Skip to main content

Comodo CWAF


cd /usr/src
rm -rf /usr/src/comodo*
 DOwnload
 https://docs.google.com/uc?export=download&id=0B_Z7t7PO4imFMU1mVG52c3VGM0k
tar xvzf comodobr.tar.gz
cp -pa comodo/cwaf_catalog.cgi /usr/local/cpanel/whostmgr/cgi
cp -pa comodo/addon_cwaf.cgi /usr/local/cpanel/whostmgr/cgi
cp -pa comodo/cwaf /usr/local/cpanel/whostmgr/cgi
cp -pa comodo/cwaf_sharedlib.pl /usr/local/cpanel/whostmgr/cgi
cp -pa comodo/addon_cwaf.conf /var/cpanel/apps
cp -pa comodo/cwaf_var/cwaf /var/cpanel
cp -pa comodo/perl5 /opt/cpanel/
/usr/local/cpanel/bin/register_appconfig /var/cpanel/apps/addon_cwaf.conf
rm -rf /var/cpanel/cwaf/rules/modsec_nagios.conf
mv /usr/local/apache/conf/modsec2.conf /usr/local/apache/conf/modsec2.conf.$(date +%d-%m-%y)
rm -rf modsec2.conf
Download and update

 https://docs.google.com/uc?export=download&id=0B_Z7t7PO4imFSEI5WDFWTHg4eGs

yes | mv /usr/local/apache/conf/modsec2.user.conf /usr/local/apache/conf/modsec2.user.conf.`date +%h-%d-%y-%s`

DOwnload
 https://docs.google.com/uc?export=download&id=0B_Z7t7PO4imFdnFSMTZMWEFsNzA

chmod 600 /usr/local/apache/conf/modsec2.user.conf
sed -i '/^.*modsec2_asl.conf/s/^/#/g' /usr/local/apache/conf/modsec2.user.conf
mkdir /var/log/CWAF
touch /var/log/CWAF/utils.log
cp modsec2.conf /usr/local/apache/conf/
chown root. /usr/local/apache/conf/modsec2.conf
chmod 600 /usr/local/apache/conf/modsec2.conf
/etc/init.d/httpd graceful
/var/cpanel/cwaf/scripts/update-client.pl

Comments

Popular posts from this blog

WiFI connection

    root@kali:~# iw dev root@kali:~# ip link set wlan0 up root@kali:~# iw wlan0 scan root@kali:~# wpa_passphrase blackMOREOps >> /etc/wpa_supplicant.conf root@kali:~# wpa_supplicant -i wlan0 -c /etc/wpa_supplicant.conf root@kali:~# iw wlan0 link root@kali:~# dhclient wlan0 root@kali:~# ping 8.8.8.8 (Where wlan0 is wifi adapter and blackMOREOps is SSID) (Add Routing manually) root@kali:~# ip route add default via 10.0.0.138 dev wlan0    

Modsecurity block rule for XMLRPC and wp-login attack

SecAction phase:1,nolog,pass,initcol:ip=%{REMOTE_ADDR},initcol:user=%{REMOTE_ADDR},id:5000134  <Locationmatch "/wp-login.php">  SecRule user:bf_block "@gt 0" "deny,status:401,log,id:5000135,msg:'ip address blocked for 5 minutes, more than 10 login attempts in 3 minutes.'"  SecRule RESPONSE_STATUS "^302" "phase:5,t:none,nolog,pass,setvar:ip.bf_counter=0,id:5000136"  SecRule RESPONSE_STATUS "^200" "phase:5,chain,t:none,nolog,pass,setvar:ip.bf_counter=+1,deprecatevar:ip.bf_counter=1/180,id:5000137"  SecRule ip:bf_counter "@gt 10" "t:none,setvar:user.bf_block=1,expirevar:user.bf_block=300,setvar:ip.bf_counter=0"  </Locationmatch>  SecAction phase:1,nolog,pass,initcol:ip=%{REMOTE_ADDR},initcol:user=%{REMOTE_ADDR},id:5000234  <Locationmatch "/xmlrpc.php">  SecRule user:bf_block "@gt 0" "deny,status:401,log,id:5000235,msg:'ip address blocked for 5 m...

Apache tuning documentation

Apache bench marking ======================= Things or checklist to be considered before the test     CPU: avoid power-saving mode. cpufreq-set -g performance.     File descriptors: raise the limit to (at least) the number of concurrent connections you wish to handle, using ulimit -n in your shell, or setrlimit(RLIMIT_NOFILE) in your server. Beware, some systems forbid you to raise the limit, you might need to investigate a bit to find how to unlock it.     Disable the logs of your server (you do not want to lose time logging thousands of requests instead of answering them).     Raise /proc/sys/net/somaxconn to the number of concurrent connections you want to handle. To understand why this is necessary, read the technical report or the excellent paper Measuring the Capacity of a Web Server (Banga and Druschel, Usenix 97). More on the fascinating topic of the accept() queue can be found in accept()able Strategies for Im...