Evaluate mod_security for preventing web server exploits and other issues #118

Open
opened 2015-04-04 16:13:43 +00:00 by GoogleCodeExporter · 6 comments
GoogleCodeExporter commented 2015-04-04 16:13:43 +00:00 (Migrated from github.com)
mod_security is a so-called web application firewall and available as Apache 
module in the official Ubuntu distribution [1]. It promises to be able to 
detect and prevent malicious client software, XSS, all kinds of injection types 
as well as trojans and backdoors [2].

Clearly enabling such module would be an advantage as it shifts responsibility 
from app development to server deployment, thus relieving Antville code.

--
[1] http://www.modsecurity.org
[2] 
http://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project

Original issue reported on code.google.com by interf...@p3k.org on 14 Jun 2010 at 7:40

``` mod_security is a so-called web application firewall and available as Apache module in the official Ubuntu distribution [1]. It promises to be able to detect and prevent malicious client software, XSS, all kinds of injection types as well as trojans and backdoors [2]. Clearly enabling such module would be an advantage as it shifts responsibility from app development to server deployment, thus relieving Antville code. -- [1] http://www.modsecurity.org [2] http://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project ``` Original issue reported on code.google.com by `interf...@p3k.org` on 14 Jun 2010 at 7:40
GoogleCodeExporter commented 2015-04-04 16:13:44 +00:00 (Migrated from github.com)

Original comment by interf...@p3k.org on 20 Jan 2011 at 11:17

  • Added labels: Milestone-Release-1.3
Original comment by `interf...@p3k.org` on 20 Jan 2011 at 11:17 - Added labels: **Milestone-Release-1.3**
GoogleCodeExporter commented 2015-04-04 16:13:44 +00:00 (Migrated from github.com)

Original comment by interf...@p3k.org on 29 May 2011 at 9:08

  • Added labels: Milestone-Release-1.4
Original comment by `interf...@p3k.org` on 29 May 2011 at 9:08 - Added labels: **Milestone-Release-1.4**
GoogleCodeExporter commented 2015-04-04 16:13:44 +00:00 (Migrated from github.com)
Although it will not solve all security issues we certainly should give it a 
try.

Original comment by interf...@p3k.org on 21 Apr 2012 at 4:27

  • Changed state: Started
``` Although it will not solve all security issues we certainly should give it a try. ``` Original comment by `interf...@p3k.org` on 21 Apr 2012 at 4:27 - Changed state: **Started**
GoogleCodeExporter commented 2015-04-04 16:13:44 +00:00 (Migrated from github.com)

Original comment by m...@tobischaefer.com on 28 Jul 2013 at 8:50

  • Added labels: Milestone-Release-1.5
  • Removed labels: Milestone-Release-1.4
Original comment by `m...@tobischaefer.com` on 28 Jul 2013 at 8:50 - Added labels: **Milestone-Release-1.5** - Removed labels: **Milestone-Release-1.4**
GoogleCodeExporter commented 2015-04-04 16:13:44 +00:00 (Migrated from github.com)

Original comment by m...@tobischaefer.com on 7 Mar 2015 at 5:59

Original comment by `m...@tobischaefer.com` on 7 Mar 2015 at 5:59
github-actions[bot] commented 2021-05-17 02:38:31 +00:00 (Migrated from github.com)

Stale issue message

Stale issue message
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: antville/antville#118
No description provided.