LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > mod_security & ModSecurity Core Rule Set

Reply
 
Thread Tools Display Modes
  #1  
Old 08-08-2011, 02:31 AM
anything anything is offline
Member
 
Join Date: Jun 2010
Posts: 40
Default mod_security & ModSecurity Core Rule Set

I was investigating using some of the OWASP rules for mod_security but I've found that almost none of them are useable with litespeed.
They appear to almost exclusively use SecRule TX:var style rules to create scores, and allow/deny based on the score. Which litespeed does not appear to support.
eg:
Code:
unknown server variable while parsing: TX:REAL_IP
Any plans to begin supporting the features required for at least the base rules of the "ModSecurity Core Rule Set"?

I also found that the following rule (which is part of the core rule set) causes litespeed to crash and auto-restart for every request.
Code:
SecRule REQUEST_HEADERS:User-Agent "^(.*)$" "phase:1,id:'981217',t:none,pass,nolog,t:sha1,t:hexEncode,setvar:tx.ua_hash=%{matched_var}"
I'm testing on ent4.1.3.

Also, please add some documentation to inform people that the request filter config in litespeed's control panel is for native sites only.
Reply With Quote
  #2  
Old 04-28-2012, 03:02 PM
QuantumNet QuantumNet is offline
Senior Member
 
Join Date: Nov 2007
Posts: 61
still doesnt work on the latest litespeed ... really thinking about switching to apache 2.4
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 06:32 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.