Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integration with Perishable Press (Jeff Star) ported 7G firewall #75

Open
LCBO opened this issue Nov 22, 2020 · 3 comments
Open

Integration with Perishable Press (Jeff Star) ported 7G firewall #75

LCBO opened this issue Nov 22, 2020 · 3 comments

Comments

@LCBO
Copy link

LCBO commented Nov 22, 2020

Hello,
I suggest integrating SS with 7G firewall from PersihablePress. https://perishablepress.com/7g-firewall/
Right now is for Apache but there are some ports that might help: as those from Gridpane for 6G: https://github.com/thewzrd/nginx-configs

(modules, etc)

@jessuppi
Copy link
Member

jessuppi commented Aug 9, 2022

Thanks for the suggestion @LCBO

Jeff Star's tireless work and generosity over the years is incredible. It looks like he released an Nginx version of 7G firewall several months ago, with the the help of @JeffCleverley:

https://perishablepress.com/7g-firewall-nginx/
https://gitlab.gridpane.net/gp-public/nginx-configs

Cleverley was an early "observer" of SlickStack in fact, before GridPane launched... he friended me on social media, but at some point he decided he didn't like me and started trash-talking me, and blocked me when I asked him about it... from what I could gather, it was something politically motivated.

(I'm tagging him since I try to avoid talking about people behind their back.)

Why I mention this background:

I'm not against reviewing the ruleset that Cleverley ported to Nginx and implementing whatever we can (with credit to both of these guys in our config comments), but I wouldn't feel comfortable simply embedding it blindly, or promoting it to users which might lead them to download/install new versions of the ported 7G outside of ss-install processes.

There's no telling what drama or maliciousness might unfold if we start sending SlickStack users to GridPane's repos and telling them to install Cleverley's stuff (the joy of WordPress community).

On a more practical note, some of the security rules likely conflict with our existing rules.

For the record we've always supported Jeff's BBQ plugin: https://wordpress.org/plugins/block-bad-queries/

@jessuppi jessuppi changed the title Integration with PerishablePress 7G firewall Integration with Perishable Press (Jeff Star) 7G firewall Aug 9, 2022
@jessuppi jessuppi changed the title Integration with Perishable Press (Jeff Star) 7G firewall Integration with Perishable Press (Jeff Star) ported 7G firewall Aug 9, 2022
@jessuppi
Copy link
Member

jessuppi commented Aug 9, 2022

A few other relevant links here:

Ref: https://github.com/Boundless-Zone/7g-nginx-rules
Ref: https://kb.linuxlove.xyz/nginx-7g.html

@jessuppi
Copy link
Member

And another: https://wpsurfer.com/block-bad-queries/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants