Difference between revisions of "Mod security"

From Atomicorp Wiki
Jump to: navigation, search
m (Disable Mod_security rules on a specific application, for a list of IPs)
(Disable Mod_security rules on a specific application, for a list of IPs)
Line 69: Line 69:
 
Step 3) Add IP to /etc/asl/whitelist
 
Step 3) Add IP to /etc/asl/whitelist
 
   echo "10.11.12.13" >> /etc/asl/whitelist
 
   echo "10.11.12.13" >> /etc/asl/whitelist
 +
 +
Or:
 +
 +
If you want to create a special whitelist for just that application:
 +
 +
Step 1) edit the vhost/vhost_ssl.conf for the domain
 +
  vim /var/www/vhosts/<DOMAINNAME>/conf/vhost.conf
 +
 +
Step 2) Add the LocationMatch for the rule to exclude.
 +
  <LocationMatch /foo/bar.php>
 +
        SecRule REMOTE_ADDR "@pmFromFile /path/to/your/custom/whitelist_for_this_application" "nolog,phase:1,allow"
 +
  </LocationMatch>
 +
 +
Step 3) Create your custom whitelist and add IP to /etc/asl/whitelist
 +
  echo "10.11.12.13" >> /path/to/your/custom/whitelist_for_this_application
 +
 +
Keep in mind these custom lists are *not* managed by ASL, so if you want to add IPs to these lists you will need to do it from the command line.

Revision as of 10:29, 1 September 2009

Contents

Disabling Mod_Security Globally

Step 1) Disable config file

 mv /etc/httpd/conf.d/00_mod_security.conf /etc/httpd/conf.d/00_mod_security.conf.disabled

Step 2) Restart Apache

 /etc/init.d/httpd restart


Disabling Mod_security per domain

Step 1) edit the vhost/vhost_ssl.conf for the domain

 vim /var/www/vhosts/<DOMAINNAME>/conf/vhost.conf

Step 2) Add the following

 SecRuleEngine Off

Step 3) Add vhost.conf to domain config

 /usr/local/psa/admin/bin/websrvmng -a

Step 4) Restart Apache

 /etc/init.d/httpd restart


Disable Mod_security on a global URL

Step 1) Create a global exclude file

 vim /etc/httpd/modsecurity.d/00_asl_custom_exclude.conf

Step 2) Add the LocationMatch for the url to exclude. Example: /server.php

 <LocationMatch /server.php>
     SecRuleEngine Off
 </LocationMatch>

Step 3) Restart apache

 /etc/init.d/httpd restart


Disable Mod_security rule for all applications in a single domain

Step 1) edit the vhost/vhost_ssl.conf for the domain

 vim /var/www/vhosts/<DOMAINNAME>/conf/vhost.conf

Step 2) Add the LocationMatch for the rule to exclude. Example, ruleid 950005

 <LocationMatch .*>
       SecRuleRemoveById 950005
 </LocationMatch>


Disable Mod_security rule for all domains

Step 1) Use ASL utility to disable rule by ID. Example: 950005

 asl --disable-signature 950005

Disable Mod_security rules on a specific application, for a list of IPs

Step 1) edit the vhost/vhost_ssl.conf for the domain

 vim /var/www/vhosts/<DOMAINNAME>/conf/vhost.conf

Step 2) Add the LocationMatch for the rule to exclude.

 <LocationMatch /foo/bar.php>
       SecRule REMOTE_ADDR "@pmFromFile /etc/asl/whitelist" "nolog,phase:1,allow"
 </LocationMatch>

Step 3) Add IP to /etc/asl/whitelist

 echo "10.11.12.13" >> /etc/asl/whitelist

Or:

If you want to create a special whitelist for just that application:

Step 1) edit the vhost/vhost_ssl.conf for the domain

 vim /var/www/vhosts/<DOMAINNAME>/conf/vhost.conf

Step 2) Add the LocationMatch for the rule to exclude.

 <LocationMatch /foo/bar.php>
       SecRule REMOTE_ADDR "@pmFromFile /path/to/your/custom/whitelist_for_this_application" "nolog,phase:1,allow"
 </LocationMatch>

Step 3) Create your custom whitelist and add IP to /etc/asl/whitelist

 echo "10.11.12.13" >> /path/to/your/custom/whitelist_for_this_application

Keep in mind these custom lists are *not* managed by ASL, so if you want to add IPs to these lists you will need to do it from the command line.

Personal tools