mod_security can't filter some words :(
2006-04-03 06:47:15 GMT
hi
i use mod_security 1.9.2 and httpd 2.0.55 test some php software .
on some case i need filter chinaese word in web software .
for example
SecFilterSelective POST_PAYLOAD 中文
SecFilterSelective POST_PAYLOAD testa
is "SecFilterSelective POST_PAYLOAD testa " is pass .but SecFilterSelective POST_PAYLOAD 中文 is not :(
this log is for testa :
==29ae5339==============================
Request:
192.168.202.47 211.157.227.29 - - [03/Apr/2006:14:38:45 +0800] "POST /7/post.php?action=reply&fid=2&tid=4&extra=page%3D1&replysubmit=yes HTTP/1.1" 403 287 "
http://192.168.202.47/7/post.php?action=reply&fid=2&tid=4&extra=page%3D1" "Mozilla/5.0 (Windows; U; Windows NT
5.1; zh-CN; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1" - "-"
----------------------------------------
POST /7/post.php?action=reply&fid=2&tid=4&extra=page%3D1&replysubmit=yes HTTP/1.1
Host: 192.168.202.47
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=
0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: zh-cn,zh;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: gb2312,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer:
http://192.168.202.47/7/post.php?action=reply&fid=2&tid=4&extra=page%3D1
Cookie: cdb_sid=65F1Y6; cdb_oldtopics=D4D3D2D1D; cdb_fid1=1144044872; cdb_cookietime=2592000; cdb_cpcollapsed=0; cdb_fid2=1144046293; cdb_visitedfid=2; cdb_auth=UFIHUApRUAgHVQwEAFMCDgxWXFsEUFZRUVYPBQQHVAFragQ
Content-Type: multipart/form-data; boundary=---------------------------5150948113011
Content-Length: 4252
mod_security-action: 403
mod_security-message: Access denied with code 403. Pattern match "testa" at POST_PAYLOAD
so if you have some tips .pls mail to this mail list .
thank you
--
http://wanghao.cublog.cn
RSS Feed