Re: How To Incident Response

2017-05-13 Thread lann...@runbox.com
Hi Gunar, OK, but I must first point to a minor contradiction here: Your mail's subject talks about incident response, but you talk here about "performing installation". Those are two very different (although, yes, conceptually related) issues. You right. Here is a longer explanation: In sur

How To Incident Response

2017-05-12 Thread lann...@runbox.com
Hi, I'm performing installation for a "secure" web app. I'm starting with psad, and suricata. Now I'd like to install Sguil or Snorby or any alternative for packet capturing. My problem is that I have to compile myself which we know is not the best solution for security. Does any alternative

ModSecurity Debian 8

2017-03-20 Thread lann...@runbox.com
Hi, I have spent about 2 days trying to understand how to setup mod-security on my web server. I choose to rely on packages in the official repo, so if possible I will not compile packages. Is correct to say that I can't have mod-security in nginx? Is mod-security only available in apache2?