• We value your experience with Plesk during 2024
    Plesk strives to perform even better in 2025. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2024.
    Please take this short survey:

    https://pt-research.typeform.com/to/AmZvSXkx
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Plesk mod_security support

K

kake26

Guest
Here is a suggestion for the developers of Plesk. Add support for mod_security to plesk as in have install along with Plesk and use the gotroot.com rules. That would be very cool and allow us poor sysadmins to worry a bit less about our servers. Here is a link to mod_security.
 
mod_security is very easy to install.

But its far from an install and forget thing, you need to update rules regularly to get the best out of it - and personally i dont recommend the use of all the rules from gotroot , its best to customize rules around your enviroment.

mod_security works by examining things like the post payload, it then compares this with every single rule that you have listed, the more rules the longer this process takes - its best to just add stuff as you feel you need too.

There fore installing it initially via plesk maybe a start - but then you as the sysadmin need to know how to update it - so you may as well go the few extra steps and install it anyway :)
 
True, but I've implemented those and I've seen no noticable difference in the speed of any requests to and from the server. Besides I was wanting to use a very refined and well written rule set which gotroot.com provided.Also given the fact there are many that apply to applications in my plesk's application vault. I'll go as far as saying those rules and mod_security had I discovered them earlier than I did could have prevented a few sites from getting hacked on my server. Your point is well taken though.
 
Back
Top