store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 18, 2013 10:58 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 
Author Message
 Post subject: Duplicate Rule Entries
Unread postPosted: Wed Feb 17, 2010 7:10 pm 
Offline
New Forum User
New Forum User

Joined: Tue Feb 16, 2010 4:06 pm
Posts: 3
We just recently purchased a subscription and are testing it out on one of our servers. My question is there any need for the following modsecurity files as they may result in duplicate rules?

modsecurity_crs_21_protocol_anomalies.conf
modsecurity_crs_23_request_limits.conf
modsecurity_crs_40_generic_attacks.conf
modsecurity_crs_45_trojans.conf
modsecurity_crs_50_outbound.conf


Thank you,


Top
 Profile  
 
 Post subject: Re: Duplicate Rule Entries
Unread postPosted: Wed Feb 17, 2010 8:33 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1843
You would normally not use any of the config/rules files supplied with mod_security itself -- you would only use the ones supplied with your subscription.

If you have a full ASL subscription and you use Plesk then there's an auto-installer and auto-updater. If you subscribe to the rules only then the situation is slightly different and as I don't know much about it I can't really comment. I'm sure Mike/Scott will supply the required info.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Duplicate Rule Entries
Unread postPosted: Wed Feb 17, 2010 10:03 pm 
Offline
New Forum User
New Forum User

Joined: Tue Feb 16, 2010 4:06 pm
Posts: 3
Yes, most of these don't matter. modsecurity_crs_40_generic_attacks.conf has been the most useful. As long as those rules are covered I'll remove them when confirmation is received.


Top
 Profile  
 
 Post subject: Re: Duplicate Rule Entries
Unread postPosted: Thu Feb 18, 2010 11:17 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
You don't any of them, its all covered in our rules. Although if you want to use both it won't hurt, they use different IDs (we have a reserved range too). Although it will use up more resources to run both sets.

Plus you have to tune all the core rules, so expect false positives with those rules until you do that.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group