Scott Galambos | 3 Jan 2012 19:01

block and redirect?

I'm trying to get modsecurity 2.6 going on apache 2.21 under linux.  it 
mostly works.  this is my basic example:

<IfModule security2_module>
    SecRuleEngine On
    SecRequestBodyAccess On
    SecResponseBodyAccess Off
    SecPcreMatchLimit 150000
    SecPcreMatchLimitRecursion 150000
    SecRequestBodyLimit 131072
    SecRequestBodyInMemoryLimit 131072
    SecResponseBodyLimit 524288
    SecUploadKeepFiles Off

    SecAuditEngine RelevantOnly
    SecAuditLogRelevantStatus ^5
    SecAuditLogParts ABIFHZ
    SecAuditLogType Serial
    SecAuditLog /usr/apache/logs/modsec_audit.log
    SecDebugLog /usr/apache/logs/modsec.log
    SecDebugLogLevel 1

    SecRule REQUEST_URI badurltest
    SecDefaultAction 
"phase:2,log,auditlog,deny,redirect:http://www.site.com/412.html"
</IfModule>

When a go to a url like http://www.site.com/index.html?badurltest it 
triggers a log entry like this:

(Continue reading)

Ryan Barnett | 3 Jan 2012 19:06

Re: block and redirect?


On 1/3/12 1:01 PM, "Scott Galambos" <scottg <at> particlesoftware.com> wrote:

>I'm trying to get modsecurity 2.6 going on apache 2.21 under linux.  it
>mostly works.  this is my basic example:
>
><IfModule security2_module>
>    SecRuleEngine On
>    SecRequestBodyAccess On
>    SecResponseBodyAccess Off
>    SecPcreMatchLimit 150000
>    SecPcreMatchLimitRecursion 150000
>    SecRequestBodyLimit 131072
>    SecRequestBodyInMemoryLimit 131072
>    SecResponseBodyLimit 524288
>    SecUploadKeepFiles Off
>
>    SecAuditEngine RelevantOnly
>    SecAuditLogRelevantStatus ^5
>    SecAuditLogParts ABIFHZ
>    SecAuditLogType Serial
>    SecAuditLog /usr/apache/logs/modsec_audit.log
>    SecDebugLog /usr/apache/logs/modsec.log
>    SecDebugLogLevel 1
>
>    SecRule REQUEST_URI badurltest
>    SecDefaultAction
>"phase:2,log,auditlog,deny,redirect:http://www.site.com/412.html"
></IfModule>
>
(Continue reading)

Christian Bockermann | 3 Jan 2012 19:14

Re: block and redirect?

Hi Scott!

Am 03.01.2012 um 19:01 schrieb Scott Galambos:
> I'm trying to get modsecurity 2.6 going on apache 2.21 under linux.  it 
> mostly works.  this is my basic example:
> 
> <IfModule security2_module>
>    SecRuleEngine On
>    SecRequestBodyAccess On
>    SecResponseBodyAccess Off
>    SecPcreMatchLimit 150000
>    SecPcreMatchLimitRecursion 150000
>    SecRequestBodyLimit 131072
>    SecRequestBodyInMemoryLimit 131072
>    SecResponseBodyLimit 524288
>    SecUploadKeepFiles Off
> 
>    SecAuditEngine RelevantOnly
>    SecAuditLogRelevantStatus ^5
>    SecAuditLogParts ABIFHZ
>    SecAuditLogType Serial
>    SecAuditLog /usr/apache/logs/modsec_audit.log
>    SecDebugLog /usr/apache/logs/modsec.log
>    SecDebugLogLevel 1
> 
>    SecRule REQUEST_URI badurltest
>    SecDefaultAction 
> "phase:2,log,auditlog,deny,redirect:http://www.site.com/412.html"
> </IfModule>

(Continue reading)

Scott Galambos | 3 Jan 2012 19:53

Re: block and redirect?

This was it.  Thanks.  I knew it was something basic.

If anyone has a set of basic rules (other then gotroot or OWASP) I'd 
like to see them.  I think OWASP are too large and complicated.

Thanks.

On 1/3/2012 1:14 PM, Christian Bockermann wrote:
> As Ryan posted, you have "deny" and "redirect" in your action. This
> won't work.
>
> You might also want to change the order of your directives here.
>
> "SecDefaultAction" will set the action to be executed for all
> following rules. If you define a rule before changing the default
> action, then this rule will inherit the previously defined default
> action.
>
> See the documentation of SecDefaultAction for details:
>
> 	http://sourceforge.net/apps/mediawiki/mod-security/index.php?title=Reference_Manual#SecDefaultAction
>
> Regards,
>      Chris
>
>

------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create 
(Continue reading)

Reindl Harald | 3 Jan 2012 19:58
Favicon

Re: block and redirect?


Am 03.01.2012 19:53, schrieb Scott Galambos:
> This was it.  Thanks.  I knew it was something basic.
> 
> If anyone has a set of basic rules (other then gotroot or OWASP) I'd 
> like to see them.  I think OWASP are too large and complicated.

and they are TOO bad for many things

most rules for XSS/SQL are damaging normal applications
as long you do not modify them or remove a lot of rules

------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create 
new or port existing apps to sell to consumers worldwide. Explore the 
Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
http://p.sf.net/sfu/intel-appdev
_______________________________________________
mod-security-users mailing list
mod-security-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
Ryan Barnett | 4 Jan 2012 23:21

Virtual Patch for ASP.Net Forms Authentication Bypass Vulnerability (CVE-2011-3416)

Virtual Patch for ASP.Net Forms Authentication Bypass Vulnerability (CVE-2011-3416)
http://blog.spiderlabs.com/2012/01/virtual-patch-for-aspnet-forms-authentication-bypass-vulnerability-cve-2011-3416.html

--
Ryan Barnett
Senior Security Researcher
Trustwave - SpiderLabs

________________________________
This transmission may contain information that is privileged, confidential, and/or exempt from
disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any
disclosure, copying, distribution, or use of the information contained herein (including any reliance
thereon) is STRICTLY PROHIBITED. If you received this transmission in error, please immediately
contact the sender and destroy the material in its entirety, whether in electronic or hard copy format.

------------------------------------------------------------------------------
Ridiculously easy VDI. With Citrix VDI-in-a-Box, you don't need a complex
infrastructure or vast IT resources to deliver seamless, secure access to
virtual desktops. With this all-in-one solution, easily deploy virtual 
desktops for less than the cost of PCs and save 60% on VDI infrastructure 
costs. Try it free! http://p.sf.net/sfu/Citrix-VDIinabox
_______________________________________________
mod-security-users mailing list
mod-security-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

(Continue reading)

Sean O'Sullivan | 10 Jan 2012 09:49
Picon
Favicon

SQLi False positive

Hi

There is a page on our website called Individual...  ModSecurity is generating a false positive because the page name contains the word div, I have included the logs below.  Is there any way to exclude a parameter from a rule if it contains a certain text string. 

I know this wont work but it is an example of what I am trying to do :  SecRuleUpdateTargetById 981244 !ARGS:pageType " <at> contains div".

Message: Warning. Pattern match "(?i:(?:\\d(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+\\d)|(?:^admin\\s*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)|(\\/\\*)+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)+\\s?(?:--|#|\\/\\*|{)?)|(?:(\"|'| ..." at ARGS:pageType. [file "/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"] [line "533"] [id "981244"] [msg "Detects basic SQL authentication bypass attempts 1/3"] [data "div"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQLI"] [tag "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
Message: Warning. Pattern match "(?i:(?:(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s*\\*.+(?:x?or|div|like|between|and|id)\\W*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\d)|(?:\\^(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98))|(?:^[\\w\\s(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)-]+( ..." at ARGS:pageType. [file "/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"] [line "573"] [id "981243"] [msg "Detects classic SQL injection probings 2/2"] [data "div"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQLI"] [tag "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
Message: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/etc/apache2/modsecurity_crs/modsecurity_crs_60_correlation.conf"] [line "37"] [id "981204"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 13, SQLi=, XSS=): 981243-Detects classic SQL injection probings 2/2"]
Apache-Handler: proxy-server
Stopwatch: 1326169975607617 51819 (- - -)
Stopwatch2: 1326169975607617 51819; combined=4777, p1=174, p2=4443, p3=1, p4=59, p5=100, sr=45, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.6.0 (http://www.modsecurity.org/); core ruleset/2.2.3.
Server: Apache/2.2.17 (

Thanks in advance.  Regards,
Sean
------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create 
new or port existing apps to sell to consumers worldwide. Explore the 
Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
http://p.sf.net/sfu/intel-appdev
_______________________________________________
mod-security-users mailing list
mod-security-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
Reindl Harald | 10 Jan 2012 11:26
Favicon

Re: SQLi False positive

this whole rule is crap!
it blocks even urls like http://yourdomain/diverses/index.htm

Am 10.01.2012 09:49, schrieb Sean O'Sullivan:
> Hi
> 
> There is a page on our website called Individual...  ModSecurity is generating a false positive because
the page
> name contains the word div, I have included the logs below.  Is there any way to exclude a parameter from a
rule if
> it contains a certain text string. 
> 
> I know this wont work but it is an example of what I am trying to do :  SecRuleUpdateTargetById 981244
> !ARGS:pageType " <at> contains div".
> 
> Message: Warning. Pattern match
> "(?i:(?:\\d(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+\\d)|(?:^admin\\s*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)|(\\/\\*)+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)+\\s?(?:--|#|\\/\\*|{)?)|(?:(\"|'|
> ..." at ARGS:pageType. [file
"/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"] [line
> "533"] [id "981244"] [msg "Detects basic SQL authentication bypass attempts 1/3"] [data "div"] [severity
> "CRITICAL"] [tag "WEB_ATTACK/SQLI"] [tag "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
> Message: Warning. Pattern match
> "(?i:(?:(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s*\\*.+(?:x?or|div|like|between|and|id)\\W*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\d)|(?:\\^(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98))|(?:^[\\w\\s(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)-]+(
> ..." at ARGS:pageType. [file
"/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"] [line
> "573"] [id "981243"] [msg "Detects classic SQL injection probings 2/2"] [data "div"] [severity
"CRITICAL"] [tag
> "WEB_ATTACK/SQLI"] [tag "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
> Message: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file
> "/etc/apache2/modsecurity_crs/modsecurity_crs_60_correlation.conf"] [line "37"] [id "981204"]
[msg "Inbound Anomaly
> Score Exceeded (Total Inbound Score: 13, SQLi=, XSS=): 981243-Detects classic SQL injection probings 2/2"]
> Apache-Handler: proxy-server
> Stopwatch: 1326169975607617 51819 (- - -)
> Stopwatch2: 1326169975607617 51819; combined=4777, p1=174, p2=4443, p3=1, p4=59, p5=100, sr=45,
sw=0, l=0, gc=0
> Response-Body-Transformed: Dechunked
> Producer: ModSecurity for Apache/2.6.0 (http://www.modsecurity.org/); core ruleset/2.2.3.
> Server: Apache/2.2.17 (
> 
> Thanks in advance.  Regards,
> Sean
> 
> 
> ------------------------------------------------------------------------------
> Write once. Port to many.
> Get the SDK and tools to simplify cross-platform app development. Create 
> new or port existing apps to sell to consumers worldwide. Explore the 
> Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
> http://p.sf.net/sfu/intel-appdev
> 
> 
> 
> _______________________________________________
> mod-security-users mailing list
> mod-security-users <at> lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/

-- 

Mit besten Grüßen, Reindl Harald
the lounge interactive design GmbH
A-1060 Vienna, Hofmühlgasse 17
CTO / software-development / cms-solutions
p: +43 (1) 595 3999 33, m: +43 (676) 40 221 40
icq: 154546673, http://www.thelounge.net/

http://www.thelounge.net/signature.asc.what.htm

------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create 
new or port existing apps to sell to consumers worldwide. Explore the 
Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
http://p.sf.net/sfu/intel-appdev
_______________________________________________
mod-security-users mailing list
mod-security-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
Josh Amishav-Zlatin | 10 Jan 2012 11:37
Picon

Re: SQLi False positive

On Tue, Jan 10, 2012 at 10:49 AM, Sean O'Sullivan <dits_ltd <at> hotmail.com> wrote:
> Hi
>
> There is a page on our website called Individual...  ModSecurity is
> generating a false positive because the page name contains the word div, I
> have included the logs below.  Is there any way to exclude a parameter from
> a rule if it contains a certain text string.

Hi Sean,

What about:
SecRule ARGS:pageType " <at> contains div"
"phase:2,t:none,log,pass,ctl:ruleUpdateTargetById=981244;!ARGS:pageType"

or

SecRule REQUEST_URI Individual "phase:2,t:none,chain,ctl:ruleRemoveById=981244
  SecRule ARGS:pageType " <at> contains div"

--
 - Josh

>
> I know this wont work but it is an example of what I am trying to do :
> SecRuleUpdateTargetById 981244 ! " <at> contains div".ARGS:pageType
>
> Message: Warning. Pattern match
> "(?i:(?:\\d(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+\\d)|(?:^admin\\s*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)|(\\/\\*)+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)+\\s?(?:--|#|\\/\\*|{)?)|(?:(\"|'|
> ..." at ARGS:pageType. [file
> "/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"]
> [line "533"] [id "981244"] [msg "Detects basic SQL authentication bypass
> attempts 1/3"] [data "div"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQLI"]
> [tag "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
> Message: Warning. Pattern match
> "(?i:(?:(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s*\\*.+(?:x?or|div|like|between|and|id)\\W*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\d)|(?:\\^(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98))|(?:^[\\w\\s(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)-]+(
> ..." at ARGS:pageType. [file
> "/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"]
> [line "573"] [id "981243"] [msg "Detects classic SQL injection probings
> 2/2"] [data "div"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQLI"] [tag
> "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
> Message: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file
> "/etc/apache2/modsecurity_crs/modsecurity_crs_60_correlation.conf"] [line
> "37"] [id "981204"] [msg "Inbound Anomaly Score Exceeded (Total Inbound
> Score: 13, SQLi=, XSS=): 981243-Detects classic SQL injection probings 2/2"]
> Apache-Handler: proxy-server
> Stopwatch: 1326169975607617 51819 (- - -)
> Stopwatch2: 1326169975607617 51819; combined=4777, p1=174, p2=4443, p3=1,
> p4=59, p5=100, sr=45, sw=0, l=0, gc=0
> Response-Body-Transformed: Dechunked
> Producer: ModSecurity for Apache/2.6.0 (http://www.modsecurity.org/); core
> ruleset/2.2.3.
> Server: Apache/2.2.17 (
>
> Thanks in advance.  Regards,
> Sean
>
> ------------------------------------------------------------------------------
> Write once. Port to many.
> Get the SDK and tools to simplify cross-platform app development. Create
> new or port existing apps to sell to consumers worldwide. Explore the
> Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
> http://p.sf.net/sfu/intel-appdev
> _______________________________________________
> mod-security-users mailing list
> mod-security-users <at> lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create 
new or port existing apps to sell to consumers worldwide. Explore the 
Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
http://p.sf.net/sfu/intel-appdev
_______________________________________________
mod-security-users mailing list
mod-security-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
Sean O'Sullivan | 10 Jan 2012 12:48
Picon
Favicon

Re: SQLi False positive

Hi Josh,

Thanks a mil for this, I will try it out today.  I did something similar, guided by the modsecurity handbook tutorial, but it didn't work.  I take it this needs to be added to a low number conf file e.g. modsecurity_crs_15_customrules.conf?  I'll let you know how it goes.  Thanks again Josh.

Sean

> From: jamuse <at> gmail.com
> Date: Tue, 10 Jan 2012 12:37:08 +0200
> Subject: Re: [mod-security-users] SQLi False positive
> To: dits_ltd <at> hotmail.com
> CC: mod-security-users <at> lists.sourceforge.net
>
> On Tue, Jan 10, 2012 at 10:49 AM, Sean O'Sullivan <dits_ltd <at> hotmail.com> wrote:
> > Hi
> >
> > There is a page on our website called Individual...  ModSecurity is
> > generating a false positive because the page name contains the word div, I
> > have included the logs below.  Is there any way to exclude a parameter from
> > a rule if it contains a certain text string.
>
> Hi Sean,
>
> What about:
> SecRule ARGS:pageType " <at> contains div"
> "phase:2,t:none,log,pass,ctl:ruleUpdateTargetById=981244;!ARGS:pageType"
>
> or
>
> SecRule REQUEST_URI Individual "phase:2,t:none,chain,ctl:ruleRemoveById=981244
> SecRule ARGS:pageType " <at> contains div"
>
> --
> - Josh
>
> >
> > I know this wont work but it is an example of what I am trying to do :
> > SecRuleUpdateTargetById 981244 ! " <at> contains div".ARGS:pageType
> >
> > Message: Warning. Pattern match
> > "(?i:(?:\\d(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s+\\d)|(?:^admin\\s*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)|(\\/\\*)+(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)+\\s?(?:--|#|\\/\\*|{)?)|(?:(\"|'|
> > ..." at ARGS:pageType. [file
> > "/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"]
> > [line "533"] [id "981244"] [msg "Detects basic SQL authentication bypass
> > attempts 1/3"] [data "div"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQLI"]
> > [tag "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
> > Message: Warning. Pattern match
> > "(?i:(?:(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\s*\\*.+(?:x?or|div|like|between|and|id)\\W*(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)\\d)|(?:\\^(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98))|(?:^[\\w\\s(\"|'|`|\xc2\xb4|\xe2\x80\x99|\xe2\x80\x98)-]+(
> > ..." at ARGS:pageType. [file
> > "/etc/apache2/modsecurity_crs/modsecurity_crs_41_sql_injection_attacks.conf"]
> > [line "573"] [id "981243"] [msg "Detects classic SQL injection probings
> > 2/2"] [data "div"] [severity "CRITICAL"] [tag "WEB_ATTACK/SQLI"] [tag
> > "WEB_ATTACK/ID"] [tag "WEB_ATTACK/LFI"]
> > Message: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file
> > "/etc/apache2/modsecurity_crs/modsecurity_crs_60_correlation.conf"] [line
> > "37"] [id "981204"] [msg "Inbound Anomaly Score Exceeded (Total Inbound
> > Score: 13, SQLi=, XSS=): 981243-Detects classic SQL injection probings 2/2"]
> > Apache-Handler: proxy-server
> > Stopwatch: 1326169975607617 51819 (- - -)
> > Stopwatch2: 1326169975607617 51819; combined=4777, p1=174, p2=4443, p3=1,
> > p4=59, p5=100, sr=45, sw=0, l=0, gc=0
> > Response-Body-Transformed: Dechunked
> > Producer: ModSecurity for Apache/2.6.0 (http://www.modsecurity.org/); core
> > ruleset/2.2.3.
> > Server: Apache/2.2.17 (
> >
> > Thanks in advance.  Regards,
> > Sean
> >
> > ------------------------------------------------------------------------------
> > Write once. Port to many.
> > Get the SDK and tools to simplify cross-platform app development. Create
> > new or port existing apps to sell to consumers worldwide. Explore the
> > Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
> > http://p.sf.net/sfu/intel-appdev
> > _______________________________________________
> > mod-security-users mailing list
> > mod-security-users <at> lists.sourceforge.net
> > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > http://www.modsecurity.org/projects/commercial/rules/
> > http://www.modsecurity.org/projects/commercial/support/
> >
------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create 
new or port existing apps to sell to consumers worldwide. Explore the 
Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
http://p.sf.net/sfu/intel-appdev
_______________________________________________
mod-security-users mailing list
mod-security-users <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

Gmane