<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user">
    <title>gmane.comp.apache.mod-security.user</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9398"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9397"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9396"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9395"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9394"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9393"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9392"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9391"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9390"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9389"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9388"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9387"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9386"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9385"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9384"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9383"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9382"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9381"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9380"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9379"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9398">
    <title>Compiling modsecurity 2.6.5 for apache 2.0.x</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9398</link>
    <description>&lt;pre&gt;Hi, I am trying to compile ModSecurity 2.6.5 for Apache 2.0.x on a Redhat Enterprise v6.2, x86_64. In the configure step, I specified --with-pcre=/usr which is Redhat's built-in pcre v7.8. When I compiled Apache 2.0.x, I specified the same for pcre. The configure step saw RHEL's pcre and passed. In the make process, I got a message:

....
/bin/sh ../libtool  --tag=CC   --mode=compile gcc -DHAVE_CONFIG_H -I.  -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE    -I/opt/apache2.0.54/include  -I/opt/apache2.0.54/include   -I/opt/apache2.0.54/include -I/usr/include/libxml2  -DWITH_PCRE_STUDY -DMODSEC_PCRE_MATCH_LIMIT=1500 -DMODSEC_PCRE_MATCH_LIMIT_RECURSION=1500        -g -O2 -MT mod_security2_la-msc_pcre.lo -MD -MP -MF .deps/mod_security2_la-msc_pcre.Tpo -c -o mod_security2_la-msc_pcre.lo `test -f 'msc_pcre.c' || echo './'`msc_pcre.c
libtool: compile:  gcc -DHAVE_CONFIG_H -I. -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -I/opt/apache2.0.54/include -I/opt/apache2.0.54/include -I/opt/apache2.0.54/include -I/usr/include/libxml2 -DWITH_&lt;/pre&gt;</description>
    <dc:creator>Ruiyuan Jiang</dc:creator>
    <dc:date>2012-05-24T22:11:23</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9397">
    <title>Re: Forum reply being blocked by mod_security</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9397</link>
    <description>&lt;pre&gt;
From: "retired1af&amp;lt; at &amp;gt;gmail.com&amp;lt;mailto:retired1af&amp;lt; at &amp;gt;gmail.com&amp;gt;" &amp;lt;retired1af&amp;lt; at &amp;gt;gmail.com&amp;lt;mailto:retired1af&amp;lt; at &amp;gt;gmail.com&amp;gt;&amp;gt;
Date: Tue, 22 May 2012 07:17:57 -0500
To: "mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net&amp;lt;mailto:mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net&amp;gt;" &amp;lt;mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net&amp;lt;mailto:mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net&amp;gt;&amp;gt;
Subject: [mod-security-users] Forum reply being blocked by mod_security

I'm not getting very far with the software developers so I'm now appealing to the experts here to find a solution to my problem.

It appears mod_security is triggering on the word nmap within a forum post, preventing replies to the thread. Link is here: http://www.globalaffairs.org/forum/threads/nmap-6-released.68912/

The mod_security log shows the following:

Access denied with code 501 (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\&lt;/pre&gt;</description>
    <dc:creator>Ryan Barnett</dc:creator>
    <dc:date>2012-05-22T12:37:11</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9396">
    <title>Re: Forum reply being blocked by mod_security</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9396</link>
    <description>&lt;pre&gt;
Hi,

It might be better to post this on the CRS mailing list, as the problem
your having is due to a false positive in the core rule set. In any case,
there are a few ways you can whitelist this rule from firing, depending on
which version of ModSecurity your running. For details take a look at:
http://blog.spiderlabs.com/2011/08/modsecurity-advanced-topic-of-the-week-exception-handling.html

--
 - Josh


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and &lt;/pre&gt;</description>
    <dc:creator>Josh Amishav-Zlatin</dc:creator>
    <dc:date>2012-05-22T12:34:29</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9395">
    <title>Forum reply being blocked by mod_security</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9395</link>
    <description>&lt;pre&gt;I'm not getting very far with the software developers so I'm now appealing  
to the experts here to find a solution to my problem.

It appears mod_security is triggering on the word nmap within a forum post,  
preventing replies to the thread. Link is here:  
http://www.globalaffairs.org/forum/threads/nmap-6-released.68912/

The mod_security log shows the following:

Access denied with code 501 (phase 2). Pattern  
match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)| 
t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd| 
ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)| 
d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at  
REQUEST_HEADERS:X-Ajax-Referer.  
[file "/usr/local/apache/conf/modsec2.user.conf"] [line "149"]  
[id "959006"] [msg "System Command Injection"] [data "/nmap-"]  
[severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"]

This is the first time I've run across this, but it seems to be a common  
occurrence with the Xen Foro &lt;/pre&gt;</description>
    <dc:creator>retired1af&lt; at &gt;gmail.com</dc:creator>
    <dc:date>2012-05-22T12:17:57</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9394">
    <title>AuditConsole 0.4.6 released!</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9394</link>
    <description>&lt;pre&gt;Dear ModSecurity users,

I am happy to announce the release of the next version of AuditConsole, the
free log-management tool for ModSecurity.

This version comes with a clean-up of the web-interface, lots of bug-fixes,
support for OpenID authentication and an internal pipe-lining model that will
allow further customization of audit-event processing in the future.

The AuditConsole is available in multiple editions (debian package, RPM package,
standalone, WAR archive) at

http://download.jwall.org/AuditConsole/0.4.6/


For details see my blog-post at

       https://secure.jwall.org/blog/2012/05/22/1337638334497.html


Best regards,

    Chris
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/s&lt;/pre&gt;</description>
    <dc:creator>Christian Bockermann</dc:creator>
    <dc:date>2012-05-22T06:28:52</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9393">
    <title>error when creating rule for op "rx"</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9393</link>
    <description>&lt;pre&gt;Hi,

I am encountering some problem when trying to compile the latest version
mod_security-apache_2.6.5 onto my Ubuntu Server 12.04 LTS. When I run "make
CFLAGS=-DMSC_TEST test, I received the following error message:

ERROR: Failed to create rule for op "rx": Error creating rule: Error
compiling pattern (offset 2): unrecognized character after (? or (?-
make[2]: *** [check-TESTS] Error 1
make[1]: *** [check-am] Error 2

Below is a more detailed message contributing to the above error

Loaded 8 tests from ./op/rx.t
     1) op "rx": passed (Pattern match "" at UNIT_TEST.)
     2) op "rx": passed
     3) op "rx": passed (Pattern match "" at UNIT_TEST.)
     4) op "rx": passed (Pattern match "abc" at UNIT_TEST.)
     5) op "rx": passed (Pattern match "def" at UNIT_TEST.)
     6) op "rx": passed (Pattern match "ghi" at UNIT_TEST.)
     7) op "rx": passed
Test exited with signal 11.
Executed: ./msc_test "-t" "op" "-n" "rx" "-p"
"(?^i:^([^=])\s*=\s*((?:abc)+(?:def|ghi){2})$)" "-D" "0" "-r" "1"
     8) op "rx": fai&lt;/pre&gt;</description>
    <dc:creator>daminto lee</dc:creator>
    <dc:date>2012-05-22T01:26:38</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9392">
    <title>Re: Persistent collections and errors inApache error_log</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9392</link>
    <description>&lt;pre&gt;Hi Luca,

Looks like an old bug https://www.modsecurity.org/tracker/browse/MODSEC-97.
Marked as closed.
I will be traveling during next week. But i will contact you and try to
debug it.

Thanks

Breno

On Mon, May 21, 2012 at 10:12 AM, Luca &amp;lt;superpizza&amp;lt; at &amp;gt;bigfoot.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercia&lt;/pre&gt;</description>
    <dc:creator>Breno Silva</dc:creator>
    <dc:date>2012-05-21T15:25:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9391">
    <title>Persistent collections and errors in Apache error_log</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9391</link>
    <description>&lt;pre&gt;Hello everyone.
I'm getting a lot of error entries related to access to DBM file used to store 
collections data.
DBM file is huge, aroung 1GB, I think it never shrinks.
Here a couple of examples:
ModSecurity: Failed deleting collection (name "ip", key
 "93.57.22.65_c40a1a4c63dc22a36a4dacec0e35e80139000959"): Internal error
 [hostname  "XYZ"] [uri "XYZ"] [unique_id "T7pTQApRQSoAAH3H7OIAAABF"]

ModSecurity: Failed to access DBM file 
"/usr/local/apache/rproxyworker/logs/data/ip": Resource deadlock avoided
 [hostname  "XYZ"] [uri "XYZ"] [unique_id "T7nbtgpRQSoAACUgnxIAAAEH"]

Current installation is:
RHEL6, 64bit
Apache: 2.2.22
ModSec: 2.6.5
CRS: 2.2.4 

Configuration:
SecCollectionTimeout 180

I'm using the standar collections created in 2.2.4
Thank you for your help.
Luca



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respo&lt;/pre&gt;</description>
    <dc:creator>Luca</dc:creator>
    <dc:date>2012-05-21T15:12:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9390">
    <title>Re: New to Modsecurity: I Need to allow directory traversal to a single virtual host</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9390</link>
    <description>&lt;pre&gt;

On 5/19/12 4:58 PM, "mrnicholsb" &amp;lt;mrnicholsb&amp;lt; at &amp;gt;gmail.com&amp;gt; wrote:


The subject line says "Directory Traversal" but you are talking about
"Directory Indexing" which are two separate issues.  I am assuming, based
on the email body, that you are hitting the following rule in the
modsecurity_crs_50_outbound.conf file -

# Directory Listing
SecRule RESPONSE_BODY "(?:&amp;lt;(?:TITLE&amp;gt;Index of.*?&amp;lt;H|title&amp;gt;Index
of.*?&amp;lt;h)1&amp;gt;Index of|&amp;gt;[To Parent Directory]&amp;lt;\/[Aa]&amp;gt;&amp;lt;br&amp;gt;)" \

"phase:4,rev:'2.2.5',t:none,capture,ctl:auditLogParts=+E,block,msg:'Directo
ry
Listing',id:'970013',tag:'LEAKAGE/INFO_DIRECTORY_LISTING',tag:'WASCTC/WASC-
13',tag:
'OWASP_TOP_10/A6',tag:'PCI/6.5.6',severity:'3',setvar:'tx.msg=%{rule.msg}',
setvar:tx.outbound_anomaly_score=+%{tx.error_anomaly_score},setvar:tx.anoma
ly_score=+%{tx.erro
r_anomaly_score},setvar:tx.%{rule.id}-LEAKAGE/INFO-%{matched_var_name}=%{tx
.0}"


If so, and you want to allow this for a specific vhost, then you could do
an exception like this in a local modsecurity_crs_15_custom.conf file -&lt;/pre&gt;</description>
    <dc:creator>Ryan Barnett</dc:creator>
    <dc:date>2012-05-19T21:26:31</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9389">
    <title>New to Modsecurity: I Need to allow directory traversal to a single virtual host</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9389</link>
    <description>&lt;pre&gt;Hello all, Im new to modsecurity and forgive me if this is a noobish 
question.

But I have a virtual host that I have a lot of iso files on that I would 
like to have directory indexing allowed on just that host.

I have my .htaccess file as follows

Options +Indexes

But ever since I got mod_security running its being ignored, is there a 
way to tell
modsecurity to respect .htaccess files?

Should I just forget about .htaccess all together while running 
mod_security?

And how would I go about adding an exception to modsecurity to allow 
indexing on this virtual host?

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
m&lt;/pre&gt;</description>
    <dc:creator>mrnicholsb</dc:creator>
    <dc:date>2012-05-19T20:58:22</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9388">
    <title>Re: Capturing Internal Server Errors</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9388</link>
    <description>&lt;pre&gt;Thanks Ryan, switched to use phase:3 and now it works :).
Cheers !!!

I have:

SecRule RESPONSE_STATUS "^[5]" \
"phase:3,t:none,log,pass,id:'500002',tag:'INTERNAL SERVER ERROR  
5xx',msg:'Internal Server Error  
5xx.',setvar:tx.anomaly_score=+%{tx.critical_anomaly     
_score},logdata:'%{response_status}',severity:1"




&lt;/pre&gt;</description>
    <dc:creator>Usman</dc:creator>
    <dc:date>2012-05-17T11:54:29</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9387">
    <title>Re: Capturing Internal Server Errors</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9387</link>
    <description>&lt;pre&gt;Gotta use phase 3 4 or 5 to access the RESPONSE_STATUS var. It is not available yet in phases 1 and 2.

Ryan

On May 17, 2012, at 7:37 AM, "Usman" &amp;lt;usmanw&amp;lt; at &amp;gt;opera.com&amp;gt; wrote:


This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is STRICTLY PROHIBITED. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format.


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http:/&lt;/pre&gt;</description>
    <dc:creator>Ryan Barnett</dc:creator>
    <dc:date>2012-05-17T11:45:14</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9386">
    <title>Capturing Internal Server Errors</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9386</link>
    <description>&lt;pre&gt;Hi,

I have the following directive in my crs_10 file:

SecAuditLogRelevantStatus "^(?:5|0(?!04))"

This logs 500 internal server errors when they happen.

I would like to set some attributes like tag, msg, severity etc for the  
above when viewing the alert in the AuditConsole.

I tried using the following rule but no luck:

SecRule RESPONSE_STATUS "&amp;lt; at &amp;gt;eq 500" \
"phase:2,t:none,log,pass,id:'500002',tag:'INTERNAL SERVER ERROR  
500',msg:'Internal Server Error  
500.',setvar:tx.anomaly_score=+%{tx.critical_anomaly_score},logdata:'%{response_status}',severity:1"

Based on the docs i found the below which does not give me the desired  
result:

SecRule RESPONSE_STATUS "^[5]" \
"phase:2,t:none,log,pass,id:'500002',tag:'INTERNAL SERVER ERROR  
5xx',msg:'Internal Server Error  
5xx.',setvar:tx.anomaly_score=+%{tx.critical_anomaly_s     
core},logdata:'%{response_status}',severity:1"

but then there was a note in the docs saying:

"This directive may not work as expected in embedded-mode as Apache  
handles many of t&lt;/pre&gt;</description>
    <dc:creator>Usman</dc:creator>
    <dc:date>2012-05-17T11:33:02</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9385">
    <title>Own POST Rate Limit Rule not Working</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9385</link>
    <description>&lt;pre&gt;Hi all, 

we have tried to write a  ModSecurity rule to limit POST Requests. But the limit does not work as expected.


Here is the rule:

 SecRule REQUEST_METHOD "^POST$" "phase:1,nolog,initcol:IP=%{REMOTE_ADDR},setvar:IP.pagecount=+1,expirevar:IP.pagecount=60"
 SecRule IP:PAGECOUNT "&amp;lt; at &amp;gt;gt 250" "phase:1,deny,status:403,msg:'Too many requests'"

The "pagecount" counter does not work correctly. as we have a few IP's with anly 10 requests and all requests are "GET" , with a pagecount of 250. 
Where is our error?

We are using ModSecurity on Debian 6, in Version 2.5.12


Regards,
------------------------------------------------------------------------ 
 Thomas Berger 
 - Certified Linux/Cisco Networking Engineer - 
 BOREUS Rechenzentrum GmbH 
 Zur Schwedenschanze 2 
 D - 18435 Stralsund 
 Germany 
 Phone:+49 (0) 38 31 - 36 76 415 
 Fax: +49 (0) 38 31 - 36 76 615 
 eMail: tbe&amp;lt; at &amp;gt;boreus.de 
 Internet: http://www.boreus.de/ 
 -------------------------------------------------------------------------- 
 Geschäftsführer&lt;/pre&gt;</description>
    <dc:creator>Thomas Berger</dc:creator>
    <dc:date>2012-05-11T12:45:10</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9384">
    <title>Re: 2.6.5 Compile Question</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9384</link>
    <description>&lt;pre&gt;Hello Dan,

The version 2.6.5 still have some issues with current Apache 2.4 code. The
2.7 version must fix it and will be released soon. If you want i can send
you a tarball for testing.

Thanks

Breno

On Thu, May 10, 2012 at 5:07 PM, Dan Denton &amp;lt;ddenton&amp;lt; at &amp;gt;remitpro.com&amp;gt; wrote:

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/comm&lt;/pre&gt;</description>
    <dc:creator>Breno Silva</dc:creator>
    <dc:date>2012-05-10T22:37:45</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9383">
    <title>2.6.5 Compile Question</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9383</link>
    <description>&lt;pre&gt;I'm compiling modsec 2.6.5 against Apache 2.4.2, and during a "make CFLAGS=-DMSC_TEST test" I get the following:

msc_test-modsecurity.o: In function `modsecurity_init':
modsecurity.c:(.text+0x240): undefined reference to `ap_unixd_set_global_mutex_perms'
modsecurity.c:(.text+0x291): undefined reference to `ap_unixd_set_global_mutex_perms'
collect2: ld returned 1 exit status
make[2]: *** [msc_test] Error 1
make[2]: Leaving directory `/opt/modsecurity-apache_2.6.5/tests'
make[1]: *** [check-am] Error 2
make[1]: Leaving directory `/opt/modsecurity-apache_2.6.5/tests'
make: *** [check-recursive] Error 1

I'm having trouble finding a work-around or solution for this. Can anyone point me in the right direction?

Thanks,

Dan

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile&lt;/pre&gt;</description>
    <dc:creator>Dan Denton</dc:creator>
    <dc:date>2012-05-10T22:07:44</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9382">
    <title>Re: ModSecurity starting, but not logging even with debug</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9382</link>
    <description>&lt;pre&gt;
Hi Steve,

Perhaps there's a configuration issue. Can you send me you config
files privately?

--
 - Josh




------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
&lt;/pre&gt;</description>
    <dc:creator>Josh Amishav-Zlatin</dc:creator>
    <dc:date>2012-05-10T17:03:45</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9381">
    <title>SecRule 981317</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9381</link>
    <description>&lt;pre&gt;In modsecurity_crs_41_sql_injection_attacks.conf, rule ID 981317 looks for
the following:

SecRule TX:SQLI_SELECT_STATEMENT_COUNT "&amp;lt; at &amp;gt;ge 3"
"phase:2,t:none,block,id:'981317'ŠŠŠ.


Which if the *_COUNT is equal to or greater the 3 of the list of SQL key
words, issue a 403 error.

I have two variable fields that consist of pure text fields where the SQL
key words will most likely be hit, i.e.: the count will equal 3 or greater
very easily.  These fields are not SQL in nature.

How can I perform the equivalent  of an if-else-then where if variables
coverLetterTxt or resumeTXT is scanned, to not perform the 981317 processŠ
I do not care if the word count reaches 20000 for these two variables
where SQL injection is concerned, but for the many other fields, I do want
these tests to be performed and permission denied in the event of an SQL
attack.

For these two fields, I do have a while list on the ASCII characters from
X01-X7F, allow.  Do I need another allow statement with the inclusion of
the SQL key words su&lt;/pre&gt;</description>
    <dc:creator>Canell, Stephen E (2240</dc:creator>
    <dc:date>2012-05-10T16:40:21</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9380">
    <title>Re: ModSecurity starting, but not logging even with debug</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9380</link>
    <description>&lt;pre&gt;Another data point.  I have tried standard logging and logging with mlogc
(neither of which produce logs).   When I set it use mlogc, mlogc is not
showing up in the ps output so apache is not trying to run it (or is
failing to).  I have verified that the mlogc executable is in the location
pointed to by the config.

Steve




------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commerci&lt;/pre&gt;</description>
    <dc:creator>mjs&lt; at &gt;terabox.org</dc:creator>
    <dc:date>2012-05-10T15:45:15</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9379">
    <title>Re: ModSecurity starting, but not logging even with debug</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9379</link>
    <description>&lt;pre&gt;Yes.  Verified with lsof that it is being loaded.

Thanks,
Steve




------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

&lt;/pre&gt;</description>
    <dc:creator>mjs&lt; at &gt;terabox.org</dc:creator>
    <dc:date>2012-05-10T14:30:14</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9378">
    <title>Re: REQUEST_BODY has some XML</title>
    <link>http://permalink.gmane.org/gmane.comp.apache.mod-security.user/9378</link>
    <description>&lt;pre&gt;Just wanted to share with the rest, Ryan's pointer worked for me.

In my modsecurity_crs_10_config.conf i set:

SecRule REQUEST_FILENAME "&amp;lt; at &amp;gt;streq /cgi-bin/form.pl" \
"chain,phase:1,id:'981053',t:none,t:lowercase,pass,nolog"
SecRule REQBODY_PROCESSOR "!&amp;lt; at &amp;gt;streq XML" "ctl:requestBodyProcessor=XML"

In my modsecurity_crs_15_customrules.conf i set:

SecRule XML "&amp;lt; at &amp;gt;validateSchema /etc/apache2/xsd/test.xsd" \
"phase:2,log,auditlog,deny,status:403,msg:'XSD check failed',tag:'MOD  
SECURITY  
TEST',setvar:tx.anomaly_score=+%{tx.critical_anomaly_score},id:'500001',severity:2"

With the above settings, i was able to test a request (to:  
/cgi/bin/form.pl) with REQUEST_HEADER = Content-type:  
application/x-www-form-urlencoded and changed the xml values in my post to  
make the xsd check fail.

Thanks much,
-Usman



&lt;/pre&gt;</description>
    <dc:creator>Usman Waheed</dc:creator>
    <dc:date>2012-05-10T11:59:47</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.apache.mod-security.user">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.apache.mod-security.user</link>
  </textinput>
</rdf:RDF>

