Skip to content

About modsecurity-nginx issue #48

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Hello-Linux opened this issue May 21, 2017 · 3 comments
Closed

About modsecurity-nginx issue #48

Hello-Linux opened this issue May 21, 2017 · 3 comments
Assignees

Comments

@Hello-Linux
Copy link

Hello-Linux commented May 21, 2017

When I use modsecurity-nginx,if I have many crs rules like "REQUEST-901-INITIALIZATION.conf REQUEST-903.9001-DRUPAL-EXCLUSION-RULES.conf REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
REQUEST-905-COMMON-EXCEPTIONS.conf REQUEST-910-IP-REPUTATION.conf REQUEST-911-METHOD-ENFORCEMENT.conf
REQUEST-912-DOS-PROTECTION.conf REQUEST-913-SCANNER-DETECTION.conf REQUEST-920-PROTOCOL-ENFORCEMENT.conf
REQUEST-921-PROTOCOL-ATTACK.conf REQUEST-930-APPLICATION-ATTACK-LFI.conf REQUEST-931-APPLICATION-ATTACK-RFI.conf
REQUEST-932-APPLICATION-ATTACK-RCE.conf REQUEST-933-APPLICATION-ATTACK-PHP.conf REQUEST-941-APPLICATION-ATTACK-XSS.conf
REQUEST-942-APPLICATION-ATTACK-SQLI.conf REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf REQUEST-949-BLOCKING-EVALUATION.conf
RESPONSE-950-DATA-LEAKAGES.conf RESPONSE-951-DATA-LEAKAGES-SQL.conf RESPONSE-952-DATA-LEAKAGES-JAVA.conf
RESPONSE-953-DATA-LEAKAGES-PHP.conf RESPONSE-954-DATA-LEAKAGES-IIS.conf RESPONSE-959-BLOCKING-EVALUATION.conf
RESPONSE-980-CORRELATION.conf" so I can use "modsecurity_rules_file /etc/nginx/owasp-modsecurity-crs/rules/*.conf"???????? If I use modsecurity-nginx so I don't use the modsecurity.conf and crs-setup.conf and unicode.mapping file ??????

@zimmerle zimmerle self-assigned this May 22, 2017
@zimmerle
Copy link
Contributor

It is ok so use modsecurity_rules_file multiple times.

@Hello-Linux
Copy link
Author

@zimmerle I used modsecurity-nginx version ,in my nginx config I only add "modsecurity on" and "modsecurity_rules_file" In addition to the two commands do I have to do any other operations?If so, please tell me the detailed steps,Because of your official document sent these two commands not only introduce the other steps??
I know I have install modsecurity-nginx successed,but I want to know my nginx configuration file is correct?? When I restart nginx why not My error.log show "ModSecurity for nginx (STABLE)/2.9.1 (http://www.modsecurity.org/) configured."?? and How do I test my configuration has been successful? When I'm with modsecurity before I use siege pressure test to determine whether open successfully but now how can I judge?
Surface I am a successful installation, but in the process of pressure testing rules have not become effective?
e88ca7b6-3f04-11e7-967f-de748966d25f
e883e478-3f04-11e7-9034-e1c75fd23b92

@zimmerle
Copy link
Contributor

You should not see 2.9.1 message if you are not running 2.9.1. There is something wrong with your installation or compilation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants