zoukankan      html  css  js  c++  java
  • ModSecurity--web应用防火墙

    Introducing ModSecurity IIS 2.7.2 Stable Release

     

    We are pleased to announce the release of a stable version of the open source web application firewall module ModSecurity IIS 2.7.2. Since the announcement of availability of the beta version in July 2012, we have been working very hard to bring the quality of the module to meet the enterprise class product requirements. In addition to numerous reliability improvements, we have introduced following changes since the first beta version was released:

    • optimized performance of request and response body handling
    • added “Include” directive, relative path and wildcard options to the configuration files
    • re-written installer code to avoid .NET Framework dependency and added installation error messages to system event log
    • integrated OWASP Core Rule Set in the MSI installer with IIS-specific configuration
    • fixed about 10 functional bugs reported by ModSecurity IIS users.

    Microsoft also released recently a TechNet article entitled “Security Best Practices to Protect Internet Facing Web Servers“, which explains in details benefits of deploying a WAF module on a web server.

    Integrated OWASP Core Rule Set

    In version 2.7.2 of ModSecurity IIS we have included OWASP Core Rules Set pre-configured to serve most common scenarios encountered on IIS server. The rule set gets installed into c:inetpubwwwrootowasp_crs directory, from which it can be included in any web.config file by adding:

    <ModSecurity enabled=”true” configFile=”owasp_crsmodsecurity_iis.conf” />

    The default setting enables request body access, disables response body access, does not use audit log, and sets temporary files and data folder to c:inetpub emp. User can
    enable or modify these and other features by uncommenting appropriate ModSecurity directives in modsecurity.conf ormodsecurity_crs_10_setup.conf files.

    2012 Toolsmith Tool of the Year Award: ModSecurity for IIS

    Russ McRee over at HolisticInfosec held open voting in January for the 2012 Toolsmith Tool of the Year Award and ModSecurity for IISwon!

    We are glad that the Toolsmith readers found value in the IIS version of ModSecurity and we hope that it will help them to quickly mitigate emerging threats to their Microsoft IIS/ASP/.Net environments.

    Acknowledgements

    I would like to thank Nazim Lala and Ashish Kurmi from Microsoft for their help in module testing, Breno Silva and Ryan Barnett from Trustwave for continuous support of the IIS version, and Simon Kosinski for his valuable insights and suggestions.

    Greg Wroblewski, MSRC

  • 相关阅读:
    如何把阿里图标库的图标生成代码并应用于自己的项目
    【记事件】
    极光推送,为什么IOS有的手机一直收不到推送。
    浮点型的数据对比。
    MySQL通过show processlist查看项目的mysql写的有问题
    thinkPHP5实现简单的多图上传
    mac终端运行/终止jar包
    referer参数和addslashes()函数的骚路子
    小技巧|addslashes绕过
    团队博客七
  • 原文地址:https://www.cnblogs.com/fangyuan303687320/p/5806332.html
Copyright © 2011-2022 走看看