Skip to main content

Editor to tame mod_security rulesets

Project description

- It doesn’t, but: no warranty and such. - Also, hasn’t many features yet.


  • Simple GUI editor for SecRuleRemoveById settings
  • Tries to suggest false positives from error and audit logs
  • And configure mod_security and CoreRuleSet variables.
  • Runs locally, via ssh -X forwarding, or per modseccfg ssh:/ remoting.



  • You can install this package locally or on a server:

    pip3 install modseccfg
  • And your distro must provide a full Python installaton and mod_security:

    sudo apt install python3-tk ttf-unifont libapache2-mod-security2

Start options

  • To run the GUI locally / on test setups:

  • Or with sshfs remoting directly to the servers filesystem:

    modseccfg root@vps5:/

    A little slower on startup, but allows live log inspection. Requires preconfigured ssh hosts and automatic pubkey authorization. Beware of the implicit ~/mnt/ point, if connecting as root.

Alternatively there’s also slow X11 forwarding (ssh -X vps modseccfg) or `xpra --start ssh:vps5 --start=modseccfg <>`__ to run it on on the server.


You obviously should have Apache + mod_security + CRS set up and running already (in DetectionOnly mode initially), to allow for log inspection and adapting rules.

  1. Start modseccfg (python3 -m modseccfg)
  2. Select a configuration/vhost file to inspect + work on.
  3. Pick the according error.log
  4. Inspect the rules with a high error count (→[info] button to see docs).
  5. [Disable] offending rules
    • Don’t just go by the error count however!
    • Make sure you don’t disable essential or heuristic rules.
    • Compare error with access log details.
    • Else craft an exception rule ([Modify] or →Recipes).
  6. Thenceforth restart Apache after testing changes (apache2ctl -t).

See also: usage remoting, or preconf/recipe setup, or the “FAQ”.


  • Preferrably do not edit default /etc/apache* files
  • Work on separated /srv/web/conf.d/* configuration, if available
  • And keep vhost settings in e.g. vhost.*.dir files, rather than multiple <VirtualHost> in one *.conf (else only the first section will be augmented).
  • Requires some setup for the recipes (notably *.preconf includes for vhosts), but not for basic rule disabling/modifications.

from project import meta

meta info
depends pysimplegui _, pluginconf, tkinter, mod-security, sshfs
compat Python ≥3.6, Apache 2.x, mod_security 2.9.x, CRS 3.x, BSD/Linux
compliancy XDG, pluginspec, !pep8, !desktop, !DND, !mallard, !netrc, !http_proxy, !nobackup, !PKG_INFO, !releases.json, !doap, !packfile
system usage opportune shell invokes (sshfs, find, cat, dpkg, xdg-open)
paths ~/mnt/, ~/backup-config/, ~/.config/modseccfg/
testing few data-driven assertions, only manual UI and usage tests
docs minimal wiki, news, no man page
dev activity burst, temporary
state beta
support None
contrib mail, fossil DVCS (account or per bundles)

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Files for modseccfg, version 0.5.5.post5
Filename, size File type Python version Upload date Hashes
Filename, size modseccfg-0.5.5.post5-py3-none-any.whl (161.5 kB) File type Wheel Python version 3.7 Upload date Hashes View

Supported by

Pingdom Pingdom Monitoring Google Google Object Storage and Download Analytics Sentry Sentry Error logging AWS AWS Cloud computing DataDog DataDog Monitoring Fastly Fastly CDN DigiCert DigiCert EV certificate StatusPage StatusPage Status page