Re: Where is the best place for the ModSecurity?
Reindl Harald <[email protected]> Wed, 24 Feb 2021 12:12:59 +0100
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Organization | the lounge interactive design |
| Message-ID | <[email protected]> |
Am 24.02.21 um 11:58 schrieb Jason Long via mod-security-users: > Hello, > Where is the best place for the ModSecurity to protect a WordPress > website? Is it true that a WAF like ModSecurity must be installed > between the web server and the Internet and not on the host itself? no it is not and given that you can adjust rules based on <Directory> in your httpd configuration it makes a lot of sense have it on the host itself and "must" don't exist at all - nobody can force you to setup a proxy nor pretend an additional proxy makes things more secure by it's existence the opposite is true: in doubt you are now vulerable for bugs of the proxy as well as the backend server - having more layers and complexity in the mix can make sense but it's not more secure out of the blue _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/