Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Web Server
  • Search

How to Install ModSecurity with OWASP on VestaCP

Questions regarding the Web Server
Apache + Nginx, Nginx + PHP5-FPM
Post Reply
  • Print view
Advanced search
5 posts • Page 1 of 1
shanjie
Posts: 37
Joined: Thu Jan 14, 2016 12:02 pm

How to Install ModSecurity with OWASP on VestaCP
  • Quote

Post by shanjie » Sun Jan 31, 2016 3:27 am

Any guidelines on this?
Top

tjebbeke
Collaborator
Posts: 783
Joined: Mon May 11, 2015 8:43 am
Contact:
Contact tjebbeke
Website

Os: CentOS 6x
Web: apache + nginx
Re: How to Install ModSecurity with OWASP on VestaCP
  • Quote

Post by tjebbeke » Sun Jan 31, 2016 9:47 am

You can search on Google ...
You can look at this: http://www.servermom.org/how-to-install ... erver/844/
Top

shanjie
Posts: 37
Joined: Thu Jan 14, 2016 12:02 pm

Re: How to Install ModSecurity with OWASP on VestaCP
  • Quote

Post by shanjie » Mon Feb 01, 2016 1:33 pm

If you follow exact the steps. You will end up having error on your existing website that ruining on vesta.

Mod_security is the fundamental and efficient way to prevent the current cms to get hacked and it's would be nice if its included in the current installation. Just like centos webpanel.
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: How to Install ModSecurity with OWASP on VestaCP
  • Quote

Post by skurudo » Mon Feb 01, 2016 1:49 pm

shanjie wrote:If you follow exact the steps. You will end up having error on your existing website that ruining on vesta.
I think it can be installed a different way:

Code: Select all

yum install mod_security
then

Code: Select all

nano /etc/httpd/modsecurity.d/modsecurity_crs_10_config.conf
and add

Code: Select all

SecRuleEngine On
and service restart

Code: Select all

service httpd restart
shanjie wrote:Mod_security is the fundamental and efficient way to prevent the current cms to get hacked

Well, vulnerabilities must be addressed to сms, rest are crutches and rake.. ;-(
shanjie wrote:and it's would be nice if its included in the current installation. Just like centos webpanel.
If you think so, please add this idea to http://bugs.vestacp.com/
Top

jonn
Posts: 72
Joined: Sun Jun 08, 2014 12:18 pm

Re: How to Install ModSecurity with OWASP on VestaCP
  • Quote

Post by jonn » Mon Feb 01, 2016 11:33 pm

I too will be trying my hand at installing mod security today, one my servers is being hit hard by a session fixation attack with nothing hosted on it yet, so I have a good testing ground. I am wondering though with a nginx + apache combo if installing it will it be effective seeing nginx is the front end it really should be compiled with nginx modsecurity options enabed standalone. But this is my first time attempting this, so trail and error here I think.
Top


Post Reply
  • Print view

5 posts • Page 1 of 1

Return to “Web Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password