Catch up on stories from the past week (and beyond) at the Slashdot story archive


Forgot your password?
Book Reviews

Submission + - ModSecurity 2.5 by Magnus Mischel

Martijn de Boer writes: "For a long time now the web has been served by Apache's webserver software, because the amount of servers and internet usage is still growing more and more important every day securing your server has become a task in the forefront of business. This book has been written to illustrate and educate you the ease of use and inner workings of the ModSecurity module for the most widespread webserver.

The cover reads “Prevent web application hacking with this easy-to-use guide” and sticks with this claim to provide you with a good pathway to secure your webserver. The book is aimed at system administrators ranging from enthusiasts running a webserver at home to your friendly administrators at a large company. Most of the book requires only familiarity with using the linux shell and basic Apache configurations, but earlier encounters with some technicalities like regular expressions may be of help during your reading period.

Throughout the chapters the author takes you from the different methods of installing ModSecurity and the basics of creating your first rules to the discovery and reporting of your possible intrusions. Generally providing solutions for example geolocating the origin of the hack, and automatically scanning uploaded files for viruses, the author Magnus Mischel proofs that his background in Internet Security makes his book a valuable asset to your bookshelf.
In the chapters found later in the book, the author shows how to use some commonly used tools to fingerprint your server and provides you with recipes on how to prevent these methods of gathering information about your server. There is also a lot of information about the impact of rules on the performance of your server. Because the impact is different in every situation, you will be guided around some tools to measure the performance and you will learn how to interpret this data.

Chapter 5 talks about Virtual Patching, a method of preventing misuse by intercepting bad traffic and creating a set of rules for this. This chapter is by far the best piece of information I have found on how this actually works, and how you implement such rules and configuration, and why you should use the method of virtual patching in your situation. Basically the author takes out all the question marks you will have about this method of quickly applying rules and provides a case which is fully illustrated with a lot of background information about the process of finding a insecure piece of code to solving this with a set of rules.

When Packt Publishing contacted me if I would like to review another book for them, I picked this one out of the new releases because using ModSecurity has never been a priority for me. After seeing the title and table of contents I realised that you can never start too early to dive into this subject, and start preventing misuse before it causes more trouble then you can handle, trouble always finds you at the worst times. The author has divided the book in logical chapters, and the depth of information builds up equally from beginning to end. For instance, the second chapter takes you trough the basics of regular expressions, but because you will encounter them during rule creation Appendix B will educate you with all specifics of creating those expressions.
As a developer running local test servers, I have found this book very interesting and a great resource on a for me grey area of server security. I am pleasantly surprised by the clarity of the book, the writing style makes you really want to dive into your webserver to apply your newly gained insight to ModSecurity."
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

ModSecurity 2.5 by Magnus Mischel

Comments Filter:

"I prefer the blunted cudgels of the followers of the Serpent God." -- Sean Doran the Younger