Re: Where is the best place for the ModSecurity?

Reindl Harald <[email protected]> Wed, 24 Feb 2021 12:12:59 +0100
Newsgroups gmane.comp.apache.mod-security.user
Organization the lounge interactive design
Message-ID <[email protected]>

Am 24.02.21 um 11:58 schrieb Jason Long via mod-security-users:
> Hello,
> Where is the best place for the ModSecurity to protect a WordPress 
> website? Is it true that a WAF like ModSecurity must be installed 
> between the web server and the Internet and not on the host itself?

no it is not and given that you can adjust rules based on <Directory> in 
your httpd configuration it makes a lot of sense have it on the host itself

and "must" don't exist at all - nobody can force you to setup a proxy 
nor pretend an additional proxy makes things more secure by it's existence

the opposite is true: in doubt you are now vulerable for bugs of the 
proxy as well as the backend server - having more layers and complexity 
in the mix can make sense but it's not more secure out of the blue


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/