Re: modsecurity in packages a must use with old rulesets? secure?

2009-09-24 Thread Joachim Schipper
On Wed, Sep 23, 2009 at 08:09:53PM -0500, Matthew Young wrote: Hello, The website of gotroot.com states for their apache1 rules: Retired Rules (No longer updated) The initial question prevails: Is this the best appoach? How secure are these old rules? Adding mod_security shouldn't

Re: modsecurity in packages a must use with old rulesets? secure?

2009-09-24 Thread Paul de Weerd
On Thu, Sep 24, 2009 at 10:42:58AM +0200, Joachim Schipper wrote: | On Wed, Sep 23, 2009 at 08:09:53PM -0500, Matthew Young wrote: | Hello, | | The website of gotroot.com states for their apache1 rules: Retired Rules | (No longer updated) | | | The initial question prevails: Is this the

Re: modsecurity in packages a must use with old rulesets? secure?

2009-09-24 Thread Joachim Schipper
On Thu, Sep 24, 2009 at 11:00:35AM +0200, Paul de Weerd wrote: On Thu, Sep 24, 2009 at 10:42:58AM +0200, Joachim Schipper wrote: | On Wed, Sep 23, 2009 at 08:09:53PM -0500, Matthew Young wrote: | Hello, | | The website of gotroot.com states for their apache1 rules: Retired Rules | (No

Re: modsecurity in packages a must use with old rulesets? secure?

2009-09-24 Thread Gonzalo Lionel Rodriguez
2009/9/24 Joachim Schipper joac...@joachimschipper.nl: On Thu, Sep 24, 2009 at 11:00:35AM +0200, Paul de Weerd wrote: On Thu, Sep 24, 2009 at 10:42:58AM +0200, Joachim Schipper wrote: | On Wed, Sep 23, 2009 at 08:09:53PM -0500, Matthew Young wrote: | Hello, | | The website of gotroot.com

modsecurity in packages a must use with old rulesets? secure?

2009-09-23 Thread Matthew Young
Hello, I just installed mod_security from packages for the apache1 in base (4.5) . I went into modsecurity.org and noticed that their ModSecurity Core Rulset (

Re: modsecurity in packages a must use with old rulesets? secure?

2009-09-23 Thread Gonzalo Lionel Rodriguez
Matt, Try this http://www.gotroot.com/downloads/ftp/mod_security/apache1/apache1-gotrootrules-latest.tar.gz Works fine for me. 2009/9/23 Matthew Young myoung24...@gmail.com: Hello, I just installed mod_security from packages for the apache1 in base (4.5) . I went into modsecurity.org and

Re: modsecurity in packages a must use with old rulesets? secure?

2009-09-23 Thread Matthew Young
Hello, The website of gotroot.com states for their apache1 rules: Retired Rules (No longer updated) The initial question prevails: Is this the best appoach? How secure are these old rules? --Matt On Wed, Sep 23, 2009 at 5:47 PM, Gonzalo Lionel Rodriguez gonz...@sepp0.com.ar wrote: Matt,