Postingan

Menampilkan postingan dari Maret, 2024

Nginx - WAF ( Web Application Firewall )

Gambar
  Install Nginx and ModSecurity. sudo apt-get update sudo apt-get install nginx -y sudo apt-get install libnginx-mod-security -y sudo apt-get intall git -y Enable ModSecurity module in Nginx configuration. sudo sed -i 's/# include \/etc\/nginx\/modules-enabled\/\*\.conf;/include \/etc\/nginx\/modules-enabled\/\*\.conf;/' /etc/nginx/nginx.conf Configure ModSecurity rules sudo mv /etc/nginx/mods-available/mod-security.conf /etc/nginx/mods-available/mod-security.conf.orig sudo cp /usr/share/modsecurity-crs/modsecurity.conf-recommended /etc/nginx/mods-available/mod-security.conf sudo mv /etc/nginx/mods-available/modsecurity.conf /etc/nginx/mods-available/modsecurity.conf.orig sudo sed -i 's/SecRuleEngine DetectionOnly/SecRuleEngine On/' /etc/nginx/mods-available/modsecurity.conf sudo sed -i 's/SecResponseBodyAccess On/SecResponseBodyAccess Off/' /etc/nginx/mods-available/modsecurity.conf Download and configure the OWASP Core Rule Set. sudo git clone https://github.c...