Re: [users@httpd] mod_evasive [OT?]

2022-03-11 Thread Darryl Philip Baker
Solved this by correctly compiling the mod_evasive source using apxs. Sorry for 
the noise on the list.

Darryl Baker, GSEC, GCLD  (he/him/his)
Sr. System Administrator
Distributed Application Platform Services
Northwestern University
4th Floor
2020 Ridge Avenue
Evanston, IL  60208-0801
darryl.ba...@northwestern.edu<mailto:darryl.ba...@northwestern.edu>
(847) 467-6674


From: Darryl Philip Baker 
Reply-To: Apache httpd Users 
Date: Thursday, March 10, 2022 at 9:34 AM
To: Apache httpd Users 
Subject: [users@httpd] mod_evasive [OT?]

I am trying to upgrade our webservers from RHEL7 to RHEL8. One third party 
module we use is mod_evasive. Searching for information I find that in 2020 it 
was in the EPEL repository for RHEL8/CentOS8 but it is no longer there. I have 
no problem building it from source if necessary. Where can I find the current 
source for it? Is there another module that is better for fending off DoS and 
DDoS attacks?

Darryl Baker, GSEC, GCLD  (he/him/his)
Sr. System Administrator
Distributed Application Platform Services
Northwestern University
4th Floor
2020 Ridge Avenue
Evanston, IL  60208-0801
darryl.ba...@northwestern.edu<mailto:darryl.ba...@northwestern.edu>
(847) 467-6674



Re: [users@httpd] mod_evasive [OT?]

2022-03-10 Thread Marc Serra
Hi Darryl,

Take a look at mod_security: https://github.com/SpiderLabs/ModSecurity

Not perfect for fending off DoS attacks, but provides a rate-limit option:
https://stackoverflow.com/questions/26409546/protecting-against-ddos-attacks-is-mod-security-and-the-owasp-rule-set-adequate

Missatge de Darryl Philip Baker  del dia
dj., 10 de març 2022 a les 16:35:

> I am trying to upgrade our webservers from RHEL7 to RHEL8. One third party
> module we use is mod_evasive. Searching for information I find that in 2020
> it was in the EPEL repository for RHEL8/CentOS8 but it is no longer there.
> I have no problem building it from source if necessary. Where can I find
> the current source for it? Is there another module that is better for
> fending off DoS and DDoS attacks?
>
>
>
> *Darryl Baker, *GSEC, GCLD  (he/him/his)
>
> Sr. System Administrator
>
> Distributed Application Platform Services
>
> *Northwestern University*
>
> 4th Floor
>
> 2020 Ridge Avenue
>
> Evanston, IL  60208-0801
>
> *darryl.ba...@northwestern.edu *
>
> (847) 467-6674 <+18474676674>
>
>
>


-- 
Marc Serra
Organització i Sistemes

-- 


   
  
  
  
 Manxa 1876, S.L.
Ctra. Les 
Tries, 85.17800 Olot (Girona)
*Tel. 972 27 45 30 www.manxa.com 
* 
  *Manxa 
Industrial *
 
  *Manxa Ferros *
   *Manxa Ferreteria i Parament de la Llar 
*
  

  



-- 


El contingut d’aquest correu electrònic i els seus annexos és 
estrictament confidencial. En el cas que no siguis el destinatari i hagis 
rebut aquest missatge per error, preguem que ho comuniquis al remitent i 
procedeixis a la seva eliminació, sense difondre, emmagatzemar o copiar el 
seu contingut. Imprimeix aquest correu només si és necessari.

El contenido 
de este correo electrónico y sus anexos es estrictamente confidencial. En 
el caso de que no seas el destinatario y hayas recibido este mensaje por 
error, rogamos lo comuniques al remitente y procedas a su eliminación, sin 
difundir, almacenar o copiar su contenido. Imprimir este correo solo si es 
necesario.

The content of this email and its attachments is strictly 
confidential. If you are not the recipient and you have received this 
message by mistake, please notify the sender and proceed to its 
elimination, without spreading, storing or copying its content. Print this 
email only if necessary.

Le contenu de cet e-mail et de ses pièces jointes 
est strictement confidentiel. Dans le cas où vous n'êtes pas le 
destinataire et avez reçu ce message par erreur, veuillez en informer 
l'expéditeur et procéder à sa suppression, sans diffuser, stocker ou copier 
son contenu. Imprimez cet e-mail uniquement si nécessaire.


Re: [users@httpd] mod_evasive [OT?]

2022-03-10 Thread Noelette Stout
I see that mod_evasive is in the Fedora (34) repo, so it may be in one of
the lesser used RHEL8 repos (didn't see it in appstream, though).

On Thu, Mar 10, 2022 at 8:34 AM Darryl Philip Baker <
darryl.ba...@northwestern.edu> wrote:

> I am trying to upgrade our webservers from RHEL7 to RHEL8. One third party
> module we use is mod_evasive. Searching for information I find that in 2020
> it was in the EPEL repository for RHEL8/CentOS8 but it is no longer there.
> I have no problem building it from source if necessary. Where can I find
> the current source for it? Is there another module that is better for
> fending off DoS and DDoS attacks?
>
>
>
> *Darryl Baker, *GSEC, GCLD  (he/him/his)
>
> Sr. System Administrator
>
> Distributed Application Platform Services
>
> *Northwestern University*
>
> 4th Floor
>
> 2020 Ridge Avenue
>
> Evanston, IL  60208-0801
>
> *darryl.ba...@northwestern.edu *
>
> (847) 467-6674 <+18474676674>
>
>
>


-- 
Noelette Stout
ITS Enterprise Applications - Senior Application Administrator
Idaho State University
E-mail: stounoel "at" isu "dot" edu
Desk: 208-282-2554


[users@httpd] mod_evasive [OT?]

2022-03-10 Thread Darryl Philip Baker
I am trying to upgrade our webservers from RHEL7 to RHEL8. One third party 
module we use is mod_evasive. Searching for information I find that in 2020 it 
was in the EPEL repository for RHEL8/CentOS8 but it is no longer there. I have 
no problem building it from source if necessary. Where can I find the current 
source for it? Is there another module that is better for fending off DoS and 
DDoS attacks?

Darryl Baker, GSEC, GCLD  (he/him/his)
Sr. System Administrator
Distributed Application Platform Services
Northwestern University
4th Floor
2020 Ridge Avenue
Evanston, IL  60208-0801
darryl.ba...@northwestern.edu
(847) 467-6674