#Modsecurity
🐻 Un jour, un logiciel Libre : jour 5

Coraza : Un WAF Open Source écrit en Go, qui prend en charge l'ensemble de règles ModSecurity SecLang et est 100 % compatible avec l'ensemble de règles de base OWASP v4.
April 5, 2025 at 6:30 PM
A Go-based HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity
#golang

github.com/casbin/caswaf
GitHub - casbin/caswaf: HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity, online demo: https://door.caswaf.com
HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity, online demo: https://door.caswaf.com - casbin/caswaf
github.com
November 6, 2025 at 6:06 AM
AlmaLinux 10.3 Beta “Mauve Lion” is now available!
🔹 ModSecurity returns
🔹 Podman 6 moves container configuration out of /etc
🔹 New compiler toolsets
🔹 New language runtimes
🔹 Improved security

https://almalinux.org/blog/2026-09-10-announcing-103-beta/?utm_medium=social&utm_source=bluesky
September 14, 2026 at 6:08 PM
2024-01-25にTrustwaveからOWASPに移管。へー知らなかった。
ModSecurityについて調べた · hnakamur's blog
hnakamur.github.io
February 10, 2024 at 8:26 AM
c'est l'enfer, on a des pages qui ne doivent pas être crawlées, ça fonctionnait bien avec les moteurs de recherche, pas avec ces saloperies écrites par des guignols en vibe coding, on a passé des jours à faire du trial and error sur modsecurity jpp
November 30, 2025 at 11:52 AM
Mala praxis no avisar, tot i això jo deixaria el ModSecurity actiu i només posar l'excepció per l'OAuth com expliquen aquí ourcodeworld.com/articles/rea...
How to disable ModSecurity Rule in Plesk (Google OAuth2 redirect callback blocked by ModSecurity)
Learn how to disable the rule of ModSecurity in Plesk that prevents your Google OAuth2 redirect callback page from working properly.
ourcodeworld.com
September 18, 2024 at 7:11 AM
Later today, I'll be hosting a ModSecurity / CRS community call

luma.com/8yc1p543

We'll be talking about success metrics, WAF testing and other integration questions.
CRS Community Call · Luma
A video call where the CRS dev team gets to meet their community face-to-face. A place for information exchange and questions for both newbies and experienced…
luma.com
September 22, 2025 at 8:07 AM
CVE-2025-27110: ModSecurity Vulnerability Leaves Web Applications Exposed
CVE-2025-27110: ModSecurity Vulnerability Leaves Web Applications Exposed
Understand the implications of CVE-2025-27110 on web application security and how it may allow attacks to bypass defenses.
securityonline.info
March 1, 2025 at 7:30 AM
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out 👉 coreruleset.org/2026...
#WAF #AppSec #OWASP #ModSecurity
February 18, 2026 at 1:43 AM
E pensar que tudo começou lá na época do modsecurity, hein? O tempo passa e as práticas são as mesmas, só mudam as ferramentas. Aprenda a base e não precisará ficar nessa corrida maluca de achar que tudo "muda" toda hora.
September 4, 2024 at 10:15 AM
🔧 ¿El error 403 te da dolores de cabeza? Descubre cómo diagnosticar si es ModSecurity o un problema de configuración y soluciona el bloqueo en tu web. Todo explicado paso a paso en nuestro nuevo post. Lee más aquí 👉 k3bone.com/blog/2024/11... #hosting #cPanel #seguridad
¿ModSecurity o un problema de configuración? Cómo diagnosticar y corregir el error 403 sin complicaciones - k3bone
¿ModSecurity o un problema de configuración? Cómo diagnosticar y corregir el error 403 sin complicaciones - k3bone - Hosting SSD en España con cPanel, LiteSpeed y WordPress
k3bone.com
November 15, 2024 at 12:21 PM
My 12 Apache / ModSecurity / OWASP CRS tutorials receive about 8k unique visitors per month.

www.netnea.com/cms/apache-t...
Apache / ModSecurity Tutorials – Welcome to netnea
www.netnea.com
December 1, 2024 at 6:58 PM
La que m'ha liat el proveïdor de hosting activant unilateralment ModSecurity al servidor amb els webs que tenen aplicacions Oauth de Google no té nom. La mare que els va parir!
September 18, 2024 at 7:06 AM
Defensive Linux Security Tools 🛡
🕸 WAFs
- ModSecurity
- Curiefense
- BunkerWeb
- Coraza
December 24, 2025 at 6:58 PM
New WAFFLED Attack Exploits AWS, Azure, Cloud Armor, Cloudflare, and ModSecurity WAFs
New WAFFLED Attack Exploits AWS, Azure, Cloud Armor, Cloudflare, and ModSecurity WAFs
cybersecuritynews.com
July 18, 2025 at 9:20 AM
정말 지긋지긋하지만, SSH 무차별 대입을 진압하니까 xmlrpc.php(워드프레스 API 엔드포인트)에 대한 무차별 공격이 이어지고 있어 오늘도 방화벽이 잠잠할 날이 없습니다. 처음에는 ModSecurity WAF를 로그만 남기는 상태로 상태를 볼 생각이었으나 같은 패턴의 공격이 너무 늘어서 차단을 켭니다. 이에 따라, 오탐으로 만에 하나 열려야 되는 페이지가 안열리는 등, 한마디로 사이트가 망가질 수 있습니다. 시각과 IP 앞 6자리를 알려주시면 최대한 고쳐보겠습니다. 미리 감사드립니다.
August 2, 2025 at 2:52 PM
Installer et configurer ModSecurity (le WAF de l'OWASP) et bloquer efficacement les attaques (XSS, injection SQL, etc.).

#nginx #ModSecurity #WAF #SécuritéWeb #Linux #Tuto #CultureLinux
💥 NGINX + ModSecurity : détection & blocage des attaques 🚀
YouTube video by CultureLinux
www.youtube.com
October 28, 2025 at 4:03 PM
Fortifying #Linux Web Applications: Mastering OWASP ZAP and ModSecurity for Optimal Security | Linux Journal www.linuxjournal.com/content/fort...
Fortifying Linux Web Applications: Mastering OWASP ZAP and ModSecurity for Optimal Security | Linux Journal
www.linuxjournal.com
November 30, 2024 at 9:52 AM
Security firm Sicuranext has built and released Karna, a new open-source WAF engine

blog.sicuranext.com/k-karna-we-b...
क Karna: we built our own WAF. Modern, Fast and Free.
We replaced ModSecurity with Karna, our open-source WAF engine in Lua and C running as a Kong plugin. CRS-compatible, MCP-aware, can sanitize instead of blocking, and 2 to 4 times faster than ModSecur...
blog.sicuranext.com
June 9, 2026 at 2:37 PM
⚙️ SSD-Powered cPanel Web Hosting – Up to 25x Faster
blog.radwebhosting.com
September 14, 2026 at 4:30 AM
#LiteSpeedWebServer: #OpenLiteSpeed a #LiteSpeedEnterprise

srovnání, studie, nasazení s CMS #WordPress, #LSCache a návody k max. využití cachování, event-driven architektury, .htaccess, ModSecurity

danielberanek.cz/tags/litespe...

#SEO #technickeSEO
April 10, 2025 at 6:40 PM
We set up 10-15 very simple modsecurity WAG rules targeted at tech we do NOT use, and integrated the log with fail2ban. Very effective to counter the majority of such attempts with zero chance of blocking legitimate traffic.
December 6, 2024 at 5:41 PM
corazawaf/coraza: OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
corazawaf/coraza: OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
https://github.com/corazawaf/coraza
github.com
January 13, 2026 at 1:11 AM