by mickey
1.安装mod-security
mickey@pentest:~$ sudo apt-get install libapache2-mod-security2
2.新建配置文件
mickey@pentest:/etc/apache2/conf.d$ sudo vim modsecurity2.conf
<ifmodule mod_security2.c>
Include conf.d/modsecurity/*.conf
</ifmodule>
3.下载规则库
mickey@pentest:/etc/apache2/conf.d$ sudo mkdir modsecurity
mickey@pentest:/etc/apache2/conf.d$ sudo wget http://www.modsecurity.org/download/modsecurity-core-rules_2.5-1.6.1.tar.gz
mickey@pentest:/etc/apache2/conf.d$ sudo tar xzvf modsecurity-core-rules_2.5-1.6.1.tar.gz
mickey@pentest:/etc/apache2/conf.d$ sudo rm CHANGELOG LICENSE README modsecurity-core-rules_2.5-1.6.1.tar.gz
4.激活mod-security模块
mickey@pentest:/etc/apache2/conf.d$ sudo a2enmod mod-security
Module mod-security already enabled
5.建立日志目录
mickey@pentest:/etc/apache2$ sudo mkdir logs
6.启动服务
mickey@pentest:/etc/apache2$ sudo /etc/init.d/apache2 start
* Starting web server apache2 [ OK ]
暂时没有评论