# ModSecurity exceptions

**URL:** https://meta.discourse.org/t/modsecurity-exceptions/125128
**Category:** Support
**Created:** [August 7, 2019, 1:33pm UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128 "2019-08-07T13:33:16Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![szogoon](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@szogoon](https://meta.discourse.org/u/szogoon)
#### Post date: [August 7, 2019, 1:33pm UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/1 "2019-08-07T13:33:17Z")

</div>

Have someone installed Discourse behind nginx/Apache with ModSecurity and CRS v3?  
Is there any known list of rules to disable or modify for Discourse?  
For now we have disabled ~11 rules and I think that is not the end.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [August 7, 2019, 3:02pm UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/2 "2019-08-07T15:02:14Z")

</div>

Why would you use that?

Discourse is open source and with way more activity than ModSecurity, which sounds like something useful when put to front some black box web software.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [August 8, 2019, 4:26am UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/3 "2019-08-08T04:26:31Z")

</div>

I promise you this will end very badly for everyone involved. It is _not_ a good idea.

---

<div class="post-metadata">

### Author: ![szogoon](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@szogoon](https://meta.discourse.org/u/szogoon)
#### Post date: [August 8, 2019, 7:29am UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/4 "2019-08-08T07:29:51Z")

</div>

So you are telling me that introducing WAF will only create new troubles and Discourse doesn’t contain any vulnerabilities?

---

<div class="post-metadata">

### Author: ![eviltrout](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eviltrout/32/5275_2.png) [@eviltrout](https://meta.discourse.org/u/eviltrout)
#### Post date: [August 8, 2019, 6:25pm UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/5 "2019-08-08T18:25:34Z")

</div>

Nobody can promise will full confidence that their software doesn’t contain vulnerabilities. We do however patch security issues promptly and responsibly when reported, and have a bug bounty program.

Having said that, ModSecurity is not the answer. You will have a very hard time if you choose to do this.

---

<div class="post-metadata">

### Author: ![szogoon](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@szogoon](https://meta.discourse.org/u/szogoon)
#### Post date: [August 8, 2019, 8:22pm UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/6 "2019-08-08T20:22:30Z")

</div>

Thank you for the answers. We will consider removing ModSecurity.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [February 17, 2023, 11:21am UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/7 "2023-02-17T11:21:06Z")

</div>



---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [February 17, 2023, 5:47pm UTC](https://meta.discourse.org/t/modsecurity-exceptions/125128/8 "2023-02-17T17:47:37Z")

</div>


