core-rules


Techniques for a CRS 4 Migration When Things Get Hairy   Recently updated !

Here at netnea, our job is to help customers run and manage their ModSecurity / OWASP CRS based WAFs. Right now, the migration of existing installations to CRS 4 is a major concern for many of them. And it rarely comes alone: There are business constraints, tight schedules, a lack of resources (and in-house know-how), […]


The netnea-CRS-Upgrading-Plugin: A Real-World Migration

This is the third and final blog post of a three-part series describing the new CRS-upgrading-plugin. In the previous two posts I introduced the new plugin (part one) and covered the technical implementation details (part two).This post walks through a real-world migration at one of our enterprise customers and the experiences gathered during the shift […]


Securing Drupal with ModSecurity and the Core Rule Set (CRS3)

The new Core Rule Set 3.0 (CRS3) release simplifies ModSecurity/Drupal integration tremendously. Here is a guide aimed at the Drupal community to learn how to work with ModSecurity. This guide and the rule file it is based on currently covers Drupal Core. Modules / Plugins are not yet supported. But count on the Drupal community […]