{"id":568,"date":"2015-05-09T10:08:52","date_gmt":"2015-05-09T10:08:52","guid":{"rendered":"http:\/\/securityresearch.cysecurity.org\/?p=568"},"modified":"2015-05-09T10:19:24","modified_gmt":"2015-05-09T10:19:24","slug":"568","status":"publish","type":"post","link":"https:\/\/securityresearch.cysecurity.org\/?p=568","title":{"rendered":"CSPF develops custom modsecurity rules for public use"},"content":{"rendered":"<p>CSPF has developed modsecurity rules that can protect servers from malicious hackers. This is written by Mr. Manish Tanwar &amp; Mr. Suriya Prakash<\/p>\n<p>Though OWASP CRS covers a lot of vulnerabilities it does not protect against most backdoor&#8217;s and latest bypasses.<\/p>\n<p>The other rules sets that are available are commercial in nature. So CSPF is developing a growing set of rules to protect against the latest bypasses and backdoors and releasing them publicly for all to use.<\/p>\n<p>The rules that we have provided can be easily expanded manually to suit your own needs.<\/p>\n<p>The video below will show how to enable these rules and also show a small demo of their functions.<\/p>\n<p>The mod-security rules can be downloaded here:<\/p>\n<p>The rules are currently able to:<\/p>\n<ul>\n<li>Block Sensitive Files\/Folders from being Accessed<\/li>\n<li>Block b374k shell variants.<\/li>\n<li>Block some common well known shells<\/li>\n<li>Disables directory listing and phpinfo<\/li>\n<li>Block SQL Injection\n<ul>\n<li>Normal SQL Injection<\/li>\n<li>Blind and Time Based SQL injection<\/li>\n<li>All types of SQLi<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>How to use it?<\/strong><\/p>\n<p>Install Modsecurity.<\/p>\n<p>Place the custom rules in a file<\/p>\n<p>eg:\/etc\/httpd\/msec\/created\/cus.conf<\/p>\n<p>then edit httpd.conf or apache.conf (Depends on OS)<\/p>\n<p>eg:\/etc\/httpd\/conf\/httpd.conf<\/p>\n<p>add the lines like this:<br \/>\n==============================================<br \/>\n&lt;IfModule security2_module&gt;<br \/>\ninclude msec\/modsecuritydefault.conf<br \/>\ninclude msec\/created\/cus.conf<br \/>\n&lt;\/IfModule&gt;<br \/>\n==============================================<\/p>\n<p>Then restart the server.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/p>\n<p><strong>Files:<\/strong><\/p>\n<p>Usage Video:<\/p>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/0BwjcnnWhy4E3UkZwckV1UGM0SE0\/view?usp=sharing\" target=\"_blank\">https:\/\/drive.google.com\/file\/d\/0BwjcnnWhy4E3UkZwckV1UGM0SE0\/view?usp=sharing<\/a><\/p>\n<p>Custom Modsecurity Rule:<\/p>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/0BwjcnnWhy4E3R1Y5T3ozTTJsS1k\/view?usp=sharing\" target=\"_blank\">https:\/\/drive.google.com\/file\/d\/0BwjcnnWhy4E3R1Y5T3ozTTJsS1k\/view?usp=sharing<\/a><\/p>\n<p>Custom Modsecurity Rules(Windows View):<\/p>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/0BwjcnnWhy4E3cDhqWDQwbURMN0k\/view?usp=sharing\" target=\"_blank\">https:\/\/drive.google.com\/file\/d\/0BwjcnnWhy4E3cDhqWDQwbURMN0k\/view?usp=sharing<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSPF has developed modsecurity rules that can protect servers from malicious hackers. This is written by Mr. Manish Tanwar &amp; Mr. Suriya Prakash Though OWASP CRS covers a lot of vulnerabilities it does not protect against most backdoor&#8217;s and latest bypasses. The other rules sets that are available are commercial in nature. So CSPF is\u2026 <span class=\"read-more\"><a href=\"https:\/\/securityresearch.cysecurity.org\/?p=568\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/568"}],"collection":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=568"}],"version-history":[{"count":4,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/568\/revisions"}],"predecessor-version":[{"id":572,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=\/wp\/v2\/posts\/568\/revisions\/572"}],"wp:attachment":[{"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=568"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=568"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securityresearch.cysecurity.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=568"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}