modseccfg GUI (for Apache setups)

mario <[email protected]> Thu, 26 Nov 2020 16:42:05 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <8158d01d.AMMAAIgXEVYAAAAAAAAAALFkHlsAAAAAAAoAAAAAAAMfkwBfv8zP@mailjet.com>
So, this is probably not very interesting to professional users. But I
made a little tool to help with the initial setup of mod_security/CRS
rules. Specifically disabling potential conflicting rules.

It's a desktop GUI, not yet another web interface. But can be used
remotely nonetheless. It's fairly alpha still, but perhaps worth a
look:
https://pypi.org/project/modseccfg/

The log viewer isn't too useful yet. I'll probably add colorization
and filtering/search, or perhaps look for some log preprocessor
scripts to bundle. The JSON format at least seems workable to craft
some predictions from.
There's possibly also a [modify] dialog coming (SecRuleUpdateAction..),
even though I'm not sure if anyone would use a GUI for that. But it's
definitely never going to become a SecRule IDE. It's intended for
simpler needs really.

And let me quickly mention again that this is alpha quality.
Goes without saying, but DO NOT use it on production servers.


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/