ModSecurity

Introduction

ModSecurity(TM) is an open source intrusion detection and prevention engine for web applications. It can also be called an web application firewall. It operates embedded into the web server, acting as a powerful umbrella, shielding applications from attacks.

ModSecurity integrates with the web server, increasing your power to deal with web attacks. Some of its features worth mentioning are:

ModSecurity can be used to detect attacks, or to detect and prevent attacks.

Licensing

ModSecurity is available under two licenses. Users can choose to use the software under the terms of the GNU General Public License (http://www.gnu.org/licenses/gpl.html), as an Open Source / Free Software product. Alternatively, a variety of commercial licenses is available: end-user licenses for individual or site-wide deployment, OEM licenses for closed-source distribution with applications, web servers, or security appliances. For more information on commercial licensing please contact Thinking Stone.

Thinking Stone Tel: +44 20 8141 2161 Fax: +44 87 0762 3934 http://www.thinkingstone.com

Note

ModSecurity and mod_security are trademarks of Thinking Stone.

Acknowledgements

This module would not be possible without the fine people who have created the Apache Web server, and the fine people who have spent many hours building the Apache modules I used to learn Apache module programming from.

Contact

ModSecurity is developed by Ivan Ristic and Thinking Stone. Comments and feature requests are welcome. Please send your emails to .

Note

Please do not send support requests to my personal email address. I do spend time responding to support queries but I don't respond privately any more. Doing so prevents other users from using mail archives to find answers for themselves. If you need answers quickly or you want guaranteed response times consider purchasing commercial support from Thinking Stone.