Useful ModSecurity Rules & Rules Sets

Share/Save

Rule Sets

To get effective security from ModSecurity you need rules, and I strongly recommend using the core rule set, though I do need to mention that I wrote it.

  • The Core Rule Set - the standard bundled with ModSecurity. Breach Security also sells a commercial Enhanced Rule Set as part of their ModSecurity support services.
  • The GotRoot rule set - The only alternative complete rule set. Free version is delayed by 30 days after the release of the commercial rules.

Additional Rules

The rule sets above are not all encompassing. Most importantly, both aim at being plug and play so anything more complex that requires configuration is not included. The rules below are useful additions to the rule sets.

Post new comment

Full HTML

  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.

Filtered HTML

  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <blockquote> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.