This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Modsecurity crs 10 config.conf
The data within this conf file may be specified within Apache virtual host containers. The following ModSecurity directives are set within this file -
SecRuleEngine SecRequestBodyAccess SecResponseBodyAccess SecResponseBodyMimeType SecResponseBodyLimit SecResponseBodyLimitAction SecDefaultAction SecUploadDir SecUploadKeepFiles SecAuditEngine SecAuditLogRelevantStatus SecAuditLogType SecAuditLog SecAuditLogParts SecCookieFormat SecRequestBodyInMemoryLimit SecDebugLog SecDebugLogLevel SecTmpDir
See the | ModSecurity Reference Manual for directive documentation.
PROJECT INFORMATION | |||||||
---|---|---|---|---|---|---|---|
Project Name | OWASP ModSecurity Core Rule Set Project | ||||||
Short Project Description |
The purpose of this project is the documentation and development of the ModSecurity Core Rule Set. Unlike intrusion detection and prevention systems, which rely on signature specific to known vulnerabilities, the Core Rules are based on generic rules in order to provide protection from zero day and unknown vulnerabilities often found in web applications, which are in most cases custom coded. | ||||||
Key Project Information |
Project Leader |
Project Contibutors |
Mailing List |
License |
Project Type |
Sponsor |
Release Status | Main Links | Related Projects |
---|---|---|
add here. |
ModSecurity-Open Source Web Application Firewall |