« PenTest Manager 2.0 - Attack Sequences | Main | TWSL2012-014: Multiple Vulnerabilities in Scrutinizer NetFlow & sFlow Analyzer »

26 July 2012

Comments

installed ModSecurity for IIS at C:\Program Files (x86)\ModSecurity IIS
There are configure.exe.config and configure.exe files in this folder.
How to configure the rules? Should use the configure.exe or configure.exe.config or some configure files in C:\inetpub\wwwroot?

can i send logs to a log server using mlogc? can i pipe mlogc in IIS using this directive:
SecAuditLog "|mlogc.exe mlogc.conf"

You can add the mod security XML .conf file into the wwwroot which will fix the 503 Server Unavailable error, i.e the .dll failed to load.

http://blogs.technet.com/b/srd/archive/2012/07/26/announcing-the-availability-of-modsecurity-extension-for-iis.aspx

sorry XML was removed.


Configuration file is required in the wwwroot of the resource pool.

The following contents is required. – replace wwwroot\domain.com.au\config.conf with the required values.

Restart the application pool.




If you have further config.conf configurations, place the into the existing

You can put the modsecurity .conf in the wwwroot of the application pool to resolve the .dll fail to load error message.


here are my build notes below:

Configuration file is required in the wwwroot of the resource pool.

The following contents is required. – replace wwwroot\domain.com.au\config.conf with the required values.

Restart the application pool.




If you have further config.conf configurations, place the into the existing

Same problem.

Same problem here. Can not get application pools for my websites running with same error as stated above.

Hi,

I installed ModSecurity for IIS. After installing it is continuously stopping DefaultAppPool (after I manually start) due to which the website is not getting loaded and giving the error as: 503 Service unavailable.

In event viewer the error is: C:\Windows\System32\inetsrv\modsecurityiis.dll failed to load. The data is error.

Any thoughts on this?

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment