Free Comodo ModSecurity Rules - Worth It?
I'm running several Wordpress sites, MySQL replication, custom PHP applications doing various things like rsyncing files, etc.
I'm also running Configserver Firewall / LFD.
Wondering if anyone has experience installing the Free Comodo Modsecurity Rules? Are they conservative enough to not cause problems or in most cases is there a high probability for issues (false positives, etc) and best to just leave it alone if I don't want to make my sys admin more time consuming working out the issues?
Also does anyone know if the Comodo Modsecurity rules prevent Wordpress Brute Force attacks (across all Wordpress sites running on the server) ?
-
Yes they block Brute Force attacks . If the wp-Admin password is entered several times incorrectly, the IP will be blocked. Also, if an IP addresses a specific number of 404 pages, its IP will be blocked 0 -
As noted by @httpdocs, they do indeed provide brute force rules for wp-admin but keep in mind that they are a 3rd party vendor and not something provided by cPanel so any issues with the 3rd party vendor would be needed to be addressed with Comodo 0 -
Comodo mod_security rules are ok. We are using them. Very few false positives. 0 -
We too have used the OWASP ruleset and no, there haven't been many false positives nor has using them resulted a lot of extra work for our team. 0
Please sign in to leave a comment.
Comments
4 comments