ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis. With over 10,000 deployments world-wide, ModSecurity is the most widely deployed WAF in existence. (by SpiderLabs)

ModSecurity Alternatives

Similar projects and alternatives to ModSecurity based on common topics and language

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a better ModSecurity alternative or higher similarity.

Suggest an alternative to ModSecurity

Reviews and mentions

Posts with mentions or reviews of ModSecurity. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2021-08-15.
  • Bulletproof at home hosting?
    reddit.com/r/TOR | 2021-08-15
    When it comes to your application: I don't know how tech-savvy you are, and I'm not sure if you're worried about someone breaking into your webapp, but you could look into setting up security extentions like snuffleupagus (PHP) and SpiderLab's ModSecurity WAF for Apache and nginx for which OWASP has a great, free ruleset
  • How to implement WAF on Kong Ingress controller? (like ModSecurity v3)
    ModSecurity (v3/master): https://github.com/SpiderLabs/ModSecurity
  • Best free security plugin for WP website?
    reddit.com/r/Wordpress | 2021-03-12
    I would recommend mod security which can be installed as a module for most web services like nginx and apache (and is open source). You can use the OWASP ruleset with some additional wordpress specific rulesets.
  • AWS SQL Injection (?)
    Looks like the webserver has a Web application firewall installed (WAF). My would guess this https://github.com/SpiderLabs/ModSecurity. Has nothing to do with AWS database per se, the WAF is running on the server along Apache, as a module. Log entry was triggered because an SQL injection attempt was detected and stopped. As it looks now the website is potentially under attack.
  • XSS: What it is, how it works, and how to prevent it
    dev.to | 2021-01-18
    It may seem like overkill, but there are web application firewalls designed to specifically prevent common web attacks such as XSS and SQL Injection. Using a web application firewall (WAF) is not necessary for most applications, but for applications that require strong security, they can be a great resource. One such WAF is ModSecurity, which is available for Apache, Nginx, and IIS. Check out their wiki for more information.

Stats

Basic ModSecurity repo stats
5
4,811
7.0
4 days ago

SpiderLabs/ModSecurity is an open source project licensed under Apache License 2.0 which is an OSI approved license.

SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
Find remote jobs at our new job board 99remotejobs.com. There are 24 new remote jobs listed recently.
Are you hiring? Post a new remote job listing for free.