LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-25-2013, 05:20 AM   #1
Nisha M
LQ Newbie
 
Registered: Dec 2013
Posts: 2

Rep: Reputation: Disabled
Mod security core rule set


Hi

I have installed modsecurity 2.7.5 on apache 2.4 to provide security for my application, I want to know to activate core rule set of mod security(like SQL injection etc) do I need to download separatly it from somewhere like I found in below link:
http://spiderlabs.github.io/owasp-modsecurity-crs/
Or all core rules are there in mod security itself, I need to just activate them in modsecurity.conf file?

Waiting for response this is urgent for me.
 
Old 12-26-2013, 12:09 PM   #2
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Rep: Reputation: 127Reputation: 127
AFAIK the core ruleset is not provided wih modsec, you need to download them manually.
To use them, check the base directory for crs, the rules are dividev in sections. Activate the ones you want by including the directories in your modsec-conf file.
Can't give more exact info now a I'm on vacation and can't reach my modsec-secured webservers.
 
3 members found this post helpful.
Old 12-26-2013, 07:00 PM   #3
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
I suppose it depends on how your distro has packaged it. But my experience (on both EL and Debian) has been that you download the OWASP core rule set (CRS) separately, as mentioned.
 
Old 12-27-2013, 04:27 AM   #4
Nisha M
LQ Newbie
 
Registered: Dec 2013
Posts: 2

Original Poster
Rep: Reputation: Disabled
Pingu/Anomie

Thanks for reply. I got it, we need to download CRS separately,I got the link for this also but its for Linux I am looking for Windows, if you can provide any link for the same. And I want to know step by step, how to configure CRS in modsecurity.conf file. Actually I am new for modsecurity, googled a lot but not getting relevant info.

I am waiting for your reply after vacation.
 
Old 12-29-2013, 09:38 PM   #5
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Configuration is site/application specific and non-trivial. Once configured, a trial and error period may be required to evaluate your applications' behaviors with mod_security filtering requests. (I had to tweak a lot of rules for one particularly quirky BI application.)

I recommend reading "ModSecurity Handbook":

http://www.modsecurity.org/documentation/
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mod Rewrite rule error redirecting to tomcat page jsaravana87 Linux - Server 1 11-16-2011 12:55 AM
[SOLVED] mod_security and PCI-DSS compliance with Breach Security's Enhanced Rule Set rsciw Linux - Security 2 07-21-2010 04:18 AM
Mod Rewrite Rule help needed! bagfull Fedora 1 02-19-2010 11:55 PM
Mod Security linux-qa Linux - Security 2 12-06-2008 04:23 PM
Exception in mod-rewrite rule Boby Programming 0 01-17-2006 07:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration