Looking for a good Mod Sec

wanah

Well-Known Member
#2
This sounds very hopefull.

cPanel asked us what we thought about them supplying a modsecurity ruleset and now I see Comodo did this before them.

http://www.melih.com/2013/12/28/free-mod_security-rules/
http://www.webhostingtalk.com/showthread.php?t=1334902

I've downloaded the full ruleset and it's only 1.6MB uncompressed for the moment.

It seems to come with a cPanel plugin (buggy from what I have read but maybe already fixed…).

It's a very new product, it seems to be currently the best hope for a good quality free ruleset.

I will be watching it very closely and I hope litespeed will test them as after testing gotroot ruleset with apache we found it to have too many false positives (they fix them quickly but you have to keep informing them of the false positives which is a pain as we discovered them on a daily basis).

This ruleset seems to be much smaller and more managable than ASL's one. I do hope it's effective (or will become effective) as well as compatible with litespeed. I would love to be able to enable modsecurity again but without slowing everything down and without loads of false positives.
 
Top