Jump to content

ModSecurity

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 203.0.215.3 (talk) at 01:28, 24 March 2016 (date typo fix). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

ModSecurity
Stable release
2.9.1 / 9 March 2016; 8 years ago (2016-03-09)
Repository
Available inEnglish
LicenseBSD license
Websitemodsecurity.org

ModSecurity supplies an array of request filtering and other security features to the Apache HTTP Server, IIS and NGINX. ModSecurity is a web application layer firewall. ModSecurity is free software released under the Apache license 2.0.

ModSecurity is one of the Apache server modules that provides website protection by defending from hackers and other malicious attacks.[1] It is a set of rules with regular expressions that helps to instantly ex-filtrate the commonly known exploits.[2] Modsecurity obstructs the processing of invalid data (code injection attacks) to reinforce and nourish server's security.[3]

Reviews

On February 13, 2013, a comparative penetration testing analysis report was published by Zero Science Lab, showing that ModSecurity is more effective than CloudFlare and Incapsula, but it has more false positives than Incapsula.[4][5]

References

  1. ^ "What is ModSecurity and why is it important".
  2. ^ "Modsecurity overview".
  3. ^ "Web Application Firewall (WAF) Overview".
  4. ^ "Protect Your Website Vulnerabilities With a WAF – New Compairson Report – CloudFlare vs Incapsula vs ModSecurity". Tony on Security. Tony Perez. Retrieved 14 April 2013.
  5. ^ http://www.slideshare.net/zeroscience/cloudflare-vs-incapsula-vs-modsecurity