<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: gotroot modsecurity Rules for Apache - Anti-spam and Security</title>
	<atom:link href="http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 08 Jan 2009 20:42:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sir Henry</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-95079</link>
		<dc:creator>Sir Henry</dc:creator>
		<pubDate>Tue, 08 Jan 2008 16:55:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-95079</guid>
		<description>@linuxamp:

I, too, am intrigued to find out what was the root cause of the issues you experienced.  Should you have the time, please post them here.</description>
		<content:encoded><![CDATA[<p>@linuxamp:</p>
<p>I, too, am intrigued to find out what was the root cause of the issues you experienced.  Should you have the time, please post them here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: goodpeople</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-94403</link>
		<dc:creator>goodpeople</dc:creator>
		<pubDate>Mon, 07 Jan 2008 14:56:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-94403</guid>
		<description>@Linuxamp

It would be nice if you could dig up what was going on. I am planning to play with this sometime later this week.</description>
		<content:encoded><![CDATA[<p>@Linuxamp</p>
<p>It would be nice if you could dig up what was going on. I am planning to play with this sometime later this week.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: linuxamp</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-94247</link>
		<dc:creator>linuxamp</dc:creator>
		<pubDate>Mon, 07 Jan 2008 06:57:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-94247</guid>
		<description>I ran mod_security for a while but noticed that some portions of my webapp (drupal+gallery2) broke.  I don't recall exactly what broke since it was a while ago but it was significant enough for me finally decide to disable mod_security.</description>
		<content:encoded><![CDATA[<p>I ran mod_security for a while but noticed that some portions of my webapp (drupal+gallery2) broke.  I don&#8217;t recall exactly what broke since it was a while ago but it was significant enough for me finally decide to disable mod_security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-93970</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Sun, 06 Jan 2008 21:31:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-93970</guid>
		<description>Wow great post. Can really use this.</description>
		<content:encoded><![CDATA[<p>Wow great post. Can really use this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sir Henry</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-92976</link>
		<dc:creator>Sir Henry</dc:creator>
		<pubDate>Fri, 04 Jan 2008 15:36:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-92976</guid>
		<description>@Pantagruel

Yet another illustration of how it is so difficult to balance security and usability.</description>
		<content:encoded><![CDATA[<p>@Pantagruel</p>
<p>Yet another illustration of how it is so difficult to balance security and usability.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-92841</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Fri, 04 Jan 2008 10:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-92841</guid>
		<description>fak3r has a good point. An extensive rule set will definitely slow down the response (especially on a overloaded server or less powerful server). To my opinion this is a small price you pay for some added security (and a nice excuse to upgrade hardware, making this hardware junkie even happier ;) )

hardening your Linux server is a good thing, hardening apache (try Google millions of howto's) is a must.

@fak3r, do you have a good link to sudokin, Google only burps out some blog messages (and no real usable stuff). Up to now I've been using www.hardened-php.net/suhosin/index.html , tutorial(s) on www.howtoforge.com and it's always a good thing to have another added layer of protection.</description>
		<content:encoded><![CDATA[<p>fak3r has a good point. An extensive rule set will definitely slow down the response (especially on a overloaded server or less powerful server). To my opinion this is a small price you pay for some added security (and a nice excuse to upgrade hardware, making this hardware junkie even happier <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> )</p>
<p>hardening your Linux server is a good thing, hardening apache (try Google millions of howto&#8217;s) is a must.</p>
<p>@fak3r, do you have a good link to sudokin, Google only burps out some blog messages (and no real usable stuff). Up to now I&#8217;ve been using <a href="http://www.hardened-php.net/suhosin/index.html" rel="nofollow">http://www.hardened-php.net/suhosin/index.html</a> , tutorial(s) on <a href="http://www.howtoforge.com" rel="nofollow">http://www.howtoforge.com</a> and it&#8217;s always a good thing to have another added layer of protection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kaneda</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-92820</link>
		<dc:creator>kaneda</dc:creator>
		<pubDate>Fri, 04 Jan 2008 10:18:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-92820</guid>
		<description>Argh - download links are broken on the gotroot website, do you guys have a mirror instead?</description>
		<content:encoded><![CDATA[<p>Argh - download links are broken on the gotroot website, do you guys have a mirror instead?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fak3r</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-92375</link>
		<dc:creator>fak3r</dc:creator>
		<pubDate>Thu, 03 Jan 2008 16:06:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-92375</guid>
		<description>I've posted here about mod_security before, it's a great tool, but it if you pile on all of these rules it will slow page loads significantly.  Best is to use mod_sec core rules, and pepper in some got root rules that look useful.

Oh, and patch PHP with sudokin first.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve posted here about mod_security before, it&#8217;s a great tool, but it if you pile on all of these rules it will slow page loads significantly.  Best is to use mod_sec core rules, and pepper in some got root rules that look useful.</p>
<p>Oh, and patch PHP with sudokin first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sir Henry</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-92307</link>
		<dc:creator>Sir Henry</dc:creator>
		<pubDate>Thu, 03 Jan 2008 12:52:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-92307</guid>
		<description>I just built a server for my director that will serve his website from home.  Although Apache is installed, I cautioned him about doing so when being an absolute neophyte in the ways of Linux and Apache.  This will be awesome for him and hopefully get him learned on a thing or two about Apache and security.  Thanks for posting this.</description>
		<content:encoded><![CDATA[<p>I just built a server for my director that will serve his website from home.  Although Apache is installed, I cautioned him about doing so when being an absolute neophyte in the ways of Linux and Apache.  This will be awesome for him and hopefully get him learned on a thing or two about Apache and security.  Thanks for posting this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: goodpeople</title>
		<link>http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/comment-page-1/#comment-92261</link>
		<dc:creator>goodpeople</dc:creator>
		<pubDate>Thu, 03 Jan 2008 11:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/gotroot-modsecurity-rules-for-apache-anti-spam-and-security/#comment-92261</guid>
		<description>Oh wow! am I going to have fun with this one...</description>
		<content:encoded><![CDATA[<p>Oh wow! am I going to have fun with this one&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
