2009/12/18 johpunk <[email protected]>: > bueno por aca les escribo sobre este tema a ver si me pueden echar una > mano. ya tengo tiempo tratando de configurar estos 2 modulos pero aun > no funcionan de manera correcta. > el mod_security lo e instalado al principio me e guiado por este > tutorial http://www.gentoo-wiki.info/Apache_Modules_mod_security con la > unica diferencia que me e descargado un core-rules mas nuevo, pero a la > hora de poner en mi http.conf estas 2 lineas > > Include /etc/apache2/modules.d/mod_security/*.conf > Include /etc/apache2/modules.d/mod_security/base_rules/*conf > > y reiniciar el apache e ingresar a mi blog no deja cargar las imagenes > ni plantilla del blog, por otro lado al querer ingresar a la base de > datos con phpmyadmin o ingresar como admin al blog me lansa un lindo > > You don't have permission to access xxxxxx on this server. > Apache Server at johpunk.homelinux.org Port 80
Echale un ojo a esto: http://richzendy.org/2007/04/22/modsecurity-howto.html > > por otro lado el mod_evasive lo tengo configurado de la siguiente > forma: > > <IfDefine EVASIVE> > LoadModule evasive_module modules/mod_evasive.so > > DOSHashTableSize 3097 > DOSPageCount 2 > DOSSiteCount 50 > DOSPageInterval 1 > DOSSiteInterval 1 > DOSBlockingPeriod 10 > > > # Set here an email to notify the DoS to someone > # (here is better to set the server administrator email) > DOSEmailNotify mi_email > > # Uncomment this line if you want to execute a specific command > # after the DoS detection > #DOSSystemCommand "su - someuser -c '/sbin/... %s ...'" > > # Specify the desired mod_evasive log location > DOSLogDir /var/log/apache2/evasive > > # WHITELISTING IP ADDRESSES > # IP addresses of trusted clients can be whitelisted to insure they are > never # denied. The purpose of whitelisting is to protect software, > scripts, local # searchbots, or other automated tools from being denied > for requesting large # amounts of data from the server. > > DOSWhitelist 172.16.1.9 > > </IfDefine> > > # vim: ts=4 filetype=apache > > y cuando ejecuto el test para probar si funciona correctamente o no > todas las lineas me salen como esta > > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > > y por lo que e leido la manera en que deberia de mostrar el test esas > lineas es de esta forma > > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 200 OK > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > HTTP/1.1 403 Forbidden > > oh! casi lo olvido en el http.conf tambien tengo esta liena que e > agregado > > Include /etc/apache2/modules.d/10_mod_evasive.conf > > al reiniciar el apache me muestra lo siguiente: > > * Stopping apache2... > [Fri Dec 18 20:27:03 2009] [warn] module evasive_module is already > loaded, skipping [ ok ] > * Starting apache2... > [Fri Dec 18 20:27:05 2009] [warn] module evasive_module is already > loaded, skipping [ ok > > la verdad nose que mas deba configurar para que funcionen bien, alguna > idea? > _______________________________________________ > Lista de Correo l-talug > Grupo de Usuarios Linux de Tchira - Venezuela > Para enviar un Correo a la lista: [email protected] > Para suscribirse o desuscribirse: > http://listas.velug.org.ve/mailman/listinfo/l-talug > Visitanos en el Canal IRC #talug en irc.freenode.net > _______________________________________________ Lista de Correo l-talug Grupo de Usuarios Linux de Tchira - Venezuela Para enviar un Correo a la lista: [email protected] Para suscribirse o desuscribirse: http://listas.velug.org.ve/mailman/listinfo/l-talug Visitanos en el Canal IRC #talug en irc.freenode.net
