ms133 发表于 2018-11-27 08:42:16

Debian下Apache2安装与设置 一 ZT-steven 业精于勤荒于嬉,行成于思毁于随

# 检测内容长度以避免堆溢出***  
SecFilterForceByteRange 32 254 =>SecFilterForceByteRange 32 126
  
# debug设置
  
SecFilterDebugLevel 9 =>SecFilterDebugLevel 0
  
# 设置缺省的动作
  
SecFilterDefaultAction "deny,log,status:499" =>SecFilterDefaultAction "deny,log,status:404"
  
# 把设置传递给子目录
  
SecFilterInheritance Off
  
# Redirect user on filter match
  
# 当匹配sh的时候,重新定向到一个特殊的警告页面,该页面是自行编写的,写些警告的话让***者知难而退,该段先不要生效,等到相关配置配好之后再失效不迟。记住在配好之后要使之生效。
  
#SecFilter sh redirect:http://localhost/hack/warning.htm
  
# Prevent OS specific keywords
  
#过滤一些敏感的东西,我们使用*是为了***者使用/etc/./passwd来绕开检测
  
SecFilter /etc/passwd =>SecFilter /etc/*passwd
  
SecFilter /bin/*sh
  
# Very crude filters to prevent SQL injection attacks
  
# 防止SQL插入(SQL Injection)***
  
SecFilter "delete[[:space:]]+from"
  
SecFilter "insert[[:space:]]+into"
  
SecFilter "select.+from"
  
SecFilter "select[[:space:]]+from"
  
SecFilter "union[[:space:]]+from"
  
==== mod-security.conf 文件内容结束====
  



页: [1]
查看完整版本: Debian下Apache2安装与设置 一 ZT-steven 业精于勤荒于嬉,行成于思毁于随