Á¦°ÅÇÏ°í ¼³Ä¡¸¦ ÇØÁ¦Çϰųª ¹«´ÉÇÏ°Ô ÇϽʽÿÀ ModSecurity (mod_security)¸¦

ModSecurity´Â À¥ ¾ÖÇø®ÄÉÀ̼ÇÀ» À§ÇÑ ¿ÀÇ ¼Ò½º embeddable À¥ ¾ÖÇø®ÄÉÀÌ¼Ç ¹æÈ£º®, ¶Ç´Â ¹«Àü¸ÁħÀÔ Å½Áö ¹× ¿¹¹æ ¿£ÁøÀÌ´Ù. ModSecurity´Â À¥ ¾ÖÇø®ÄÉÀ̼ǿ¡ ´ëÇÏ¿© °ø°ÝÀÇ ¹üÀ§¿¡¼­ º¸È£ÇØÁÖ°í HTTP ¼ÒÅë·® °¨½Ã¿Í ¼ø°£ ºÐ¼®À» ±âÁ¸ÇÏ´Â ±â¹Ý¿¡ º¯È­ ¾øÀÌ ¿î¿µÇؼ­ Apache Web Server ´ÜÀ§ mod_security·Î, ¶Ç´Â µ¶¸³, ÀÌ·¸°Ô À¥ ¾ÖÇø®ÄÉÀÌ¼Ç ¾ÈÀüÀ» Áõ°¡ÇÑ´Ù. ±×·¯³ª, À߸ø ¼³Á¤ÇÏ´Â Àü¸éÀ¸·Î ÁؾöÇÑ ±ÔÄ¢ ¼¼Æ®, ModSecurity´Â ´ç½ÅÀÇ À¥»çÀÌÆ®¸¦ HTTP 403 ±ÝÁöÇÑ °ú½Ç°ú °°Àº °¢Á¾ °ú½ÇÀ» µ¹·Áº¸³»°Å³ª ºÎÁ¤ÇÑ °ú½Ç ·Î±×ÀÎ ¹®Á¦, ¶Ç´Â HTTP 412 ÀüÁ¦ Á¶°Ç¿¡ ÀÇÇÏ¿© ½ÇÆÐµÈ °ú½Ç, ¶Ç´Â HTTP 406 ¼ö¶ô°¡´ÉÇÑ °ú½Ç ¹× ´Ù¸¥ Ʋ¸° È®½Ç¼º ÁõÈĸ¦ Á¢±ÙÇÏ´Â ¿øÀÎÀÌ µÉÁöµµ ¸ð¸¥´Ù.

»çÁ¤À» ´õ ³ª»Û ½Ã۱â À§ÇÏ¿©´Â, ModSecurity ±ÔÄ¢ÀÇ À±°û ¹× ¿©°ú±â´Â ¼öµ¿À¸·Î ÇàÇØÁ®¾ß ÇÑ´Ù. ³õÀÎ »óÀÚ¿¡¼­ ModSecurity¿Í ÇÔ²² »ç¿ëµÉ ¼ö ÀÖ´Â ÀÚÀ¯·Ó°Ô ¹Ì¸® Á¤ÀÇÇÑ Áõ¸íÇÑ ±ÔÄ¢ÀÌ ÀÖ´õ¶óµµ, ±ÔÄ¢ ¼¼Æ®°¡ °¢ ȯ°æÀ» À§ÇØ Àû´çÇÒÁöµµ À¥»çÀÌÆ® blogs, ÁÖ¹®À» ¹Þ¾Æ¼­ ¸¸µé°í º¯°æÀÇ °¡µ¿°ú ¹æÇØÇÒÁöµµ ¸ð¸¥´Ù ±×·¯³ª ±ÔÄ¢Àº ¸î¸î »ç¿ëÀÚ¸¦ À§ÇØ ³Ê¹« Á¤±³Çϰųª º¹ÀâÇÒÁöµµ ¸ð¸¥´Ù. ±×¸®°í °øµ¿ È£½ºÆ® ¼­ºñ½º¿¡ Á¢´ëÇÑ ¸î¸î À¥»çÀÌÆ®¸¦ À§ÇØ, mod_security´Â ¼±ÅÃ±Ç ¾øÀÌ ºÎÀü½ÂÀ¸·Î °¡´ÉÇÏ°Ô ÇÑ´Ù ÀÏÁöµµ ¸ð¸¥´Ù. ÀÌ·¸°Ô ÀÌ °æ¿ì¿¡´Â, mod ¾ÈÀü º¸Àå¿¡ °ü°èµÇ´Â ¹®Á¦Á¡À» À§ÇÑ Á¦ÀÏ ÇØ°áÃ¥ ¶Ç´Â workaround´Â °Å¸£´Â mod_security¸¦ ¹«´ÉÇÏ°Ô Çϱâ À§ÇÑ °ÍÀ̰í Áö¹èÇÑ´Ù.

´ç½ÅÀÌ Apache Web Server (ÁÖ·Î) »ç¿ëÇÏ´Â °æ¿ì¿¡, mod_security´Â .htaccess ÆÄÀÏ¿¡ Àִ Ư¼ºÀ» Ãß°¡Çؼ­ ¹«´ÉÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. Á¸ÀçÇÏÁö ¾ÊÀ¸¸ç, .htaccessÀ̶ó°í Áö¸íµÈ »õ ÆÄÀÏÀ» âÁ¶ÇÏÁö ¾ÊÀ¸¸ç °æ¿ì¿¡, µÚ¿¡ ¿À´Â ºÎÈ£¿¡¼­ µ¡ºÙÀÌÁö ¾ÊÀ¸¸é, ¾ÆÆÄÄ¡ À¥ ·çÆ® µð·ºÅ丮¿¡ ÀÖ´Â .htaccess ÆÄÀÏÀ» (public_html ¶Ç´Â /var/www/ ¶Ç´Â ´Ù¸¥ »ç¶÷) ã¾Æ³»½Ê½Ã¿À:


¶³¾îÁ® SecFilterEngine
¶³¾îÁ® SecFilterScanPOST

.htaccess¿¡ ÀÖ´Â À§ ÀÔÀåÀº ¿µ¿ªÀ» À§ÇÑ ModSecurity (mod_security) ´ÜÀ§¸¦ ¹«´ÉÇÏ°Ô ÇÒ °ÍÀÌ´Ù.

¾ÆÆÄÄ¡ ´ÜÀ§¿¡¼­ ModSecurity (mod_security)ÀÇ »èÁ¦

mod_security¸¦ Á¦°ÅÇÏ°í ¼³Ä¡¸¦ ÇØÁ¦ÇÏ´Â ½¬¿î ¹æ¹ýÀº ¼³¸íÇϰųª httpd.conf ¾ÆÆÄÄ¡ ±¸¼º ÆÄÀÏ¿¡¼­ °ü·Ã mod_security ÀÔÀåÀ» »èÁ¦Çϱâ À§ÇÑ °ÍÀÌ´Ù. Á¦°ÅµÇ¾î¾ß ÇÏ´Â ¼±Àº ´ÙÀ½À» Æ÷ÇÔÇÑ´Ù:

AddModule mod_security.c
LoadModule security_module ´ÜÀ§ ¶Ç´Â mod_security.so
Æ÷ÇÔÇϽʽÿÀ "/usr/local/apache/conf/modsec.conf"¸¦ ÀÌ ¼±Àº ¸®´ª½º À¯´Ð½ºÀÇ ¹«½¼ ÀÌü¸¦ ´ç½ÅÀÌ ±×¸®°í ÀÓ¸í À§Ä¡ »ç¿ëÇÑ¿¡ µû¶ó¼­ ´Ù¸¦Áöµµ ¸ð¸¥´Ù

httpd.conf¸¦ ÀúÀåÇÏ°í ¾ÆÆÄÄ¡¸¦ ÀçÃâ¹ßÇϽʽÿÀ. ModSecurity´Â ¼³Ä¡¸¦ ÇØÁ¦ÇØ Ã³·³ ÀûÀçµÇÁö ¾ÊÀ¸¸ç.

´ç½ÅÀÌ WebHost ¸Å´ÏÀú (WHM)¸¦ »ç¿ëÇÏ´Â °æ¿ì¿¡, »èÁ¦´Â ´õ °£´ÜÇÏ´Ù Á¶Â÷. cPanel ´Ü¸éµµ¿¡ Á¤´çÇÑ ÀÏÆøÀº, Addon ´ÜÀ§¸¦ Ŭ¸¯ÇÑ´Ù. ±× ¶§ ´ÜÀ§¿¡ ÀÏÆøÀº modsecurity¸¦ Áö¸íÇß´Ù. ¼³Ä¡Çϰí À¯ÁöÇÑ´Ù ÇöÀç »õ·Ó°Ô ÇØ °Ë»çµÇ¾î¾ß ÇÑ´Ù. ´Ù¸¸ À§¿¡ Apache Web Server¿¡¼­ mod ¾ÈÀü Ư¡À» Á¦°ÅÇϱâ À§ÇÏ¿© ¼³Ä¡¸¦ ÇØÁ¦ÇÑ´Ù ´©¸£½Ê½Ã¿À.

Áß¿äÇÑ : This is a machine translated page which is provided "as is" without warranty. Machine translation may be difficult to understand. Please refer to original English article whenever possible.

Share and contribute or get technical support and help at My Digital Life Forums.



4 Responses to ¡°Remove and Uninstall or Disable ModSecurity (mod_security)¡±

  1. John
    July 7th, 2007 00:16
    1

    A BIG Thanks to You!

    It really works! Thanks You!

  2. Adam Dempsey
    February 2nd, 2008 00:51
    2

    Exactly what I was looking for, thanks :)

  3. Neran
    April 17th, 2008 17:13
    3

    Thanks alot! It works!

  4. Karlos
    June 29th, 2008 23:47
    4

    Cheers, just what I needed, worked first time

Leave a Reply

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Subscribe without commenting


Custom Search

New Articles

Incoming Search Terms for the Article

disable modsecurity - disable mod security - disable mod_security - htaccess mod_security - turn off mod_security - mod_security disable - disable mod_security htaccess - mod_security .htaccess - .htaccess disable mod_security - disable mod_security .htaccess - disable mod_sec - How to disable mod security - uninstall mod_security - .htaccess mod_security - htaccess disable mod_security - mod_security disable htaccess - mod_security htaccess - turn off modsecurity - htaccess modsecurity - mod security disable - how to disable modsecurity - apache disable mod_security - disable mod security htaccess - modsecurity disable rule - how to disable mod_security - remove modsecurity - mod_sec disable - whm Mod Security - htaccess mod security - how to turn off mod security - htaccess disable mod security - apache disable modsecurity - disable mod_security httpd.conf - disable mod security apache - modsecurity disable htaccess - disable mod_security with .htaccess - turn off mod_security htaccess - disable mod_security apache - disable mod-security - turn off mod security - mod_security2 disable - modsecurity htaccess - disable mod_security2 - disable modsec using .htaccess - disable mod_security via .htaccess - mod_security uninstall - turn off mod security htaccess - mod_security2 .htaccess - modsecurity disable - remove mod security -