赵小黑 发表于 2018-11-10 07:13:49

nginx增加modsecurity模块

git clone https://github.com/SpiderLabs/owasp-modsecurity-crs  
cp -R owasp-modsecurity-crs /etc/nginx/
  
cp
  
/etc/nginx/owasp-modsecurity-crs/modsecurity_crs_10_setup.conf.example
  
/etc/nginx/owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
  
cd ModSecurity/
  
cp modsecurity.conf-recommended /etc/nginx/modsecurity.conf
  
cp unicode.mapping /etc/nginx
  
vim modsecurity.conf
  
SecRuleEngine on
  
nclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
  
Includeowasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
  
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
  
Includeowasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
  
Includeowasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
  
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
  
Includeowasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf


页: [1]
查看完整版本: nginx增加modsecurity模块