Skip to content

v2.78.0 - ModSecurity WAF

Choose a tag to compare

@fotsakir fotsakir released this 20 Jan 17:54
· 53 commits to main since this release

What's New

Added

  • ModSecurity WAF - Web Application Firewall with OWASP Core Rule Set
    • New setup_waf.sh script for easy installation
    • Protection against SQL injection, XSS, command injection
    • OWASP Top 10 attack prevention
    • Custom exclusions for CodeHero (WebSocket, Terminal, Editor, API)
  • WAF Setup in Package Manager - Install WAF from web UI
  • WAF Documentation - New docs/WAF_SETUP.md with full setup guide

Security

  • ModSecurity 3.x with OWASP CRS 3.3.5 (~2,800 rules)
  • Automatic blocking mode enabled
  • Protects Admin Panel (9453), Projects (9867), phpMyAdmin (9454)

Install WAF

# Via script
sudo /opt/codehero/scripts/setup_waf.sh

# Or via Package Manager (Dashboard → Packages → WAF Security Setup)

Upgrade

cd /root
wget https://github.com/fotsakir/codehero/releases/latest/download/codehero-2.78.0.zip
unzip codehero-2.78.0.zip
cd codehero
sudo ./upgrade.sh