[Pound Mailing List] Integrated Libmodsecurity in Pound

Álvaro Cano Blanco <[email protected]> Mon, 24 Jun 2019 16:59:29 +0200
Newsgroups gmane.comp.web.pound.general
Message-ID <[email protected]>
--000000000000c536a6058c130f91
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hello everybody,

Recently, we (the Zevenet Team) integrated libmodsecurity 3.0.3 in Pound.
So, if it is useful for anybody or somebody wants to try it, it is
available in the GitHub Zevenet Pound repository:

https://github.com/zevenet/pound.

I regret cannot add a patch only with the WAF code, but the Zevenet Pound
code has diverged a lot from its original point. Other community patches
have been applied and other developments too.

As brief information:
* The ruleset directives are global for all HTTP/S listeners in a Pound
process.
* The "WafRule" directive is a file with the Modsecurity directives to
execute. Several wafRule directives can be added to a pound config file.
* The "WafBodySize" directive sets a limit for the body buffer. If the
request body or response body is bigger than this value, the body will not
be inspected. The 0 value does not set any limit.
* pounctl -R -s <pound_ctl_socket>, will reload the WAF rules without
stopping the load balancing service.

If anybody has a doubt or suggestion for improvement I will be glad to hear
it.

Regards,
Alvaro


--=20
=C3=81lvaro Cano Development and Support Department www.zevenet.com
<https://www.zevenet.com/skype-redirect/[email protected]>
<https://www.facebook.com/zevenet> <https://twitter.com/zevenet>
<https://www.linkedin.com/company/zevenet> <https://github.com/zevenet>
<https://sourceforge.net/projects/zevenet/>
[image: Zevenet] <https://www.zevenet.com/signature/>

DISCLAIMER: This message contains confidential information and is intended
only for the individual named. If you are not the named addressee please
notify the sender immediately by email if you have received it by mistake
and delete it from your system, you should not disseminate, distribute or
copy this email in whole or in part.

--000000000000c536a6058c130f91
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hello everybody,</div><div><br></div><div>Recently, w=
e (the Zevenet Team) integrated libmodsecurity 3.0.3 in Pound. So, if it is=
 useful for anybody or somebody wants to try it, it is available in the Git=
Hub Zevenet Pound repository: <br></div><div><br></div><div><a href=3D"http=
s://github.com/zevenet/pound" target=3D"_blank">https://github.com/zevenet/=
pound</a>.</div><div><br></div><div>I regret cannot add a patch only with t=
he WAF code, but the Zevenet Pound code has diverged a lot from its origina=
l point. Other community patches have been applied and other developments t=
oo.<br></div><div><br></div><div>As brief information:<br></div><div>* The =
ruleset directives are global for all HTTP/S listeners in a Pound process.<=
/div><div>* The &quot;WafRule&quot; directive is a file with the Modsecurit=
y directives to execute. Several wafRule directives can be added to a pound=
 config file.</div>* The &quot;<span class=3D"gmail-m_1799661342251039112gm=
ail-blob-code-inner"><span class=3D"gmail-m_1799661342251039112gmail-pl-cce=
"><span class=3D"gmail-m_1799661342251039112gmail-pl-s">WafBodySize&quot; d=
irective sets a limit for the body buffer. If the request body or response =
body is bigger than this value, the body will not be inspected. The 0 value=
 does not set any limit.<br></span></span></span><div>* pounctl -R -s &lt;p=
ound_ctl_socket&gt;, will reload the WAF rules without stopping the load ba=
lancing service.<br></div><div><br></div><div>If anybody has a doubt or sug=
gestion for improvement I will be glad to hear it.<br></div><div><br></div>=
<div>Regards,</div><div>Alvaro</div><br clear=3D"all"><br>-- <br><div dir=
=3D"ltr" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div =
dir=3D"ltr"><span><font color=3D"#888888"><h4 style=3D"color:#6e6e6e;margin=
:0;font-size:12px;font-family:sans-serif">=C3=81lvaro Cano</h4>
      <h5 style=3D"color:#848484;margin:0;font-size:12px;font-family:sans-s=
erif">Development and Support Department</h5>
      <h5 style=3D"margin-top:0"><a style=3D"color:#595959;font-size:12px;f=
ont-family:sans-serif" href=3D"https://www.zevenet.com" target=3D"_blank">w=
ww.zevenet.com</a></h5>
      <a href=3D"https://www.zevenet.com/skype-redirect/?user=3Dalvaro.cano=
@zevenet.com" target=3D"_blank"><img src=3D"https://www.zevenet.com/img/Ico=
n_skype_medium.png"></a> <a href=3D"https://www.facebook.com/zevenet" targe=
t=3D"_blank"><img src=3D"https://www.zevenet.com/img/Icon_facebook_medium.p=
ng"></a> <a href=3D"https://twitter.com/zevenet" target=3D"_blank"><img src=
=3D"https://www.zevenet.com/img/Icon_twitter_medium.png"></a> <a href=3D"ht=
tps://www.linkedin.com/company/zevenet" target=3D"_blank"><img src=3D"https=
://www.zevenet.com/img/Icon_linkedIn_medium.png"></a> <a href=3D"https://gi=
thub.com/zevenet" target=3D"_blank"><img src=3D"https://www.zevenet.com/img=
/Icon_gitHub_medium.png"></a> <a href=3D"https://sourceforge.net/projects/z=
evenet/" target=3D"_blank"><img src=3D"https://www.zevenet.com/img/Icon_med=
ium_sourceforge.png"></a><br>
      <a href=3D"https://www.zevenet.com/signature/" target=3D"_blank"><img=
 style=3D"margin-top:5px" src=3D"https://www.zevenet.com/img/Zevenet_email_=
signature.png" title=3D"Zevenet" alt=3D"Zevenet"></a><br>
      <br>
      <span style=3D"color:#848484;margin:0;font-size:9px;font-family:sans-=
serif">DISCLAIMER: This message contains confidential information and is in=
tended only for the individual named. If you are not the named addressee pl=
ease notify the sender immediately by email if you have received it by mist=
ake and delete it from your system, you should not disseminate, distribute =
or copy this email in whole or in part.</span></font></span></div></div></d=
iv>

--000000000000c536a6058c130f91--

--
To unsubscribe send an email with subject unsubscribe to [email protected]
Please contact [email protected] for questions.