ModSecurity Community Console Application Tips

ModSecurity is a open source web application firewall. "With over 70% of all attacks now carried out over the web application level, organisations need every help they can get in making their systems secure. Web application firewalls are deployed to establish an external security layer that increases security, detects, and prevents attacks before they reach web applications."

ModSecurity console is a free tool (with limitation of up to 3 ModSecurity Sensors) to collect and analysis the ModSecurity logs. The main features include:

  1. Self-contained application that comes with an embedded web server and an embedded database.
  2. Collects logs and alerts from any number of remote sensors in real time.
  3. User interface provides support for sensor, alert, and transaction management.
  4. Runs on any platform that supports JDK/JRE 1.4 or better.
  5. Installs in a few minutes.
  6. Automated maintenance options keep the database at a manageable size.
  7. Sensor activity history.
  8. Alerting facilities.
  9. Reporting facilities. Nice and shiny reports in PDF format can be scheduled or produced on-demand. Automatic distribution via email.
  10. Automatic DNS and Geo IP resolution1.

When I put them to work together, it does a nice job for manage the web application firewall logs especially when you are tuning the ModSecurity rules in a production network. It will be very tough to handle the huge amount of alerts without a tool especially if you implement the Core Rule Set from ModSecurity.

One small tip to set the email reporting right is to put the email server ip into hosts file if the email server name is not resovlable from your dns system. If you don't do that, even when you put ip address into the email server field of ModSecurity Console, you will still encounter the following error:

class javax.mail.MessagingException: 501 5.0.0 HELO requires domain address

And it's tricky to find where to download the ModSecurity Console because you can not find a link from both the ModSecurity site and Breach site. But it does exist at this URL: http://www.breach.com/products/ModSecurity-Community-Console.html .

So good luck and happy pretecting your web application.

Thanks for sharing some tips!

Thanks for sharing some tips! According in some related researchabout ModSecurity does not give you much without a good rule set. However, good rule sets are time consuming to develop and require a lot of testing and tuning.

Hi,

Finally I found this page that talking about Console Application Tips because I have some problem with my app and I dont know what i'm going to do. read more

Thanks for the tips and

Thanks for the tips and tricks, I am about test the applications myself and am relying on the fact they are easy to install. I am not sure that I have the right system requirements though. Is there any way to verify that? I've already set a clean registry software to help my system have an optimum functionality.

the community console can't

the community console can't be found anywhere - I tried the above link and it redirects to another page where I can get a quote for the commercial version. I've googled hard to find the free one, it's gone, history.

reply

This is great they show to us the application tips. and they put here the some examples they give the ten tips. credit cards

reply

The article have post here is show to us about the Community Console Application Tips. This is great. flashlight mounts

Post new comment

  • Lines and paragraphs break automatically.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • You may post PHP code. You should include <?php ?> tags.

More information about formatting options