This worked for me on centos 5.2 using info elsewhere on the DA forums and modsecurity site
For info see http://www.modsecurity.org/document...che/2.1.4/html-multipage/02-installation.html
download latest files from http://www.modsecurity.org/download/index.html
wget http://www.modsecurity.org/download/modsecurity-apache_2.5.9.tar.gz
tar xzvf modsecurity-apache_2.5.9.tar.gz
cd modsecurity-apache_2.5.9/apache2
./configure
make
make test
make install
mkdir -p /etc/modsecurity2/base_rules/
cd /etc/modsecurity2/base_rules/
wget http://www.modsecurity.org/download/modsecurity-core-rules_2.5-1.6.1.tar.gz
vi /etc/httpd/conf/httpd.conf
after load php module, add...
#mod_sec
LoadModule security2_module /usr/lib/apache/mod_security2.so
and at end of file...
<IfModule mod_security2.c>
# ModSecurity2 config file.
#
Include /etc/modsecurity2/base_rules/*conf
</IfModule>
then compile into apache with custombuild
cd /usr/local/directadmin/custombuild
mkdir -p custom/ap2
cp configure/ap2/configure.apache custom/ap2/configure.apache
vi custom/ap2/configure.apache
and add...
"--with-mod_security2"
then...
./build clean
./build apache
mkdir -p /etc/modsecurity2/base_rules/
cd /etc/modsecurity2/base_rules/
wget http://www.modsecurity.org/download/...5-1.6.1.tar.gz
[...]
"--enable-proxy" \
"--enable-expires" \
"--with-ssl=/usr" \
"--enable-headers" \
"--with-mod_security2"
SecAuditLog logs/modsec_audit.log
SecAuditLog /var/log/modsec_audit.log
SecDebugLog logs/modsec_debug.log
SecDebugLog /var/log/modsec_debug.log
This worked for me on centos 5.2 using info elsewhere on the DA forums and modsecurity site
For info see http://www.modsecurity.org/document...che/2.1.4/html-multipage/02-installation.html
download latest files from http://www.modsecurity.org/download/index.html
wget http://www.modsecurity.org/download/modsecurity-apache_2.5.9.tar.gz
tar xzvf modsecurity-apache_2.5.9.tar.gz
cd modsecurity-apache_2.5.9/apache2
./configure
make
make test
make install
mkdir -p /etc/modsecurity2/base_rules/
cd /etc/modsecurity2/base_rules/
wget http://www.modsecurity.org/download/modsecurity-core-rules_2.5-1.6.1.tar.gz
vi /etc/httpd/conf/httpd.conf
after load php module, add...
#mod_sec
LoadModule security2_module /usr/lib/apache/mod_security2.so
and at end of file...
<IfModule mod_security2.c>
# ModSecurity2 config file.
#
Include /etc/modsecurity2/base_rules/*conf
</IfModule>
then compile into apache with custombuild
cd /usr/local/directadmin/custombuild
mkdir -p custom/ap2
cp configure/ap2/configure.apache custom/ap2/configure.apache
vi custom/ap2/configure.apache
and add...
"--with-mod_security2"
then...
./build clean
./build apache
Noooooooooooo!Where do i go about adding these? In httpd.conf?
Noooooooooooo!
Add them to /etc/httpd/conf/security/modsecurity_crs_48_local_exceptions.conf
or to the custom vhost if it only applies to a domain
Theres no plug-ins, to see if its loaded, look for it in the phpinfo(); command.i dont see mod_security in the DA plugins . where i can see it ?
tnx
LoadFile /usr/local/lib/libxml2.so
LoadModule security2_module /usr/lib/apache/mod_security2.so
<IfModule mod_security2.c>
Include /etc/modsecurity2/*.conf
</IfModule>