{"id":6261,"date":"2018-02-25T13:16:00","date_gmt":"2018-02-25T12:16:00","guid":{"rendered":"https:\/\/www.domenca.com\/blog\/?p=6261"},"modified":"2018-03-02T13:17:52","modified_gmt":"2018-03-02T12:17:52","slug":"vse-o-modsecurity","status":"publish","type":"post","link":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/","title":{"rendered":"Vse o ModSecurity"},"content":{"rendered":"<p>ModSecutiry \u0161\u010diti spletne aplikacije pred dolo\u010denimi oblikami napadov.<\/p>\n<p>ModSecurity je t.i. \u201cWeb Application Firewall\u201d (WAF) oziroma po\u017earni zid spletnega stre\u017enika. WAFi se uporabljajo za pove\u010danje (izbolj\u0161anje) zunanje za\u0161\u010ditne plasti za odkrivanje in\/ali\u00a0<strong>prepre\u010devanje napadov, preden ti dose\u017eejo spletne aplikacije<\/strong>.<\/p>\n<p>ModSecurity nudi za\u0161\u010dito pred \u0161irokim spektrom napadov na spletne aplikacije, omogo\u010da pa tudi spremljanje in analizo HTTP prometa z namenom zaznavanja morebitnih napadov.<\/p>\n<h2>Kako deluje?<\/h2>\n<p>ModSecurity deluje tako, da blokira HTTP poizvedbe, ki jih zazna kot zlonamerne. Ko zahtevek s strani obiskovalca spletne aplikacije pride na stre\u017enik, ModSecurity podatke tega zahtevka in druge poslane del\u010dke informacij skenira in jih filtrira na podlagi lastnega nabora pravil. Primerjajo se, denimo, brskalnik, ki ga obiskovalec uporablja, velikost zahtevka in datoteke, na katere se ta nana\u0161a. \u010ce se ob tem zaznajo neustreznosti ali morebitne nevarnosti, je zahtevek blokiran, \u0161e preden dose\u017ee spletno aplikacijo. V tem smislu lahko ModSecurity razumemo tudi kot nekak\u0161en po\u017earni zid spletne aplikacije.<\/p>\n<h2>Kaj zaznava in pred \u010dim \u0161\u010diti?<\/h2>\n<p>ModSceurity zaznava in \u0161\u010diti spletne aplikacije pred:<\/p>\n<ul>\n<li>zahtevami zlonamernih avtomatiziranih programov,<\/li>\n<li>XSS (Cross Site Scripting),<\/li>\n<li>SQL injections,<\/li>\n<li>File name injections,<\/li>\n<li>trojanskimi konji in<\/li>\n<li>drugimi podobnimi zlorabami.<\/li>\n<\/ul>\n<h2>Vpliv na delovanje<\/h2>\n<p>Za ve\u010dino spletnih strani, ki gostujejo na stre\u017eniku s tem modulom, ta nima vidnih posledic na njihovo delovanje. Vendar pa pri tem velja poudariti, da ModSecurity temelji na sistemu pravil, kjer se filtrirajo tisti zahtevki, ki se zdijo zlonamerni. Z ozirom na \u0161irok nabor razli\u010dnih konfiguracij, razli\u010dic programske opreme in nenazadnje spletnih aplikacij samih se ob\u010dasno lahko zgodi, da ModSecurity blokira zahtevek, ki ni zlonameren. V teh primerih se na spletnih straneh najpogosteje pojavi napaka Forbidden 403.<\/p>\n<p>V primeru te\u017eav lahko ModSecurity v svojem paketu gostovanja izklopite.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ModSecutiry \u0161\u010diti spletne aplikacije pred dolo\u010denimi oblikami napadov. ModSecurity je t.i. \u201cWeb Application Firewall\u201d (WAF) oziroma po\u017earni zid spletnega stre\u017enika. WAFi se uporabljajo za pove\u010danje (izbolj\u0161anje) zunanje za\u0161\u010ditne plasti za odkrivanje in\/ali\u00a0prepre\u010devanje napadov, preden ti dose\u017eejo spletne aplikacije. ModSecurity nudi za\u0161\u010dito pred \u0161irokim spektrom napadov na spletne aplikacije, omogo\u010da pa tudi spremljanje in analizo HTTP [&hellip;]<\/p>\n","protected":false},"author":55,"featured_media":6262,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_ef_editorial_meta_date_first-draft-date":"","_ef_editorial_meta_paragraph_assignment":"","_ef_editorial_meta_checkbox_needs-photo":"","_ef_editorial_meta_number_word-count":"","footnotes":""},"categories":[112],"tags":[],"class_list":["post-6261","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-varnost"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vse o ModSecurity - Domenca.com Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/\" \/>\n<meta property=\"og:locale\" content=\"sl_SI\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vse o ModSecurity - Domenca.com Blog\" \/>\n<meta property=\"og:description\" content=\"ModSecutiry \u0161\u010diti spletne aplikacije pred dolo\u010denimi oblikami napadov. ModSecurity je t.i. \u201cWeb Application Firewall\u201d (WAF) oziroma po\u017earni zid spletnega stre\u017enika. WAFi se uporabljajo za pove\u010danje (izbolj\u0161anje) zunanje za\u0161\u010ditne plasti za odkrivanje in\/ali\u00a0prepre\u010devanje napadov, preden ti dose\u017eejo spletne aplikacije. ModSecurity nudi za\u0161\u010dito pred \u0161irokim spektrom napadov na spletne aplikacije, omogo\u010da pa tudi spremljanje in analizo HTTP [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/\" \/>\n<meta property=\"og:site_name\" content=\"Domenca.com Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/domenca\" \/>\n<meta property=\"article:published_time\" content=\"2018-02-25T12:16:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-03-02T12:17:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2018\/03\/Depositphotos_36515569_xl-2015-1024x683.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"683\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Vanesa Smole\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Vanesa Smole\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minuta\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/\"},\"author\":{\"name\":\"Vanesa Smole\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/#\\\/schema\\\/person\\\/8ec8af8fe4992174aa1787d1e2692e2b\"},\"headline\":\"Vse o ModSecurity\",\"datePublished\":\"2018-02-25T12:16:00+00:00\",\"dateModified\":\"2018-03-02T12:17:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/\"},\"wordCount\":299,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/03\\\/Depositphotos_36515569_xl-2015.jpg\",\"articleSection\":[\"Varnost\"],\"inLanguage\":\"sl-SI\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/\",\"url\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/\",\"name\":\"Vse o ModSecurity - Domenca.com Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/03\\\/Depositphotos_36515569_xl-2015.jpg\",\"datePublished\":\"2018-02-25T12:16:00+00:00\",\"dateModified\":\"2018-03-02T12:17:52+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/#\\\/schema\\\/person\\\/8ec8af8fe4992174aa1787d1e2692e2b\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#breadcrumb\"},\"inLanguage\":\"sl-SI\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"sl-SI\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/03\\\/Depositphotos_36515569_xl-2015.jpg\",\"contentUrl\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/03\\\/Depositphotos_36515569_xl-2015.jpg\",\"width\":4368,\"height\":2912,\"caption\":\"Internet security online business concept pointing security services\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/2018\\\/02\\\/25\\\/vse-o-modsecurity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vse o ModSecurity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/\",\"name\":\"Domenca.com Blog\",\"description\":\"Domenca Blog\",\"alternateName\":\"Domenca Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sl-SI\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/#\\\/schema\\\/person\\\/8ec8af8fe4992174aa1787d1e2692e2b\",\"name\":\"Vanesa Smole\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sl-SI\",\"@id\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/LR5D5493_1-100x100.jpg\",\"url\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/LR5D5493_1-100x100.jpg\",\"contentUrl\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/LR5D5493_1-100x100.jpg\",\"caption\":\"Vanesa Smole\"},\"url\":\"https:\\\/\\\/www.domenca.com\\\/blog\\\/author\\\/vanesa\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vse o ModSecurity - Domenca.com Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/","og_locale":"sl_SI","og_type":"article","og_title":"Vse o ModSecurity - Domenca.com Blog","og_description":"ModSecutiry \u0161\u010diti spletne aplikacije pred dolo\u010denimi oblikami napadov. ModSecurity je t.i. \u201cWeb Application Firewall\u201d (WAF) oziroma po\u017earni zid spletnega stre\u017enika. WAFi se uporabljajo za pove\u010danje (izbolj\u0161anje) zunanje za\u0161\u010ditne plasti za odkrivanje in\/ali\u00a0prepre\u010devanje napadov, preden ti dose\u017eejo spletne aplikacije. ModSecurity nudi za\u0161\u010dito pred \u0161irokim spektrom napadov na spletne aplikacije, omogo\u010da pa tudi spremljanje in analizo HTTP [&hellip;]","og_url":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/","og_site_name":"Domenca.com Blog","article_publisher":"https:\/\/www.facebook.com\/domenca","article_published_time":"2018-02-25T12:16:00+00:00","article_modified_time":"2018-03-02T12:17:52+00:00","og_image":[{"width":1024,"height":683,"url":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2018\/03\/Depositphotos_36515569_xl-2015-1024x683.jpg","type":"image\/jpeg"}],"author":"Vanesa Smole","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Vanesa Smole","Est. reading time":"1 minuta"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#article","isPartOf":{"@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/"},"author":{"name":"Vanesa Smole","@id":"https:\/\/www.domenca.com\/blog\/#\/schema\/person\/8ec8af8fe4992174aa1787d1e2692e2b"},"headline":"Vse o ModSecurity","datePublished":"2018-02-25T12:16:00+00:00","dateModified":"2018-03-02T12:17:52+00:00","mainEntityOfPage":{"@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/"},"wordCount":299,"commentCount":0,"image":{"@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2018\/03\/Depositphotos_36515569_xl-2015.jpg","articleSection":["Varnost"],"inLanguage":"sl-SI"},{"@type":"WebPage","@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/","url":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/","name":"Vse o ModSecurity - Domenca.com Blog","isPartOf":{"@id":"https:\/\/www.domenca.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#primaryimage"},"image":{"@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2018\/03\/Depositphotos_36515569_xl-2015.jpg","datePublished":"2018-02-25T12:16:00+00:00","dateModified":"2018-03-02T12:17:52+00:00","author":{"@id":"https:\/\/www.domenca.com\/blog\/#\/schema\/person\/8ec8af8fe4992174aa1787d1e2692e2b"},"breadcrumb":{"@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#breadcrumb"},"inLanguage":"sl-SI","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/"]}]},{"@type":"ImageObject","inLanguage":"sl-SI","@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#primaryimage","url":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2018\/03\/Depositphotos_36515569_xl-2015.jpg","contentUrl":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2018\/03\/Depositphotos_36515569_xl-2015.jpg","width":4368,"height":2912,"caption":"Internet security online business concept pointing security services"},{"@type":"BreadcrumbList","@id":"https:\/\/www.domenca.com\/blog\/2018\/02\/25\/vse-o-modsecurity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.domenca.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Vse o ModSecurity"}]},{"@type":"WebSite","@id":"https:\/\/www.domenca.com\/blog\/#website","url":"https:\/\/www.domenca.com\/blog\/","name":"Domenca.com Blog","description":"Domenca Blog","alternateName":"Domenca Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.domenca.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sl-SI"},{"@type":"Person","@id":"https:\/\/www.domenca.com\/blog\/#\/schema\/person\/8ec8af8fe4992174aa1787d1e2692e2b","name":"Vanesa Smole","image":{"@type":"ImageObject","inLanguage":"sl-SI","@id":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2019\/05\/LR5D5493_1-100x100.jpg","url":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2019\/05\/LR5D5493_1-100x100.jpg","contentUrl":"https:\/\/www.domenca.com\/blog\/wp-content\/uploads\/2019\/05\/LR5D5493_1-100x100.jpg","caption":"Vanesa Smole"},"url":"https:\/\/www.domenca.com\/blog\/author\/vanesa\/"}]}},"_links":{"self":[{"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/posts\/6261","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/comments?post=6261"}],"version-history":[{"count":1,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/posts\/6261\/revisions"}],"predecessor-version":[{"id":6263,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/posts\/6261\/revisions\/6263"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/media\/6262"}],"wp:attachment":[{"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/media?parent=6261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/categories?post=6261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.domenca.com\/blog\/wp-json\/wp\/v2\/tags?post=6261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}