• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.

Plesk mod_security support

K

kake26

Guest
Here is a suggestion for the developers of Plesk. Add support for mod_security to plesk as in have install along with Plesk and use the gotroot.com rules. That would be very cool and allow us poor sysadmins to worry a bit less about our servers. Here is a link to mod_security.
 
mod_security is very easy to install.

But its far from an install and forget thing, you need to update rules regularly to get the best out of it - and personally i dont recommend the use of all the rules from gotroot , its best to customize rules around your enviroment.

mod_security works by examining things like the post payload, it then compares this with every single rule that you have listed, the more rules the longer this process takes - its best to just add stuff as you feel you need too.

There fore installing it initially via plesk maybe a start - but then you as the sysadmin need to know how to update it - so you may as well go the few extra steps and install it anyway :)
 
True, but I've implemented those and I've seen no noticable difference in the speed of any requests to and from the server. Besides I was wanting to use a very refined and well written rule set which gotroot.com provided.Also given the fact there are many that apply to applications in my plesk's application vault. I'll go as far as saying those rules and mod_security had I discovered them earlier than I did could have prevented a few sites from getting hacked on my server. Your point is well taken though.
 
Back
Top