Modsecurity rules to avoid brute force attack

Viewed 179

I have two websites.

http://example1.com/project1/login.php 

http://example2.com/project2/login.php

Both need to log in to use. And they send username and password to

/project1/action1/login_submit1.php
/project2/action2/login_submit2.php

I wrote a rule to block it.

<Location /project1/action1/login_submit1.php>


 SecAction "initcol:IP=%{REMOTE_ADDR},pass,nolog,id:5554"

 SecRule IP:bf_block "@eq 1" \
                "id:5555,deny,\
                msg:'IP address blocked because of suspected brute-force attack'"


 SecRule REQUEST_METHOD  "^POST$"  "auditlog,pass,id:5556,chain"
    SecRule RESPONSE_STATUS "^[200]" "setvar:IP.bf_counter=+1"

 SecRule IP:bf_counter "@ge 3" \
                "id:5557,auditlog, phase:5,pass,t:none, \
                setvar:IP.bf_block=1,\
                setvar:!IP.bf_counter,\
                expirevar:IP.bf_block=30"

</Location>

But it still blocks attack on single web because it uses Location tag. Now, i want to custom a rule to protect both web from brute force attacks. It means that rule can used by any web apps. So any ideas for it.

0 Answers
Related