Thank you for the great contents you deliver through your channel. You can check if it works from the modsecurity log, it will show the requests that waf blocked or detected and the details of these requests
great tutorial, i setup modsec to implement as a solution for a vulnerable web app and makes everything secure by just deploying the WAF, i have seen a lot of your videos and you teach quality tools for security!! keep up the good work!!
Good to see you are back
The Boss is back !!! ♥️
After a long time. Informative come back!!!
hi please help me with my problem, when I apply this module my website becomes text only without images or order or anything , do you know what is it and how to fix it?
Why we remove existing rule and adding rules again? Is modsecurity installed with same oswap ?
thank you so much! loved the documentation :)
What if I do not have phpmyadmin, where to add config then? Thank you
Hello Sir, I have followed the instruction until the time 14:58, and the next step is to restart apache2, when I did this, I got this error "Syntax error on line 43 of /usr/share/modsecurity-crs/rules/REQUEST-922-MULTIPART-ATTACK.conf Error creating rule: Unknown variable: &MULTIPART_PART_HEADERS", can you help me, how can I solve it? thanks in advance
i have a reverse proxy with nginx if someone access my apache site through nginx reverse proxy which is normal but does somebody actually have to access the apache2 site directly for modsecurity to work or people can still access nginx reverse proxy to my site(apache2) and will modsecurity still work. thanks.
brother nice video but can you help me solvin this ? Job for apache2.service failed because the control process exited with error code. See "systemctl status apache2.service" and "journalctl -xeu apache2.service" for details. I have tried every possible way i know..
Can we create apache on different machine and modsecurity on another machine ?
Very nice sir 😊❤ thank you so much sar 😊❤
I have question: On installation of latest version of modsecurity, owasp rules are present in usr/share/modsecurity-crs dir then why it is required to replace with the owasp rules available on git repository? i even found version difference for installed modsecurity rules & git clone owasp rules, if i am not wrong its always safe to use latest version.
Can this block an automated sqlmap injection running from Kali machine?
hello is this modsecurity3 or the old version
Having an error here sir: systemctl restart apache2 (after all the configurations) returns an error. after inspecting, I found out using the journalctl that the webserver will refuse to start with an Unknown variable: &MULTIPART_PART_HEADERS error. I temporarily deleted the file rules/REQUEST-922-MULTIPART-ATTACK.conf as a workaround. Apache now starts normally, but I am wary because now the rules are incomplete. modsecurity2 version is 2.9.5 (I followed your commands in this video). Has anyone found a solution to this? Anyway sir, your tutorials are great, as always! Learned a lot. :)
Any tutorial modsec in IIS 10?
@HackerSploit