2009/12/18 johpunk <[email protected]>:
> bueno por aca les escribo sobre este tema a ver si me pueden echar una
> mano. ya tengo tiempo tratando de configurar estos 2 modulos pero aun
> no funcionan de manera correcta.
> el mod_security lo e instalado al principio me e guiado por este
> tutorial http://www.gentoo-wiki.info/Apache_Modules_mod_security con la
> unica diferencia que me e descargado un core-rules mas nuevo, pero a la
> hora de poner en mi http.conf estas 2 lineas
>
> Include /etc/apache2/modules.d/mod_security/*.conf
> Include /etc/apache2/modules.d/mod_security/base_rules/*conf
>
> y reiniciar el apache e ingresar a mi blog no deja cargar las imagenes
> ni plantilla del blog, por otro lado al querer ingresar a la base de
> datos con phpmyadmin o ingresar como admin al blog me lansa un lindo
>
> You don't have permission to access xxxxxx on this server.
> Apache Server at johpunk.homelinux.org Port 80

Echale un ojo a esto:

http://richzendy.org/2007/04/22/modsecurity-howto.html

>
> por otro lado el mod_evasive lo tengo configurado de la siguiente
> forma:
>
> <IfDefine EVASIVE>
> LoadModule evasive_module modules/mod_evasive.so
>
> DOSHashTableSize 3097
> DOSPageCount 2
> DOSSiteCount 50
> DOSPageInterval 1
> DOSSiteInterval 1
> DOSBlockingPeriod 10
>
>
> # Set here an email to notify the DoS to someone
> # (here is better to set the server administrator email)
> DOSEmailNotify mi_email
>
> # Uncomment this line if you want to execute a specific command
> # after the DoS detection
> #DOSSystemCommand "su - someuser -c '/sbin/... %s ...'"
>
> # Specify the desired mod_evasive log location
> DOSLogDir /var/log/apache2/evasive
>
> # WHITELISTING IP ADDRESSES
> # IP addresses of trusted clients can be whitelisted to insure they are
> never # denied. The purpose of whitelisting is to protect software,
> scripts, local # searchbots, or other automated tools from being denied
> for requesting large # amounts of data from the server.
>
> DOSWhitelist 172.16.1.9
>
> </IfDefine>
>
> # vim: ts=4 filetype=apache
>
> y cuando ejecuto el test para probar si funciona correctamente o no
> todas las lineas me salen como esta
>
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
>
> y por lo que e leido la manera en que deberia de mostrar el test esas
> lineas es de esta forma
>
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 200 OK
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
> HTTP/1.1 403 Forbidden
>
> oh! casi lo olvido en el http.conf tambien tengo esta liena que e
> agregado
>
> Include /etc/apache2/modules.d/10_mod_evasive.conf
>
> al reiniciar el apache me muestra lo siguiente:
>
> * Stopping apache2...
> [Fri Dec 18 20:27:03 2009] [warn] module evasive_module is already
>  loaded, skipping       [ ok ]
> * Starting apache2...
> [Fri Dec 18 20:27:05 2009] [warn] module evasive_module is already
> loaded, skipping       [ ok
>
> la verdad nose que mas deba configurar para que funcionen bien, alguna
> idea?
> _______________________________________________
> Lista de Correo l-talug
> Grupo de Usuarios Linux de Tchira - Venezuela
> Para enviar un Correo a la lista: [email protected]
> Para suscribirse o desuscribirse: 
> http://listas.velug.org.ve/mailman/listinfo/l-talug
> Visitanos en el Canal IRC #talug en irc.freenode.net
>
_______________________________________________
Lista de Correo l-talug
Grupo de Usuarios Linux de Tchira - Venezuela
Para enviar un Correo a la lista: [email protected]
Para suscribirse o desuscribirse: 
http://listas.velug.org.ve/mailman/listinfo/l-talug
Visitanos en el Canal IRC #talug en irc.freenode.net

Responder a