LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > Mod Security Rules 1.0x-2.5x with ASL Got Root Rules with LSWS

Reply
 
Thread Tools Display Modes
  #1  
Old 06-24-2009, 02:51 PM
grniyce grniyce is offline
Senior Member
 
Join Date: Jan 2009
Posts: 52
Lightbulb Mod Security Rules 1.0x-2.5x with ASL Got Root Rules with LSWS

I haven't seen this thread accurately described on this site yet, so I'm going to do my best to explain exactly what I did to get this to work effectively on my server with the variety of regular sites, forum sites (vB, IPB, PHPbb, etc.), including ClamAV, while using cPanel WHM. Hopefully this helps all of you.

First thing to know is that the rules are default in nature, so if you think you can just follow the easy instructions and apply all of them and everything will work perfectly ---- it won't... You need to be able to tweak the rules for your environment. Because my server environment is so flexible in regards to the types of sites I host, I have tweaked some of these rules, and they now work excellently.

Ok first make these folders in /usr/local/apache:



Now open /usr/local/apache/conf/httpd.conf and add these Include lines and do not restart httpd yet:



Now download these rules which have been optimized as I stated above to work with LSWS in multiple environments without compromising security.

Click Here To Download The Optimized Mod_Security Rules

If a moderator / admin could attach these rules it would be helpful.

Now open the .zip file and go into each folder and simply drag and drop those files to their corresponding folders in /usr/local/apache (modsecurity or modsecurity.d).

NOW RESTART HTTPD

Everything should work fine for all environments. Keep in mind there is one file in here that you should remove IF YOU DO NOT HAVE CLAMAV installed on your server. Remove the 05_asl_scanner.conf file in the modsecurity.d folder or it could trigger errors.

Regards,

Ant

Last edited by grniyce; 06-24-2009 at 02:54 PM..
Reply With Quote
  #2  
Old 02-02-2011, 10:39 PM
markb1439 markb1439 is offline
Senior Member
 
Join Date: Nov 2009
Posts: 56
Are updated rules available?
Reply With Quote
  #3  
Old 02-12-2011, 04:16 PM
mikegotroot mikegotroot is offline
New Member
 
Join Date: Feb 2011
Posts: 7
You can download up to date modsecurity rules from:

https://www.atomicorp.com/wiki/index...Security_Rules

Unfortunately, Litespeed does not currently support modsecurity 2.5.x (The latest version of modsecurity) rules, so none of the modern rulesets anyone publishes will load or work correctly with Litespeed :-(

http://www.litespeedtech.com/support...ht=modsecurity

As soon as litespeed supports the full 2.5.x ruleset, you will be able to use the same modsecurity rules Apache users enjoy. Right now, litespeed only support a subset of the features that the Apache modsecurity implementation provides.

So, if you want a WAF with Litespeed, you will either have to use older 1.9.x rules - which is not recommended, as no one publishes or maintains 1.9.x rules - as 1.9.x is neither supported nor maintained anymore and hasnt been for many years. Or hack up 2.5.x rules to ribbons, basically making them miss attacks and run much slower.

In short, the best bet is to encourage litespeed to fully support modsecurity 2.5.x. Once they can do that, then you can use the same rules that Apache users use now.

Last edited by mikegotroot; 02-12-2011 at 04:27 PM..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 08:42 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.