Nginx ModSecurity Tutorial | Nginx WAF

Поділитися
Вставка
  • Опубліковано 12 гру 2024

КОМЕНТАРІ • 71

  • @tiom28x
    @tiom28x 3 роки тому +11

    Alexis ,hope you read this mate. Just wanted to write that none of my lectures can explain in the way you do. Perspective of your lessons are on one of the highest levels. My route is Digital forensics and cybersecurity, and because of you I'm hungry for more knowledge. Big THANK YOU . DANKE

    • @HackerSploit
      @HackerSploit  3 роки тому +5

      Hello, thank you very much for your support. I am glad you find value in the videos. That is great, we have an upcoming series on forensics.

    • @tiom28x
      @tiom28x 3 роки тому

      @@HackerSploit I cant wait to learn more from you. If you have discord group or maybe planning to create one ,I'm in. The content , explanations, and the way you teach are seriously one of the best. I have so many questions ,that I'd like to ask you to put me on the right path (focus to go in right direction) regards.

  • @sameerakwc
    @sameerakwc 3 роки тому +3

    Awesome tutorial - first shot it worked like charm on nginx 1.18 and Ubuntu server 20.04 focal fossa ❤️ love it

    • @djebabliazakaria4593
      @djebabliazakaria4593 3 роки тому

      How People Get Infected With Malicious Word Document':
      ua-cam.com/video/E-Xc_bQyG2c/v-deo.html

  • @mohammadabdi1793
    @mohammadabdi1793 3 роки тому

    Thank goodness you’re back👊🏾👊🏾

  • @HackerSploit
    @HackerSploit  3 роки тому +1

    Documentation: www.linode.com/docs/guides/securing-nginx-with-modsecurity/

  • @martintovmassian5538
    @martintovmassian5538 Рік тому

    Excellent! Thank you for the step by step tour!

  • @Parendinate
    @Parendinate Рік тому

    its very clear guide. Thank you for high quality content

  • @memorysells
    @memorysells 3 роки тому +1

    Very detailed and informative. However, please check that the path mentioned in Step 3 of Configuring Modsecurity is incorrect. This can cause confusion for newbies because the path is not correct

    • @mohamedhabas7391
      @mohamedhabas7391 3 роки тому

      Hey , can you tell me how to get around this ?? please :) ?

  • @ChapalPuteh_
    @ChapalPuteh_ 9 місяців тому

    Thank you alexis, you make me curious on WAF … 😊

  • @timothylrobb
    @timothylrobb 6 місяців тому

    Thank you. This was very helpful.

  • @peopleyoumustknow1325
    @peopleyoumustknow1325 3 роки тому

    Thank you from Vietnam.

  • @aleejunaid
    @aleejunaid 3 роки тому +2

    Hi,
    My all 12 cores of my server shoots to 100% usage after turning the Modsecurity On. It works fine after turning it off.
    What is wrong?

  • @Mia-cutee
    @Mia-cutee 10 місяців тому +1

    does it work for ubuntu 22?

  • @binaryfire
    @binaryfire 3 роки тому

    Great video. What are your thoughts on NAXSI? Modsec has a huge performance hit. NAXSI is supposed to be a lot faster

  • @ThoriumHeavyIndustries
    @ThoriumHeavyIndustries 3 роки тому +1

    There is an error in your documentation in the section configure modsecurity. Either the path to copy or config from/to are wrong or you left a step to create the directories. Please, check. Thanks.

    • @rabbitcreative
      @rabbitcreative Рік тому +1

      Errors are sometimes put in on purpose. Makes it easier to sell support contracts. Also evil.

  • @realhomy
    @realhomy 3 роки тому +1

    LET'S GOOO we got 3 vids in one day

    • @mbm6048
      @mbm6048 3 роки тому +1

      Bro you beat me in a few seconds for the first comment .😅

    • @realhomy
      @realhomy 3 роки тому

      @@mbm6048 damn u were close congrats

  • @nicocolt
    @nicocolt 2 роки тому

    Perfect ! many thanks to you !

  • @sandraa-s6d
    @sandraa-s6d 4 місяці тому

    How to see the log file of preventions?

  • @danlegend3104
    @danlegend3104 3 роки тому +1

    If you were to do this for a friend/client and secure their server for their website what would be a fair price to charge as a freelance engineer? They already have a website the web designer just hasn’t secured or optimised anything.

    • @HackerSploit
      @HackerSploit  3 роки тому +1

      It depends on the scale of the project and cost factor. Do you charge per hour?

    • @danlegend3104
      @danlegend3104 3 роки тому +1

      @@HackerSploit hourly or per day which ever is cheaper for them, that’s usually how repeat business is kept over here in the Uk

    • @HackerSploit
      @HackerSploit  3 роки тому +1

      @@danlegend3104 Thank you for the clarification, in that case depending on your skill level I would suggest anywhere from 30-50$ per hour. This is just a rough estimate based on the nature of the work likely will be doing.

  • @anthonydelagarde3990
    @anthonydelagarde3990 2 роки тому

    Can please you list the tools you installed post the NGINx install

  • @mecrayavcin
    @mecrayavcin 2 роки тому

    Hi i have a question
    What if ubuntu is upgraded / updated , so maybe there can be a higher version of nginx (example 1.25) !
    (can nginx be upgraded if we upgrade Ubuntu version? I don't know this buy the way )
    So we composed module from nginx 1.14 nginx file
    Is tihs make a problem?

  • @christoferfrascarelli3944
    @christoferfrascarelli3944 3 роки тому +1

    can UFW and modsecurity coexist? or would it be better to use only one? Thanks a lot!!

  • @azizutkuozdemir
    @azizutkuozdemir 2 роки тому

    Is there some docker version which all tools enabled and still you can check what has been installed with dockerfile or so :)

  • @732_dipen4
    @732_dipen4 3 роки тому

    why you keep switching OS sometimes parrot sometimes kali sometimes ubuntu

  • @amirshadmani4830
    @amirshadmani4830 4 місяці тому

    Thank you alexis

  • @thinnadisoe4039
    @thinnadisoe4039 Рік тому

    how to host a static php website in nginx server

  • @imadedwis5658
    @imadedwis5658 2 роки тому

    Can you upload video waf nginx on centOS 8.5 ?

  • @drishalballaney
    @drishalballaney 3 роки тому

    3 videos in less than 2 hrs today?

  • @betterwithrum
    @betterwithrum Рік тому

    My only complaint is something this complicated should be automated with an Ansible playbook or Chef cookbook, IMHO

  • @mohanraam869
    @mohanraam869 3 роки тому

    What tool is used identify the defects in bug bounty please tell bro

  • @kossidoh
    @kossidoh 2 роки тому

    Hello. Thanks forthe video. I was installing the modsecurity for nginx but I run into trouble. This is the error message i got "adding module in /build/nginx-qDpDX0/nginx-1.18.0/debian/modules/http-geoip2
    ./configure: error: no /build/nginx-qDpDX0/nginx-1.18.0/debian/modules/http-geoip2/config was found"
    Can you help on this. the ubuntu system is 22. and there is no help on this on the internet.

    • @juantavarez9493
      @juantavarez9493 Рік тому

      Did you resolve this ? I'm facing the samething

  • @mbm6048
    @mbm6048 3 роки тому +1

    Cool awesome video

  • @cryptolicious3738
    @cryptolicious3738 3 роки тому

    cool video! is there a app or way to get notifications of IPs violating rules, what rule and what url and button to send to fail2ban jail? if not ill dev one

    • @HackerSploit
      @HackerSploit  3 роки тому +1

      Not yet, that is a great video idea. I will definitely work on this.

    • @cryptolicious3738
      @cryptolicious3738 3 роки тому

      @@HackerSploit , excellent , thanks! lets dev it together in flutter , u wanna, if nothings out there already?

  • @mazenn99
    @mazenn99 3 роки тому

    thank you very much

  • @h4cker
    @h4cker 3 роки тому +1

    I don't know why but You looks like my elder brother 😂 ...

  • @namansharma1330
    @namansharma1330 3 роки тому

    Can ece stream guy learn ethical hacking?

  • @kermitdaphrogge525
    @kermitdaphrogge525 3 роки тому +1

    Bro can you make a video "impact of AI in cybersecurity and future of jobs in cybersecurity" please?

  • @shubhamghosh2228
    @shubhamghosh2228 3 роки тому

    Missed your voice more than your videos. Lol 😅

  • @unly-trd
    @unly-trd 3 роки тому

    good video

  • @juul216
    @juul216 3 роки тому

    amazing

  • @enos5192
    @enos5192 3 роки тому

    Nobody finished the Video, I bet . Cuz it's just 3 minutes after Release 😂😂

  • @realhomy
    @realhomy 3 роки тому

    YESSIR

  • @dipadityadas
    @dipadityadas Рік тому

    just change the SELinux context thats it. No need of Mob Security.

  • @sajjadjafaribojd3189
    @sajjadjafaribojd3189 3 роки тому

    thank very much. very useful video .You speak very fast man ... a little slower please

  • @hirthicshyam9290
    @hirthicshyam9290 3 роки тому

    Hello

  • @faust9091
    @faust9091 3 роки тому

    First
    EDIT:Damn

  • @8080VB
    @8080VB 3 роки тому

    Hww k worked

  • @Ayush_kumar123
    @Ayush_kumar123 2 роки тому

    I have done everything as you have said, but after running the command "sudo nginx -t" to test nginx syntax, it throws an error saying modsecurity_rules_file" directive Rules error. File: /usr/local/modsecurity-crs/rules/REQUEST-922-MULTIPART-ATTACK.conf Then i removed the file and everything worked fine. But it is an important config file why is this happeing.