{"id":5610,"date":"2025-06-06T15:39:06","date_gmt":"2025-06-06T11:39:06","guid":{"rendered":"https:\/\/jsnet.biz\/?p=5610"},"modified":"2025-07-07T17:00:13","modified_gmt":"2025-07-07T13:00:13","slug":"mod-securty-n%c9%99dir","status":"publish","type":"post","link":"https:\/\/jsnet.biz\/ru\/mod-securty-n%c9%99dir\/","title":{"rendered":"Mod Security n\u0259dir?"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"5610\" class=\"elementor elementor-5610\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ab3ed80 e-flex e-con-boxed e-con e-parent\" data-id=\"ab3ed80\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-55966ec elementor-widget elementor-widget-text-editor\" data-id=\"55966ec\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p data-start=\"0\" data-end=\"277\"><strong data-start=\"0\" data-end=\"15\">ModSecurity<\/strong> \u2014 veb serverl\u0259r \u00fc\u00e7\u00fcn a\u00e7\u0131q m\u0259nb\u0259 kodlu <strong data-start=\"54\" data-end=\"88\">Web Application Firewall (WAF)<\/strong> sistemidir. Onun \u0259sas funksiyas\u0131 veb t\u0259tbiql\u0259ri z\u0259r\u0259rli trafikd\u0259n v\u0259 h\u00fccumlardan qorumaqd\u0131r. Bu sistem <strong data-start=\"192\" data-end=\"202\">Apache<\/strong>, <strong data-start=\"204\" data-end=\"213\">Nginx<\/strong> \u0432\u0259 <strong data-start=\"217\" data-end=\"224\">IIS<\/strong> kimi m\u0259\u015fhur veb serverl\u0259rl\u0259 inteqrasiya oluna bilir.<\/p><hr data-start=\"279\" data-end=\"282\" \/><h3 data-start=\"284\" data-end=\"315\">\ud83d\udd10 <strong data-start=\"291\" data-end=\"315\">ModSecurity n\u0259 edir?<\/strong><\/h3><p data-start=\"316\" data-end=\"412\">ModSecurity real vaxtda HTTP trafiki analiz edir v\u0259 a\u015fa\u011f\u0131dak\u0131 hallar\u0131 a\u015fkar edib bloklaya bilir:<\/p><ul data-start=\"414\" data-end=\"626\"><li data-start=\"414\" data-end=\"437\"><p data-start=\"416\" data-end=\"437\">\u2757 <strong data-start=\"418\" data-end=\"435\">SQL-\u0438\u043d\u044a\u0435\u043a\u0446\u0438\u044f<\/strong><\/p><\/li><li data-start=\"438\" data-end=\"474\"><p data-start=\"440\" data-end=\"474\">\u2757 <strong data-start=\"442\" data-end=\"472\">Cross Site Scripting (XSS)<\/strong><\/p><\/li><li data-start=\"475\" data-end=\"511\"><p data-start=\"477\" data-end=\"511\">\u2757 <strong data-start=\"479\" data-end=\"509\">Local File Inclusion (LFI)<\/strong><\/p><\/li><li data-start=\"512\" data-end=\"549\"><p data-start=\"514\" data-end=\"549\">\u2757 <strong data-start=\"516\" data-end=\"547\">Remote Code Execution (RCE)<\/strong><\/p><\/li><li data-start=\"550\" data-end=\"580\"><p data-start=\"552\" data-end=\"580\">\u2757 <strong data-start=\"554\" data-end=\"578\">Brute Force H\u00fccumlar<\/strong><\/p><\/li><li data-start=\"581\" data-end=\"626\"><p data-start=\"583\" data-end=\"626\">\u2757 <strong data-start=\"585\" data-end=\"626\">Bot v\u0259 DDoS h\u00fccumlar\u0131n\u0131n a\u015fkarlanmas\u0131<\/strong><\/p><\/li><\/ul><hr data-start=\"628\" data-end=\"631\" \/><h3 data-start=\"633\" data-end=\"656\">\u2699\ufe0f <strong data-start=\"640\" data-end=\"656\">\u0130\u015f prinsipi:<\/strong><\/h3><p data-start=\"657\" data-end=\"857\">ModSecurity HTTP sor\u011fular\u0131n\u0131 (GET, POST, HEADER v\u0259 s.) yoxlay\u0131r v\u0259 <strong data-start=\"724\" data-end=\"761\">t\u0259hl\u00fck\u0259 yarada bil\u0259c\u0259k n\u00fcmun\u0259l\u0259ri<\/strong> \u00f6nc\u0259d\u0259n t\u0259yin edilmi\u015f <strong data-start=\"784\" data-end=\"814\">qaydalar toplusu (ruleset)<\/strong> il\u0259 m\u00fcqayis\u0259 edir. \u018fg\u0259r uy\u011funsuzluq varsa:<\/p><ul data-start=\"859\" data-end=\"927\"><li data-start=\"859\" data-end=\"871\"><p data-start=\"861\" data-end=\"871\">Blok edir,<\/p><\/li><li data-start=\"872\" data-end=\"895\"><p data-start=\"874\" data-end=\"895\">Log fayllar\u0131na yaz\u0131r,<\/p><\/li><li data-start=\"896\" data-end=\"927\"><p data-start=\"898\" data-end=\"927\">Administratoru x\u0259b\u0259rdar edir.<\/p><\/li><\/ul><hr data-start=\"929\" data-end=\"932\" \/><h3 data-start=\"934\" data-end=\"984\">\ud83d\udce6 <strong data-start=\"941\" data-end=\"984\">\u018fn \u00e7ox istifad\u0259 olunan qayda paketl\u0259ri:<\/strong><\/h3><ul data-start=\"985\" data-end=\"1155\"><li data-start=\"985\" data-end=\"1078\"><p data-start=\"987\" data-end=\"1078\"><strong data-start=\"987\" data-end=\"1017\">OWASP Core Rule Set (CRS):<\/strong> Standart v\u0259 geni\u015f yay\u0131lm\u0131\u015f a\u00e7\u0131q m\u0259nb\u0259li qaydalar toplusudur.<\/p><\/li><li data-start=\"1079\" data-end=\"1155\"><p data-start=\"1081\" data-end=\"1155\"><strong data-start=\"1081\" data-end=\"1102\">Comodo WAF rules:<\/strong> X\u00fcsusi qaydalar t\u0259qdim ed\u0259n kommersiya versiyas\u0131d\u0131r.<\/p><\/li><\/ul><hr data-start=\"1157\" data-end=\"1160\" \/><h3 data-start=\"1162\" data-end=\"1185\">\u2705 <strong data-start=\"1168\" data-end=\"1185\">\u00dcst\u00fcnl\u00fckl\u0259ri:<\/strong><\/h3><ul data-start=\"1186\" data-end=\"1331\"><li data-start=\"1186\" data-end=\"1217\"><p data-start=\"1188\" data-end=\"1217\">A\u00e7\u0131q m\u0259nb\u0259lidir v\u0259 pulsuzdur.<\/p><\/li><li data-start=\"1218\" data-end=\"1250\"><p data-start=\"1220\" data-end=\"1250\">\u00c7ox \u00e7evik qayda mexanizmi var.<\/p><\/li><li data-start=\"1251\" data-end=\"1286\"><p data-start=\"1253\" data-end=\"1286\">Apache, Nginx v\u0259 IIS il\u0259 i\u015fl\u0259yir.<\/p><\/li><li data-start=\"1287\" data-end=\"1331\"><p data-start=\"1289\" data-end=\"1331\">Real vaxtda trafik analizi imkan\u0131 yarad\u0131r.<\/p><\/li><\/ul><hr data-start=\"1333\" data-end=\"1336\" \/><h3 data-start=\"1338\" data-end=\"1364\">\u274c <strong data-start=\"1344\" data-end=\"1364\">\u00c7at\u0131\u015fmazl\u0131qlar\u0131:<\/strong><\/h3><ul data-start=\"1365\" data-end=\"1561\"><li data-start=\"1365\" data-end=\"1436\"><p data-start=\"1367\" data-end=\"1436\">Y\u00fcks\u0259k performans t\u0259l\u0259b ed\u0259n saytlar \u00fc\u00e7\u00fcn b\u0259z\u0259n l\u0259nglik yarada bil\u0259r.<\/p><\/li><li data-start=\"1437\" data-end=\"1490\"><p data-start=\"1439\" data-end=\"1490\">Yanl\u0131\u015f m\u00fcsb\u0259t (false positive) n\u0259tic\u0259l\u0259r ola bil\u0259r.<\/p><\/li><li data-start=\"1491\" data-end=\"1561\"><p data-start=\"1493\" data-end=\"1561\">Konfiqurasiya v\u0259 qaydalar\u0131n d\u00fczg\u00fcn t\u0259nziml\u0259nm\u0259si t\u0259cr\u00fcb\u0259 t\u0259l\u0259b edir.<\/p><\/li><\/ul><hr data-start=\"1563\" data-end=\"1566\" \/><h3 data-start=\"1568\" data-end=\"1603\">\ud83d\udccc <strong data-start=\"1575\" data-end=\"1603\">N\u0259 \u00fc\u00e7\u00fcn istifad\u0259 olunur?<\/strong><\/h3><p data-start=\"1604\" data-end=\"1786\">\u018fg\u0259r bir sayt\u0131n\u0131z varsa v\u0259 t\u0259hl\u00fck\u0259sizlik sizin \u00fc\u00e7\u00fcn vacibdirs\u0259, ModSecurity sistemini aktivl\u0259\u015fdir\u0259r\u0259k veb t\u0259tbiqinizi bir \u00e7ox z\u0259r\u0259rli h\u00fccumdan <strong data-start=\"1747\" data-end=\"1775\">proaktiv \u015f\u0259kild\u0259 qorumaq<\/strong> m\u00fcmk\u00fcnd\u00fcr.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>ModSecurity \u2014 \u0432\u0435\u0431-\u0441\u0435\u0440\u0432\u0435\u0440, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0439 \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0431\u0440\u0430\u043d\u0434\u043c\u0430\u0443\u044d\u0440\u043e\u043c \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (WAF). \u041e\u043d\u0443\u043d \u0259sas funksiyas\u0131 veb t\u0259tbiql\u0259ri z\u0259r\u0259rli trafikd\u0259n v\u0259 h\u00fccumlardan qorumaqd\u0131r. \u0412 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Apache, Nginx \u0438 IIS \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0432\u0435\u0431-\u0441\u0435\u0440\u0432\u0435\u0440 \u0434\u043b\u044f \u0438\u043d\u0442\u0435\u0433\u0440\u0430\u0446\u0438\u0438 \u0431\u0435\u0437 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438. \ud83d\udd10 ModSecurity \u043d\u0435\u0442? ModSecurity \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0439 \u0430\u043d\u0430\u043b\u0438\u0437 HTTP-\u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0438 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438: \u2757 [\u2026]<\/p>","protected":false},"author":1,"featured_media":5611,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[],"class_list":["post-5610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-computing"],"_links":{"self":[{"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/posts\/5610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/comments?post=5610"}],"version-history":[{"count":0,"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/posts\/5610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/media\/5611"}],"wp:attachment":[{"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/media?parent=5610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/categories?post=5610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jsnet.biz\/ru\/wp-json\/wp\/v2\/tags?post=5610"}],"curies":[{"name":"WP","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}