovi copia dei log in modo da capire meglio il perchè sia nato questo problema basta chiedere e lo faccio volentieri.
[Tue May 22 09:48:26.059485 2018] [:error] [pid 72930:tid 140133978240768] [client 110.83.60.34:54963] [client 110.83.60.34] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwPLSt0L-3faEVTVV9DFWAAAAN8"]
[Tue May 22 09:48:27.344856 2018] [:error] [pid 72930:tid 140134137702144] [client 110.83.60.34:55022] [client 110.83.60.34] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwPLS90L-3faEVTVV9DFagAAAMw"]
[Tue May 22 09:48:28.563408 2018] [:error] [pid 72932:tid 140133919491840] [client 110.83.60.34:55071] [client 110.83.60.34] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwPLTK7wmSgGLFXOh7W1YgAAAmY"]
[Tue May 22 09:48:29.808749 2018] [:error] [pid 72930:tid 140133751637760] [client 110.83.60.34:55119] [client 110.83.60.34] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwPLTd0L-3faEVTVV9DFjQAAAPo"]
[Tue May 22 12:09:41.239121 2018] [fcgid:warn] [pid 104240:tid 140134062167808] (32)Broken pipe: [client 66.249.66.66:60021] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function
[Tue May 22 14:11:39.086070 2018] [fcgid:warn] [pid 134824:tid 140134303377152] (32)Broken pipe: [client 66.249.66.64:55153] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function
[Tue May 22 14:47:18.027996 2018] [fcgid:warn] [pid 134824:tid 140133801993984] (32)Broken pipe: [client 66.249.66.66:44766] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function
[Tue May 22 15:28:11.294806 2018] [fcgid:warn] [pid 169387:tid 140133885921024] (32)Broken pipe: [client 66.249.66.64:56344] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function
[Fri May 25 13:04:13.806505 2018] [fcgid:warn] [pid 145980:tid 140134104131328] (104)Connection reset by peer: [client 157.55.39.137:16067] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function
[Sat May 26 16:34:23.080831 2018] [fcgid:warn] [pid 152250:tid 140134179665664] (104)Connection reset by peer: [client 40.77.167.35:12791] mod_fcgid: ap_pass_brigade failed in handle_request_ipc function
[Mon May 28 11:40:52.170918 2018] [:error] [pid 123699:tid 140133869135616] [client 61.154.29.152:50083] [client 61.154.29.152] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwvOpEb9ugluHi8wNRpzSAAAASw"]
[Mon May 28 11:40:53.133448 2018] [:error] [pid 123321:tid 140134011811584] [client 61.154.29.152:50129] [client 61.154.29.152] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwvOpaCXi748953Y9oG4mAAAAFs"]
[Mon May 28 11:40:53.833526 2018] [:error] [pid 123321:tid 140134053775104] [client 61.154.29.152:50158] [client 61.154.29.152] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwvOpaCXi748953Y9oG4mwAAAFY"]
[Mon May 28 11:40:54.522329 2018] [:error] [pid 123321:tid 140133986633472] [client 61.154.29.152:50178] [client 61.154.29.152] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:JDatabaseDriverMysqli|[oOcC]\\\\:\\\\d+\\\\:.+?\\\\:\\\\d+\\\\:\\\\{.*\\\\})" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_Joomla.conf"] [line "47"] [id "222390"] [rev "5"] [msg "COMODO WAF: PHP Injection Attack: Serialized Object Injection in the Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 (CVE-2015-8562)||afinformatica.it|F|2"] [data "Matched Data: O:21:\\x22JDatabaseDriverMysqli\\x22:3:{s:2:\\x22fc\\x22;O:17:\\x22JSimplepieFactory\\x22:0:{}s:21:\\x22\\x5c0\\x5c0\\x5c0disconnectHandlers\\x22;a:1:{i:0;a:2:{i:0;O:9:\\x22SimplePie\\x22:5:{s:8:\\x22sanitize\\x22;O:20:\\x22JDatabaseDriverMysql\\x22:0:{}s:8:\\x22feed_url\\x22;s:119:\\x22eval(chr(112).chr(104).chr(112).chr(105).chr(110).chr(102).chr(111).chr(40).chr(41).chr(59));JFactory::getConfig();exit\\x22;s:19:\\x22cache_name_function\\x22;s:6:\\x22assert\\x22;s:5:\\x22cache\\x22;b:1;s:11:\\x22cache_class\\x22;O:20..."] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afinformatica.it"] [uri "/"] [unique_id "WwvOpqCXi748953Y9oG4nwAAAF4"]
[Tue May 29 18:31:41.544571 2018] [fcgid:warn] [pid 91258:tid 140133751637760] (104)Connection reset by peer: [client 79.36.50.107:58955] mod_fcgid: error reading data from FastCGI server
[Tue May 29 18:31:41.544631 2018] [core:error] [pid 91258:tid 140133751637760] [client 79.36.50.107:58955] End of script output before headers: index.php
[Tue May 29 18:57:37.449924 2018] [fcgid:warn] [pid 91254:tid 140133793601280] (104)Connection reset by peer: [client 79.36.50.107:59005] mod_fcgid: error reading data from FastCGI server
[Tue May 29 18:57:37.449985 2018] [core:error] [pid 91254:tid 140133793601280] [client 79.36.50.107:59005] End of script output before headers: index.php
[Tue May 29 18:59:32.974177 2018] [fcgid:warn] [pid 91251:tid 140134303377152] (104)Connection reset by peer: [client 79.36.50.107:59061] mod_fcgid: error reading data from FastCGI server
[Tue May 29 18:59:32.974221 2018] [core:error] [pid 91251:tid 140134303377152] [client 79.36.50.107:59061] End of script output before headers: index.php