Author Topic: Free mod_security rules!  (Read 16089 times)

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Free mod_security rules!
« on: December 28, 2013, 01:17:38 PM »
Click here to get Free Modsecurity rules

Web hosting industry is an important industry for Comodo.
Protecting web sites is an important function as attacks against websites increase and not only are the businesses running these websites are under attack, but visitors who use these websites are also vulnerable due to compromised web servers and web sites.

Mod_sec is a decent platform but without signatures/rules its not much use (ModSecurity™ is a web application firewall engine that provides very little protection on its own. In order to become useful, ModSecurity™ must be configured with rules)](ModSecurity™ is a web application firewall engine that provides very little protection on its own. In order to become useful, ModSecurity™ must be configured with rules)

There were some free mod_sec rules in the past that did a good job, albeit delayed it was decent, but it no longer is available. (Please note that Atomicorp no longer provides a free delayed version of its ModSecurity Rule set.)

Comodo is a company who sees the threat on daily basis on both sides of the fight, consumer side and business side. We see it in the consumer side because we protect tens of millions of users using our Antivirus products. We see it on the business site because we monitor and protect businesses and their website with products like www.hackerguardian.com and www.webinspector.com.

So, this puts Comodo in the position of most capable company who can produce the mod_sec rules and do so very effectively. And here we are, we decided to build the infrastructure and provide mod_sec rules for FREE! (there might be different variation in future but we will always provide some free version so that you can be secure).

Here is our promise to you: We will work with you to protect your web sites and web servers! Talk to us about problems/attacks you are facing and let us provide you mod_sec rules for free to protect yourself.

you can go ahead and get your mod_sec rules for free at http://modsecurity.comodo.com/

Free Mod_security Rules blog

cheers

Melih

[attachment deleted by admin]
« Last Edit: April 08, 2014, 09:34:16 AM by Melih »

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Re: Free mod_security rules!
« Reply #1 on: December 29, 2013, 01:31:36 PM »
BTW...

We are more than happy to focus on specific attack vectors,  and create custom virtual patches for these vulnerabilities.

So talk to us about these and we'll be more than happy to create these...(for free)...

Melih

Offline w-e-v

  • Star Group
  • Comodo's Hero
  • *****
  • Posts: 1498
  • BETA FORCE MEMBER
Re: Free mod_security rules!
« Reply #2 on: December 30, 2013, 08:28:29 AM »
One I install it, will it protect all my websites hosted under the same server, or do I have to create rules for each website?

Offline idem

  • Comodo Staff
  • Comodo Member
  • *****
  • Posts: 40
Re: Free mod_security rules!
« Reply #3 on: December 30, 2013, 04:05:39 PM »
It will work for all sites on server by default, but you can limit it to specific sites if you want.

Offline George_Fusioned

  • Newbie
  • *
  • Posts: 19
Re: Free mod_security rules!
« Reply #4 on: December 30, 2013, 04:42:30 PM »
One I install it, will it protect all my websites hosted under the same server, or do I have to create rules for each website?

In case this is for cPanel, there's a great tool called ConfigServer ModSecurity Control (cmc) which allows you to control the domains you wish to protect (or not) with mod_security as well as see the mod_security logfile with detailed information about each entry. Additionally you can edit the mod_security conf files from there.

Check it out here: http://configserver.com/cp/cmc.html

Offline w-e-v

  • Star Group
  • Comodo's Hero
  • *****
  • Posts: 1498
  • BETA FORCE MEMBER
Re: Free mod_security rules!
« Reply #5 on: December 30, 2013, 08:12:51 PM »
Thank you both for your reply. I will give it a try. :-TU

Offline platinumservermanagement

  • Newbie
  • *
  • Posts: 1
  • Platinum Server Management
Re: Free mod_security rules!
« Reply #6 on: January 01, 2014, 09:08:02 PM »
This is really great that comodo is providing a free set of modsecurity rules. Just wondering, how often are the rules updated? and how strict are they (will they cause a lot of false alarms with common scripts like WP, Joomla, etc)?

Thanks!
« Last Edit: January 01, 2014, 09:11:02 PM by platinumservermanagement »
PlatinumServerManagement
The OLDEST and LARGEST and MOST TRUSTED server management provider in the USA, with 15+ employees and growing!
Providing quality support for OVER 15 years! Currently supporting over 3,000 servers monthly!

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Re: Free mod_security rules!
« Reply #7 on: January 02, 2014, 08:07:35 AM »
This is really great that comodo is providing a free set of modsecurity rules. Just wondering, how often are the rules updated? and how strict are they (will they cause a lot of false alarms with common scripts like WP, Joomla, etc)?

Thanks!

We have over 70M users with our Free antivirus products and FP is an important thing to watch for them too. Our AV labs are well trained to "hate FPs" :).
Of course nothing is 100% and the key is, our AV labs guys are present here in this forum 24/7. If you get any FP, you can report via the application or come here and tell us, we'll see to it immediately and release patch.
How fast are the updates? As fast as a new vulnerability is found. We are constantly watching any new vulnerability, the second we find out, is the second we start writing the rules.

Our job is to protect you and your business.

Melih

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Re: Free mod_security rules!
« Reply #8 on: January 10, 2014, 04:20:21 PM »
we will have the new version of cpanel plugin available early next week! HURRAY :)

Offline Julien-WebTalkPRO

  • Newbie
  • *
  • Posts: 15
Re: Free mod_security rules!
« Reply #9 on: January 10, 2014, 09:01:19 PM »
Great! 0.32 btw are pretty smooth so far.  8)
WebTalkPRO - Webmaster & Hosting community

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Re: Free mod_security rules!
« Reply #10 on: January 11, 2014, 08:48:37 AM »
Great! 0.32 btw are pretty smooth so far.  8)

Thanks Julien, good to hear.

I think the rules are pretty smooth now (thanks to you guys!).

New cpanel plugin will be released early next week and we hope it will be working nicely too...

then the work is about creating the fastest modsec rules...offer highest security with the least cpu cycles!

cheers

Melih

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Re: Free mod_security rules!
« Reply #11 on: January 13, 2014, 01:13:42 PM »
The latest version is now released.

Cpanel plugin supports the latest cpanel version and all seems to be working nicely (fingers crossed).

you can now install free modsecurity rules using our Comodo cpanel plugin at waf.comodo.com

please let us know if we can help in any way.

Offline Julien-WebTalkPRO

  • Newbie
  • *
  • Posts: 15
Re: Free mod_security rules!
« Reply #12 on: January 13, 2014, 06:08:00 PM »
1.0 cPanel Plugin working good so far. Nice!
WebTalkPRO - Webmaster & Hosting community

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14623
    • Video Blog
Re: Free mod_security rules!
« Reply #13 on: January 13, 2014, 07:29:57 PM »
1.0 cPanel Plugin working good so far. Nice!

hurray :) thanks for the confirmation Julien!


Offline w-e-v

  • Star Group
  • Comodo's Hero
  • *****
  • Posts: 1498
  • BETA FORCE MEMBER
Re: Free mod_security rules!
« Reply #14 on: January 14, 2014, 09:46:38 AM »
I want to give this a try, but I have 3 concise questions:

1. If I am running another panel other than cPanel, can I still use the Agent? If "yes", how can I access the WAF panel to manage and update the rules?
2. How can I apply the rules to only a few specific websites (virtual hosts), instead of ALL the websites?
3. Is there a tool or online service that can be used to do an "attack" and see Comodo WAF in action?


Thank you very much. I am very interested in this product.

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek