owasp-modsecurity / ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.
https://www.modsecurity.org
Apache License 2.0
8.14k stars 1.59k forks source link

Which rules to enable from the available 15138 ModSecurity Commercial rules for a Banking App #2597

Closed titucse closed 3 years ago

titucse commented 3 years ago

We have purchased a license for Trustwave ModSecurity Commercial Rules. There are total 15138 rules. Which rules should enable from the available 15138 ModSecurity Commercial rules for a Banking App. Can anyone help please?

App Description: This is a banking app. Bank customers need to register to use the app. During the registration process customers take selfies and take photos of ID documents. Registered customers sign in with username and password. They can view balance, do fund transfer, download statements etc. For fund transfer they need OTP sent via SMS.

martinhsv commented 3 years ago

Hi @titucse ,

This forum is really for questions and issues pertaining to the open-source ModSecurity engine, rather than information about particular rule sets.

For questions about the Trustwave's Commercial Rule set, a better avenue would be to contact their support for that product. There is a some information here:

https://www.trustwave.com/en-us/company/support/

Select 'ModSecurity' in the dropdown and there is an email address along with other information.