Koozali.org: home of the SME Server

New contrib : mod_security2

Offline Fof

  • **
  • 22
  • +0/-0
New contrib : mod_security2
« on: December 18, 2008, 04:19:09 PM »
hi guys,

I just created my second SMEserver's package which is the very powerful and useful module for apache2 but I have always no cvs access... what's a  pity ! (cf http://forums.contribs.org/index.php/topic,42830.0.html)

I'm pressed to uploads my contribs.

Best regards.

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: New contrib : mod_security2
« Reply #1 on: December 18, 2008, 07:28:51 PM »
but I have always no cvs access... what's a  pity !
Please stop commenting on this in the forum in every topic you create. Use the bug you created for that. It is there for a reason, if you are wondering why it is not picked up: try there.
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)

Offline Franco

  • *
  • 1,171
  • +0/-0
    • http://contribs.org
Re: New contrib : mod_security2
« Reply #2 on: December 20, 2008, 04:27:54 AM »
where is the package?

Offline Fof

  • **
  • 22
  • +0/-0
Re: New contrib : mod_security2
« Reply #3 on: December 22, 2008, 09:40:50 AM »
where is the package?

I have to get an access through sourceforge in order to upload my contribs on the cvs.

Offline Franco

  • *
  • 1,171
  • +0/-0
    • http://contribs.org
Re: New contrib : mod_security2
« Reply #4 on: December 22, 2008, 12:23:47 PM »
I have to get an access through sourceforge in order to upload my contribs on the cvs.
Why wait? Put it up somewhere so we can try! What does mod_security2 do?

Thanks,

Offline Fof

  • **
  • 22
  • +0/-0
Re: New contrib : mod_security2
« Reply #5 on: December 22, 2008, 02:53:32 PM »
Why wait? Put it up somewhere so we can try! What does mod_security2 do?

Thanks,

Somewhere on my own servers did you mean ?
Actually, I could upload my contribs on my server for some tests, it's really not a problem.

Offline Franco

  • *
  • 1,171
  • +0/-0
    • http://contribs.org
Re: New contrib : mod_security2
« Reply #6 on: December 22, 2008, 03:12:59 PM »
That's what I mean ;)
Let us know and I'll be happy to test.

Thanks,


Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: New contrib : mod_security2
« Reply #8 on: December 22, 2008, 11:59:28 PM »
Fof, please also supply links to your src.rpm files.

Offline Fof

  • **
  • 22
  • +0/-0
Re: New contrib : mod_security2
« Reply #9 on: December 23, 2008, 01:26:04 AM »
Ok, sorry, I will package it with the "-ba" option tomorrow.

Offline Fof

  • **
  • 22
  • +0/-0
Re: New contrib : mod_security2
« Reply #10 on: December 23, 2008, 09:52:50 AM »
I have supplied the src.rpm as well ;)

Thanks.

Offline Fof

  • **
  • 22
  • +0/-0
Re: New contrib : mod_security2
« Reply #11 on: December 23, 2008, 04:25:52 PM »
I have improved the building process in order to build much better as said in the devguide.

ModSecurity-2.5.7 release 2 :
http://www.deblogtoi.com/public/informatique/SME_Server/modsecurity-2.5.7-2.src.rpm
http://www.deblogtoi.com/public/informatique/SME_Server/modsecurity-2.5.7-2.i386.rpm

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: New contrib : mod_security2
« Reply #12 on: December 23, 2008, 04:29:32 PM »
I have improved the building process in order to build much better as said in the devguide.
No you did not, as there are still actions being done in the SPEC file. Please subscribe to the devinfo mailinglist so we can discuss and help you there.
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: New contrib : mod_security2
« Reply #13 on: December 23, 2008, 11:18:30 PM »
No you did not, as there are still actions being done in the SPEC file. Please subscribe to the devinfo mailinglist so we can discuss and help you there.

Cactus, alternatively you could open bugs in the bug tracker, and we can provide feedback there.

Offline soprom

  • *
  • 589
  • +0/-0
    • www.logiciel-libre.org
Re: New contrib : mod_security2
« Reply #14 on: December 28, 2008, 08:47:03 PM »
Please tell us more about what it does!
Why should I use this for?
does it compare to snort?
« Last Edit: December 28, 2008, 08:49:50 PM by soprom »
Sophie from Montréal

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: New contrib : mod_security2
« Reply #15 on: December 29, 2008, 10:42:31 AM »
Please tell us more about what it does!
Why should I use this for?
does it compare to snort?

Just a tiny bit of effort will provide answers to your questions:

http://www.google.com.au/search?q=mod_security2

Offline soprom

  • *
  • 589
  • +0/-0
    • www.logiciel-libre.org
Re: New contrib : mod_security2
« Reply #16 on: December 29, 2008, 02:55:45 PM »
Thanks Charlie, but I had already done that. But since I'm not good at ready rpms, I'd like to understand a little more if this is important or not in SME and if Snort does the same on a separate firewall.
Sophie from Montréal

Offline Fof

  • **
  • 22
  • +0/-0
Re: New contrib : mod_security2
« Reply #17 on: December 29, 2008, 03:05:54 PM »
Snort is an IDS and not a firewall. The currently firewall is Netfilter but it's used for intercepting and manipulationg the network package (filtering).
On the other hand, modSecurity is used for parsing the http headers because the most of attacks come from URL.

From the modsecurity doc :
"ModSecurity is a web application firewall (WAF). With over 70% of attacks now carried out over the
web application level, organisations need all the help they can get in making their systems secure. WAFs
are deployed to establish an increased external security layer to detect and/or prevent attacks before they
reach web applications. ModSecurity provides protection from a range of attacks against web applications
and allows for HTTP traffic monitoring and real-time analysis with little or no changes to existing infra-
structure."

Is it better now ?