Learn about Centmin Mod LEMP Stack today
Become a Member

Master Branch OWASP Modsecurity Core Rule set 3.1.1 in 123.09beta01

Discussion in 'Centmin Mod Github Commits' started by eva2000, Jul 2, 2019.

  1. eva2000

    eva2000 Administrator Staff Member

    59,410
    12,518
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,154
    Local Time:
    3:25 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    OWASP Modsecurity Core Rule set 3.1.1 in 123.09beta01

    - update with OWASP Modsecurity Core Rule Set 3.1.1 fix for ReDOS DDOS attack vulnerabilities which only apply if you have enabled optional Nginx modsecurity module via persistent config file /etc/centminmod/custom_config.inc set NGINX_MODSECURITY='y' prior to nginx recompiles via centmin.sh menu option 4 Security - ModSecurity OWASP Core Ruleset Security Vulnerabilities Leading To DDOS Attacks. NGINX_MODSECURITY='n' is set by default to be disabled on initial installs so wouldn't apply to users out of the box.
    - to update existing Centmin Mod Nginx if you enabled modsecurity, you run cmupdate to update 123.09beta01, then run centmin.sh menu option 4 to recompile Nginx and verify that /usr/local/nginx/owasp-modsecurity-crs-3.1.1/ directory exists and that your /usr/local/nginx/modsec/main.conf file references the Include files to 3.1.1 directory for crs-setup.conf and *.conf

    Continue reading...


    Centmin Mod Github Master branch

    Master branch is where most recent commits are made as at May 24, 2015.