Skip to content

ModSecurity - CRS4 Rules

ℹ️ Opened from Application Modules - this module page is reached from the Module Manager grid (/admin/module-manager), not from a dedicated sidebar item.

The ModSecurity - CRS4 Rules page provides detailed information about the CRS4 rule set module for MyApache. This module enhances your server’s web application firewall by applying a predefined set of OWASP security rules.

ModSecurity - CRS4 Rules

Overview

This module is part of the MyApache ecosystem and delivers a comprehensive set of custom security rules derived from the OWASP Core Rule Set (CRS). It is intended to help protect web applications from a wide range of threats with minimal configuration required.

URL

/admin/modules/myapache-crs4-modsecurity-rules

Description

MyApache ModSecurity Rule Set provides a set of custom security rules for Apache servers to enhance web application security.

The OWASP CRS is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls. It aims to protect web applications from a wide range of attacks, including the OWASP Top Ten, with a minimum of false alerts. CRS provides protection against many common attack categories, including SQL Injection, Cross Site Scripting, Local File Inclusion, etc.

Features

  • Custom security rules
  • Protection against common web attacks
  • Easy integration with Apache servers

Installation

Install the module from the Application Modules page (/admin/module-manager). Once installed, the OWASP CRS4 rule set is registered with ModSecurity: its rule files appear under MyApache ModSecurity Rules with vendor CRS4 (for example REQUEST-930-APPLICATION-ATTACK-LFI.conf, REQUEST-942-APPLICATION-ATTACK-SQLI.conf), where each can be toggled on or off. ModSecurity itself is configured on MyApache ModSecurity Configuration.

Module Management

  • Uninstall - removes the CRS4 rule set from the panel (available from the module page).