LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-20-2009, 10:44 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Rep: Reputation: 30
mod_security - exclude one file from checking


Hi there,
I would like to know if there is a possibility to exclude rules per files basis.
What I mean is that I have some php files that trigger alerts and I can't modify those files, I don't want to comment mod sec rules for the whole server, only for whose files.
Any way those files are special and are not available to the public.

Thanks
 
Old 05-22-2009, 04:12 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The preferred way to have mod_security cover your server is by running it on everything except some exceptions, not on "just a few files". Make certain your motivation for doing that is based not on arbitrary reasons like logging, annoyances et cetera. Excluding a file can be done either by removing a rule (SecRuleRemove) or a location match container.

What I'm interested in is the state of your server. Up to now you've posted quite a lot of questions with a security component, culminating in http://www.linuxquestions.org/questi...-pages-725844/, quite a few of which you've never gotten back to to respond properly. I acknowledge it is your right to stubbornly seek your own way doing things your way, but in the grand scheme of things I'd rather see you provide closure regarding important issues. If that doesn't work for you then try to see it simply as reciprosity.
 
Old 05-22-2009, 08:37 AM   #3
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
Thank you unSpawn !
You are right, I'll try to motivate and respond back every time when I post something. This forum represents very much for me because I learned a lot from here.
And yes, I am very interested in Security.

About mod_security, we have an e-learning System (made in-house) and there is an exam about bash scripts and users have to post some scripts in a web page (html <textarea>).
Of course modsec blocks something like this, this is normal.
But, all the users are not strange persons, we know them (we know their address, personal data etc) and I think the possibility that someone attacks the server is very low. Of course there could be worms or something on their machine.
We cant change thinks right away because the system in in production with hundreds or maybe thousands of users and the programming team said it needs months to change that thing.

I think there is no other way but to exclude that file.

Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
--exclude-from=FILE excluding patterns complications cucolin@ Linux - Server 7 04-06-2007 12:35 PM
How exclude | from txt.file using awk or sed? sarajevo Programming 2 08-21-2006 07:26 AM
TAR: Unpack file, exclude a folder Smeerbalg Linux - Software 1 01-29-2006 07:59 AM
tar --exclude-from=FILE GATTACA Programming 1 07-29-2005 12:25 PM
removing a file (--exclude is the name of the file) Santinelli Linux - General 2 01-14-2004 09:03 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration