Ubuntu 12.04 Precise LTS: Install ModSecurity for Apache 2 web server

简介: Install ModSecurity:   sudo apt-get install libxml2 libxml2-dev libxml2-utils libaprut...
Install ModSecurity:   
sudo apt-get install libxml2 libxml2-dev libxml2-utils libaprutil1 libaprutil1-dev libapache-mod-security
If your Ubuntu is 64bit, you need to fix a bug:   
sudo ln -s /usr/lib/x86_64-linux-gnu/libxml2 .so.2 /usr/lib/libxml2 .so.2
Configure ModSecurity:   
sudo mv /etc/modsecurity/modsecurity .conf-recommended /etc/modsecurity/modsecurity .conf; sudo vi /etc/modsecurity/modsecurity .conf
Enable the rule engine:   
SecRuleEngine On
Increase the request body size limit to 10Mb(Optional, only if your site accepts uploads):   
SecRequestBodyLimit 10000000
SecRequestBodyInMemoryLimit 10000000
Check the ModSecurity version:   
dpkg -s libapache-mod-security | grep Version
The installed ModSecurity version is:   
Version: 2.6.3-1ubuntu0.2
Install OWASP ModSecurity Core Rule Set:   
  1. Download the rule set(version 2.2.5 because the latest version requires ModSecurity 2.7.0+):       
    wget https: //github .com /SpiderLabs/owasp-modsecurity-crs/tarball/v2 .2.5 -O /tmp/owasp . tar .gz
  2. Extract the package:       
    cd /tmp ; tar -zxvf owasp. tar .gz; rm owasp. tar .gz
  3. Copy the directory to /etc/modsecurity, and set the permissions:       
    sudo mv SpiderLabs-owasp-modsecurity-crs-5c28b52/ /etc/modsecurity/owasp-crs
    sudo chmod -R 644 /etc/modsecurity/owasp-crs
  4. Link the rules to /etc/modsecruity/owasp-crs/activated_rules directory:       
    sudo mv /etc/modsecurity/owasp-crs/modsecurity_crs_10_setup .conf.example /etc/modsecurity/owasp-crs/modsecurity_crs_10_setup .conf
    cd /etc/modsecurity/owasp-crs/activated_rules/
    sudo ln -s .. /modsecurity_crs_10_setup .conf
    for f in $( ls .. /base_rules/ ); do sudo ln -s .. /base_rules/ $f; done
    for f in $( ls .. /optional_rules/ ); do sudo ln -s .. /optional_rules/ $f; done
  5. Modify /etc/apache2/mods-available/mod-security.conf to include the rules:       
    sudo vi /etc/apache2/mods-available/mod-security .conf
    Add the following line:       
    Include "/etc/modsecurity/owasp-crs/activated_rules/*.conf"
  6. Enable headers module:       
    sudo a2enmod headers
    This to fix the following error:
    Syntax error on line 29 of /etc/apache2/conf.d/modsecurity/optional_rules/modsecurity_crs_49_header_tagging.conf:
    Invalid command 'RequestHeader', perhaps misspelled or defined by a module not included in the server configuration
    Action 'configtest' failed.
    The Apache error log may have more information.
        ...fail!
    when restarting apache2.     
Enable ModSecurity module and restart apache2:   
sudo a2enmod mod-security; sudo /etc/init .d /apache2 restart
目录
相关文章
|
1月前
|
Ubuntu Java 测试技术
【Linux】一站式教会:Ubuntu(无UI界面)使用apache-jmeter进行压测
【Linux】一站式教会:Ubuntu(无UI界面)使用apache-jmeter进行压测
|
2月前
|
Kubernetes Ubuntu 应用服务中间件
在Ubuntu22.04 LTS上搭建Kubernetes集群
在Ubuntu22.04.4上安装Kubernetes v1.28.7,步骤超详细
324 1
在Ubuntu22.04 LTS上搭建Kubernetes集群
|
3月前
|
监控 Ubuntu
如何在 Ubuntu 22.04 LTS 上安装 Logwatch?
如何在 Ubuntu 22.04 LTS 上安装 Logwatch?
29 0
|
3月前
|
Ubuntu Java 数据库
如何在 Ubuntu 22.04 LTS 上安装和配置 OrientDB?
如何在 Ubuntu 22.04 LTS 上安装和配置 OrientDB?
34 1
如何在 Ubuntu 22.04 LTS 上安装和配置 OrientDB?
|
3月前
|
Ubuntu 编译器 C语言
如何在 Ubuntu 22.04 LTS 上安装 Spack?
【1月更文挑战第8天】
67 0
如何在 Ubuntu 22.04 LTS 上安装 Spack?
|
3月前
|
监控 Linux 网络安全
【Linux】Web服务之Apache服务
【Linux】Web服务之Apache服务
42 0
|
5月前
|
Cloud Native Java 应用服务中间件
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(1)
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(1)
120 1
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(1)
|
5月前
|
Cloud Native Java 应用服务中间件
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(2)
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(2)
143 1
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(2)
|
5月前
|
Cloud Native Java 应用服务中间件
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(3)
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(3)
106 1
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(3)
|
5月前
|
Cloud Native Java 应用服务中间件
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(4)
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(4)
带你读《Apache Tomcat的云原生演进》——GraalVM static compilation in web container application(4)