Page 1 of 1
How to Install ModSecurity with OWASP on VestaCP
Posted: Sun Jan 31, 2016 3:27 am
by shanjie
Any guidelines on this?
Re: How to Install ModSecurity with OWASP on VestaCP
Posted: Sun Jan 31, 2016 9:47 am
by tjebbeke
Re: How to Install ModSecurity with OWASP on VestaCP
Posted: Mon Feb 01, 2016 1:33 pm
by shanjie
If you follow exact the steps. You will end up having error on your existing website that ruining on vesta.
Mod_security is the fundamental and efficient way to prevent the current cms to get hacked and it's would be nice if its included in the current installation. Just like centos webpanel.
Re: How to Install ModSecurity with OWASP on VestaCP
Posted: Mon Feb 01, 2016 1:49 pm
by skurudo
shanjie wrote:If you follow exact the steps. You will end up having error on your existing website that ruining on vesta.
I think it can be installed a different way:
then
Code: Select all
nano /etc/httpd/modsecurity.d/modsecurity_crs_10_config.conf
and add
and service restart
shanjie wrote:Mod_security is the fundamental and efficient way to prevent the current cms to get hacked
Well, vulnerabilities must be addressed to сms, rest are crutches and rake.. ;-(
shanjie wrote:and it's would be nice if its included in the current installation. Just like centos webpanel.
If you think so, please add this idea to
http://bugs.vestacp.com/
Re: How to Install ModSecurity with OWASP on VestaCP
Posted: Mon Feb 01, 2016 11:33 pm
by jonn
I too will be trying my hand at installing mod security today, one my servers is being hit hard by a session fixation attack with nothing hosted on it yet, so I have a good testing ground. I am wondering though with a nginx + apache combo if installing it will it be effective seeing nginx is the front end it really should be compiled with nginx modsecurity options enabed standalone. But this is my first time attempting this, so trail and error here I think.