Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions hardening/Nginx WAF/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@ All notable changes to this project will be documented in this file.

The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## v1.0.1 - 2026-09-02

### Fixed

- Add missing required packages `bison` and `flex` for ModSecurity source build.

## v1.0.0 - 2026-07-03

### Added
Expand Down
12 changes: 10 additions & 2 deletions hardening/Nginx WAF/nginx-waf.bash
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
# Nginx to load the module, and sets up the OWASP Core Rule Set for basic protection against
# common web vulnerabilities.
#
# Version: v1.0.0
# Version: v1.0.1
# License: MIT License
# Copyright (c) 2026 Hunter T. (StrangeRanger)
#
Expand Down Expand Up @@ -37,6 +37,8 @@ readonly C_REQUIRED_PKGS=(
autoconf
automake
build-essential
bison
flex
libcurl4-openssl-dev
libgeoip-dev
libpcre2-dev
Expand Down Expand Up @@ -192,6 +194,9 @@ fi
###
### [ Clone and build ModSecurity ]
###
### TODO: Implement a check that offers to update ModSecurity, rather than get the newest
### version automatically.
###

if [[ ! -d "ModSecurity/.git" ]]; then
echo "${C_INFO}Cloning ModSecurity repository..."
Expand Down Expand Up @@ -275,8 +280,9 @@ echo "${C_INFO}Configuring ModSecurity rules..."
pushd ModSecurity >/dev/null
sudo mkdir -p "$C_MODSEC_PATH"
sudo cp unicode.mapping "$C_MODSEC_PATH/"
## TODO: Add a check to prevent overwriting an existing modsecurity.conf if it has been
## modified.
sudo cp modsecurity.conf-recommended "$C_MODSEC_CONF_PATH"

echo "${C_INFO}Enabling ModSecurity in On mode..."
sudo sed -i 's/SecRuleEngine DetectionOnly/SecRuleEngine On/' "$C_MODSEC_CONF_PATH"
popd >/dev/null
Expand All @@ -297,6 +303,8 @@ if [[ $coreruleset_clone_exists == true ]]; then
confirm_git_pull "" "true"
fi

## TODO: Add a check to prevent overwriting an existing crs-setup.conf if it has been
## modified.
echo "${C_INFO}Configuring OWASP Core Rule Set..."
sudo cp crs-setup.conf.example crs-setup.conf
popd >/dev/null
Expand Down
Loading