ai
ModSecurity WAF Remote Work Setup — ตั้งค่า Web

ModSecurity WAF Remote Work

ModSecurity WAF Remote Work VPN OWASP CRS SQL Injection XSS Brute Force Geo-blocking Rate Limiting Zero Trust Production
| Attack | OWASP CRS Rule | Remote Work Risk | Prevention |
|---|---|---|---|
| SQL Injection | 942xxx | สูง (Public-facing App) | CRS PL2 + Virtual Patch |
| XSS | 941xxx | สูง | CRS PL2 + CSP Header |
| Brute Force | Custom Rate Limit | สูงมาก (Login จากทุกที่) | Rate Limit + Account Lock |
| Path Traversal | 930xxx | ปานกลาง | CRS PL1 |
| Bot Attack | Custom UA Rule | สูง | Bot Detection + CAPTCHA |
| DDoS | Custom Rate Limit | สูง (No Office Firewall) | Cloudflare + Rate Limit |

เคล็ดลับ
- DetectionOnly: เริ่มด้วย DetectionOnly Mode 2 สัปดาห์ ก่อนเปิด Block
- PL2: ใช้ Paranoia Level 2 สมดุลระหว่าง Security และ False Positive
- VPN+WAF: ใช้ร่วมกัน VPN ป้องกัน Network WAF ป้องกัน Application
- Geo-block: จำกัดประเทศที่ Remote Workers อยู่จริง
- JSON Log: ใช้ JSON Audit Log ส่ง ELK ง่ายกว่า
ModSecurity คืออะไร
Open Source WAF Apache Nginx OWASP CRS SQL Injection XSS CSRF Brute Force Virtual Patching Rate Limiting Audit Log Detection Prevention





