Question about Easyapache3 and mod_security

noimad1

Well-Known Member
Mar 27, 2003
626
0
166
So I see that there is an option for mod_security in the easyapache3.

I chose to install it on one server, but i was curious what rules it uses? Does it have it's own rules? Or does it just install the module, but no rules?

What if I want to add my own rules to it?
 

cPanelDavidG

Technical Product Specialist
Nov 29, 2006
11,212
13
313
Houston, TX
cPanel Access Level
Root Administrator
So I see that there is an option for mod_security in the easyapache3.

I chose to install it on one server, but i was curious what rules it uses? Does it have it's own rules? Or does it just install the module, but no rules?

What if I want to add my own rules to it?
It does not come with any rules, it just installs the module. You can configure your own rules after it is installed by going to WHM -> Plugins -> Mod Security.
 

noimad1

Well-Known Member
Mar 27, 2003
626
0
166
It does not come with any rules, it just installs the module. You can configure your own rules after it is installed by going to WHM -> Plugins -> Mod Security.

Ah, thank you very much for the information. One more quick question about adding the rules there.

Do I need to put the :

<IfModule mod_security.c>

</IfModule>
with the rules in between in that area, or do I just put the rules themselves in there?

SecFilter "pacotar\.txt"
 

mtindor

Well-Known Member
Sep 14, 2004
1,417
82
178
inside a catfish
cPanel Access Level
Root Administrator
If you are running Apache 1.3, I would recommend the HostMerit rules - I like them.

http://www.hostmerit.com/modsec.user.conf

See this post regarding where else to get rules:

http://forums.cpanel.net/showthread.php?t=71985&highlight=hostmerit

If you are running Apache 2.x, I would suggest the rules from modsecurity.org or gotroot.com - The Hostmerit rules will not work on the Mod Security in Apache 2.x as they were designed for the Mod Security that runs on Apache 1.3

As for figuring out how to incorporate those rules in, you need to do the legwork on that.

Mike
 

noimad1

Well-Known Member
Mar 27, 2003
626
0
166
Mike,

Thanks for the info. Yea, I've been using the hostmerit rules for quite some time.

I've entered in the rules with the

<IfModule mod_security.c>

</IfModule>

In there, and that seems to work.

Thanks,
Damion