Mod Security rules.
Submitted by felosi on Wed, 08/09/2006 - 03:03.
I recently went over some of the mod security rules from gotroot. Lots were pretty useful but I notice most of them were for stuff no one even uses and some just gave false positives on everything. After extensive testing and checking my audit logs regularly I finally come up with a real good set of apache 2 rules. Although I say lots of the phpbb stuff is useless as its for older versions, its probably still good to have seeing as most of the exploits are similar. Here are the rules, rename them to rulez.conf when you wget them to your rules directory.
http://evolution-security.com/rulez
»
- felosi's blog
- Login or register to post comments
- 1905 reads


Recent comments
2 hours 38 min ago
2 hours 53 min ago
3 hours 31 min ago
13 hours 13 min ago
1 day 2 hours ago
1 day 3 hours ago
1 day 16 hours ago
1 day 16 hours ago