Skip to main content

WARNING: THIS IS ALPHA STAGE QUALITY AND WILL MOST CERTAINLY DELETE YOUR APACHE CONFIGURATION (It doesn’t, but: no waranty and such.)

modseccfg

  • Simple GUI editor for SecRuleDisableById settings

  • Tries to suggest false positives from error and audit logs

  • (And a few options to configure mod_security and CRS variables.)

  • Obviously requires ssh -X forwarding, or preparing config rules on a local test setup, and *.conf files to be writable by current user (running as root is not advised).

Usage

image0

You obviously should have Apache(2.x) + mod_security(2.9) + CRS(3.x) set up and running already (in DetectionOnly mode initially), to allow for log inspection and adapting rules.

  1. start modseccfg (python3 -m modseccfg)

  2. Select a configuration/vhost file to inspect + work on.

  3. Pick the according error.log

  4. Inspect the rules with a high error count.

  5. [Disable] offending rules (if they’re not essential to CRS, or would likely poke holes into useful protections).

  6. Thenceforth restart Apache after testing changes (apache2ctl -t).

Notes

  • Preferrably do not edit default /etc/apache* files

  • Work on separated /srv/web/conf.d/* configuration, if available

  • And keep vhost settings in e.g. vhost.*.dir files, rather than multiple <VirtualHost> in one *.conf (else only the first section will be augmented).

Missing features

  • Doesn’t process any audit.log yet.

  • Can’t classify wrapped (<Location> or other directives) rules yet.

  • No rule information dialog.

  • No SecOption editor yet.

  • No CRS settings (setvar:crs…) editor yet.

  • Recipes are not worth using yet.

  • No sudo usage.

  • No support for nginx or mod_sec v3.

  • No support for Windows setups. (Would work, but no interest in user support.)

Metadata

Release files for modseccfg 0.0.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for modseccfg 0.0.9
File Interpreter ABI Platform
modseccfg-0.0.9-py3-none-any.whl Python 3 none any Details

Release files / modseccfg-0.0.9-py3-none-any.whl

Download URL modseccfg-0.0.9-py3-none-any.whl
Size 38.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5ca2817080652bd5af319abd8cefa3cb3d4769614d87f6850d5986718d03dabb
BLAKE2b-256 checksum
How to use checksums
1fa4b70074d2bc3aa1c31dc372555a0cf51ac221f4bda730afe825f042df086d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via Python-urllib/3.7

Release history Release notifications | RSS feed

0.7.3

1 release file

0.7.0

1 release file

0.6.3

1 release file

0.6.0

1 release file

0.5.0

1 release file

0.4.1

1 release file

0.4.0

1 release file

0.3.1

1 release file

0.3.0

1 release file

0.2.0

1 release file

0.1.0

1 release file

This release

0.0.9 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page