<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://blog.gmane.org/gmane.comp.apache.mod-security.user">
    <title>gmane.comp.apache.mod-security.user</title>
    <link>http://blog.gmane.org/gmane.comp.apache.mod-security.user</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9398"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9395"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9394"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9393"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9391"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9389"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9386"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9385"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9383"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9381"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9375"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9372"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9370"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9366"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9361"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9357"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9355"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9354"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9352"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9350"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9398">
    <title>Compiling modsecurity 2.6.5 for apache 2.0.x</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9398</link>
    <description>&lt;pre&gt;Hi, I am trying to compile ModSecurity 2.6.5 for Apache 2.0.x on a Redhat Enterprise v6.2, x86_64. In the configure step, I specified --with-pcre=/usr which is Redhat's built-in pcre v7.8. When I compiled Apache 2.0.x, I specified the same for pcre. The configure step saw RHEL's pcre and passed. In the make process, I got a message:

....
/bin/sh ../libtool  --tag=CC   --mode=compile gcc -DHAVE_CONFIG_H -I.  -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE    -I/opt/apache2.0.54/include  -I/opt/apache2.0.54/include   -I/opt/apache2.0.54/include -I/usr/include/libxml2  -DWITH_PCRE_STUDY -DMODSEC_PCRE_MATCH_LIMIT=1500 -DMODSEC_PCRE_MATCH_LIMIT_RECURSION=1500        -g -O2 -MT mod_security2_la-msc_pcre.lo -MD -MP -MF .deps/mod_security2_la-msc_pcre.Tpo -c -o mod_security2_la-msc_pcre.lo `test -f 'msc_pcre.c' || echo './'`msc_pcre.c
libtool: compile:  gcc -DHAVE_CONFIG_H -I. -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -I/opt/apache2.0.54/include -I/opt/apache2.0.54/include -I/opt/apache2.0.54/include -I/usr/include/libxml2 -DWITH_&lt;/pre&gt;</description>
    <dc:creator>Ruiyuan Jiang</dc:creator>
    <dc:date>2012-05-24T22:11:23</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9395">
    <title>Forum reply being blocked by mod_security</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9395</link>
    <description>&lt;pre&gt;I'm not getting very far with the software developers so I'm now appealing  
to the experts here to find a solution to my problem.

It appears mod_security is triggering on the word nmap within a forum post,  
preventing replies to the thread. Link is here:  
http://www.globalaffairs.org/forum/threads/nmap-6-released.68912/

The mod_security log shows the following:

Access denied with code 501 (phase 2). Pattern  
match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)| 
t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd| 
ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)| 
d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at  
REQUEST_HEADERS:X-Ajax-Referer.  
[file "/usr/local/apache/conf/modsec2.user.conf"] [line "149"]  
[id "959006"] [msg "System Command Injection"] [data "/nmap-"]  
[severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"]

This is the first time I've run across this, but it seems to be a common  
occurrence with the Xen Foro &lt;/pre&gt;</description>
    <dc:creator>retired1af&lt; at &gt;gmail.com</dc:creator>
    <dc:date>2012-05-22T12:17:57</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9394">
    <title>AuditConsole 0.4.6 released!</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9394</link>
    <description>&lt;pre&gt;Dear ModSecurity users,

I am happy to announce the release of the next version of AuditConsole, the
free log-management tool for ModSecurity.

This version comes with a clean-up of the web-interface, lots of bug-fixes,
support for OpenID authentication and an internal pipe-lining model that will
allow further customization of audit-event processing in the future.

The AuditConsole is available in multiple editions (debian package, RPM package,
standalone, WAR archive) at

http://download.jwall.org/AuditConsole/0.4.6/


For details see my blog-post at

       https://secure.jwall.org/blog/2012/05/22/1337638334497.html


Best regards,

    Chris
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/s&lt;/pre&gt;</description>
    <dc:creator>Christian Bockermann</dc:creator>
    <dc:date>2012-05-22T06:28:52</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9393">
    <title>error when creating rule for op "rx"</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9393</link>
    <description>&lt;pre&gt;Hi,

I am encountering some problem when trying to compile the latest version
mod_security-apache_2.6.5 onto my Ubuntu Server 12.04 LTS. When I run "make
CFLAGS=-DMSC_TEST test, I received the following error message:

ERROR: Failed to create rule for op "rx": Error creating rule: Error
compiling pattern (offset 2): unrecognized character after (? or (?-
make[2]: *** [check-TESTS] Error 1
make[1]: *** [check-am] Error 2

Below is a more detailed message contributing to the above error

Loaded 8 tests from ./op/rx.t
     1) op "rx": passed (Pattern match "" at UNIT_TEST.)
     2) op "rx": passed
     3) op "rx": passed (Pattern match "" at UNIT_TEST.)
     4) op "rx": passed (Pattern match "abc" at UNIT_TEST.)
     5) op "rx": passed (Pattern match "def" at UNIT_TEST.)
     6) op "rx": passed (Pattern match "ghi" at UNIT_TEST.)
     7) op "rx": passed
Test exited with signal 11.
Executed: ./msc_test "-t" "op" "-n" "rx" "-p"
"(?^i:^([^=])\s*=\s*((?:abc)+(?:def|ghi){2})$)" "-D" "0" "-r" "1"
     8) op "rx": fai&lt;/pre&gt;</description>
    <dc:creator>daminto lee</dc:creator>
    <dc:date>2012-05-22T01:26:38</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9391">
    <title>Persistent collections and errors in Apache error_log</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9391</link>
    <description>&lt;pre&gt;Hello everyone.
I'm getting a lot of error entries related to access to DBM file used to store 
collections data.
DBM file is huge, aroung 1GB, I think it never shrinks.
Here a couple of examples:
ModSecurity: Failed deleting collection (name "ip", key
 "93.57.22.65_c40a1a4c63dc22a36a4dacec0e35e80139000959"): Internal error
 [hostname  "XYZ"] [uri "XYZ"] [unique_id "T7pTQApRQSoAAH3H7OIAAABF"]

ModSecurity: Failed to access DBM file 
"/usr/local/apache/rproxyworker/logs/data/ip": Resource deadlock avoided
 [hostname  "XYZ"] [uri "XYZ"] [unique_id "T7nbtgpRQSoAACUgnxIAAAEH"]

Current installation is:
RHEL6, 64bit
Apache: 2.2.22
ModSec: 2.6.5
CRS: 2.2.4 

Configuration:
SecCollectionTimeout 180

I'm using the standar collections created in 2.2.4
Thank you for your help.
Luca



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respo&lt;/pre&gt;</description>
    <dc:creator>Luca</dc:creator>
    <dc:date>2012-05-21T15:12:08</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9389">
    <title>New to Modsecurity: I Need to allow directory traversal to a single virtual host</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9389</link>
    <description>&lt;pre&gt;Hello all, Im new to modsecurity and forgive me if this is a noobish 
question.

But I have a virtual host that I have a lot of iso files on that I would 
like to have directory indexing allowed on just that host.

I have my .htaccess file as follows

Options +Indexes

But ever since I got mod_security running its being ignored, is there a 
way to tell
modsecurity to respect .htaccess files?

Should I just forget about .htaccess all together while running 
mod_security?

And how would I go about adding an exception to modsecurity to allow 
indexing on this virtual host?

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
m&lt;/pre&gt;</description>
    <dc:creator>mrnicholsb</dc:creator>
    <dc:date>2012-05-19T20:58:22</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9386">
    <title>Capturing Internal Server Errors</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9386</link>
    <description>&lt;pre&gt;Hi,

I have the following directive in my crs_10 file:

SecAuditLogRelevantStatus "^(?:5|0(?!04))"

This logs 500 internal server errors when they happen.

I would like to set some attributes like tag, msg, severity etc for the  
above when viewing the alert in the AuditConsole.

I tried using the following rule but no luck:

SecRule RESPONSE_STATUS "&amp;lt; at &amp;gt;eq 500" \
"phase:2,t:none,log,pass,id:'500002',tag:'INTERNAL SERVER ERROR  
500',msg:'Internal Server Error  
500.',setvar:tx.anomaly_score=+%{tx.critical_anomaly_score},logdata:'%{response_status}',severity:1"

Based on the docs i found the below which does not give me the desired  
result:

SecRule RESPONSE_STATUS "^[5]" \
"phase:2,t:none,log,pass,id:'500002',tag:'INTERNAL SERVER ERROR  
5xx',msg:'Internal Server Error  
5xx.',setvar:tx.anomaly_score=+%{tx.critical_anomaly_s     
core},logdata:'%{response_status}',severity:1"

but then there was a note in the docs saying:

"This directive may not work as expected in embedded-mode as Apache  
handles many of t&lt;/pre&gt;</description>
    <dc:creator>Usman</dc:creator>
    <dc:date>2012-05-17T11:33:02</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9385">
    <title>Own POST Rate Limit Rule not Working</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9385</link>
    <description>&lt;pre&gt;Hi all, 

we have tried to write a  ModSecurity rule to limit POST Requests. But the limit does not work as expected.


Here is the rule:

 SecRule REQUEST_METHOD "^POST$" "phase:1,nolog,initcol:IP=%{REMOTE_ADDR},setvar:IP.pagecount=+1,expirevar:IP.pagecount=60"
 SecRule IP:PAGECOUNT "&amp;lt; at &amp;gt;gt 250" "phase:1,deny,status:403,msg:'Too many requests'"

The "pagecount" counter does not work correctly. as we have a few IP's with anly 10 requests and all requests are "GET" , with a pagecount of 250. 
Where is our error?

We are using ModSecurity on Debian 6, in Version 2.5.12


Regards,
------------------------------------------------------------------------ 
 Thomas Berger 
 - Certified Linux/Cisco Networking Engineer - 
 BOREUS Rechenzentrum GmbH 
 Zur Schwedenschanze 2 
 D - 18435 Stralsund 
 Germany 
 Phone:+49 (0) 38 31 - 36 76 415 
 Fax: +49 (0) 38 31 - 36 76 615 
 eMail: tbe&amp;lt; at &amp;gt;boreus.de 
 Internet: http://www.boreus.de/ 
 -------------------------------------------------------------------------- 
 Geschäftsführer&lt;/pre&gt;</description>
    <dc:creator>Thomas Berger</dc:creator>
    <dc:date>2012-05-11T12:45:10</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9383">
    <title>2.6.5 Compile Question</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9383</link>
    <description>&lt;pre&gt;I'm compiling modsec 2.6.5 against Apache 2.4.2, and during a "make CFLAGS=-DMSC_TEST test" I get the following:

msc_test-modsecurity.o: In function `modsecurity_init':
modsecurity.c:(.text+0x240): undefined reference to `ap_unixd_set_global_mutex_perms'
modsecurity.c:(.text+0x291): undefined reference to `ap_unixd_set_global_mutex_perms'
collect2: ld returned 1 exit status
make[2]: *** [msc_test] Error 1
make[2]: Leaving directory `/opt/modsecurity-apache_2.6.5/tests'
make[1]: *** [check-am] Error 2
make[1]: Leaving directory `/opt/modsecurity-apache_2.6.5/tests'
make: *** [check-recursive] Error 1

I'm having trouble finding a work-around or solution for this. Can anyone point me in the right direction?

Thanks,

Dan

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile&lt;/pre&gt;</description>
    <dc:creator>Dan Denton</dc:creator>
    <dc:date>2012-05-10T22:07:44</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9381">
    <title>SecRule 981317</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9381</link>
    <description>&lt;pre&gt;In modsecurity_crs_41_sql_injection_attacks.conf, rule ID 981317 looks for
the following:

SecRule TX:SQLI_SELECT_STATEMENT_COUNT "&amp;lt; at &amp;gt;ge 3"
"phase:2,t:none,block,id:'981317'ŠŠŠ.


Which if the *_COUNT is equal to or greater the 3 of the list of SQL key
words, issue a 403 error.

I have two variable fields that consist of pure text fields where the SQL
key words will most likely be hit, i.e.: the count will equal 3 or greater
very easily.  These fields are not SQL in nature.

How can I perform the equivalent  of an if-else-then where if variables
coverLetterTxt or resumeTXT is scanned, to not perform the 981317 processŠ
I do not care if the word count reaches 20000 for these two variables
where SQL injection is concerned, but for the many other fields, I do want
these tests to be performed and permission denied in the event of an SQL
attack.

For these two fields, I do have a while list on the ASCII characters from
X01-X7F, allow.  Do I need another allow statement with the inclusion of
the SQL key words su&lt;/pre&gt;</description>
    <dc:creator>Canell, Stephen E (2240</dc:creator>
    <dc:date>2012-05-10T16:40:21</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9375">
    <title>ModSecurity starting,but not logging even with debug</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9375</link>
    <description>&lt;pre&gt;I have installed ModSecurity 2.6.5 on Apache httpd 2.0.52 and I see it  
load in the error_log, but I get nothing from the ModSecurity logs.  I  
have set SecDebugLogLevel to 9.  I have turned debug logs on in apache  
as well, but am seeing nothing in the logs about ModSecurity failing.   
Apache is writing to it's own logs as it should and the ModSecurity  
logs are set to be in the same directory as the Apache logs.  I have  
rules linked in to the activated_rules directory.  I copied the  
error_log from apache below.

I have ModSecurity running great with the same configuration on a  
newer httpd 2.2.3, but am unable to upgrade this older server at the  
moment.

Thanks in advance for your time and help,
Steve


... caught SIGTERM, shutting down
... suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
... ModSecurity for Apache/2.6.5 (http://www.modsecurity.org/) configured.
... ModSecurity: APR compiled version="0.9.4"; loaded version="0.9.4"
... ModSecurity: PCRE compiled version="4.5"; loaded version&lt;/pre&gt;</description>
    <dc:creator>mjs&lt; at &gt;terabox.org</dc:creator>
    <dc:date>2012-05-09T18:54:21</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9372">
    <title>REQUEST_BODY has some XML</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9372</link>
    <description>&lt;pre&gt;Hi,

I am new to mod security and have an application that POSTS XML data in  
the REQUEST_BODY.

The REQUEST_HEADER Content-type is set to  
application/x-www-form-urlencoded and NOT to text/xml.

A sample of my XML POST data in the REQUEST_BODY looks like:

&amp;lt;?xml version="1.0" encoding="utf-8"?&amp;gt;&amp;lt;oau:versioncheck  
schema-version="1.0" update-level="3" main="1" xmlns:oau="urn:myupdate"&amp;gt;
&amp;lt;legend&amp;gt;&amp;lt;product&amp;gt;test777&amp;lt;/product&amp;gt;&amp;lt;version&amp;gt;1.0&amp;lt;/version&amp;gt;&amp;lt;build-number&amp;gt;1347&amp;lt;/build-number&amp;gt;&amp;lt;/legend&amp;gt;

What i am trying to do is sanitize the inputs within this XML i receive  
using mod security rules.

I could write a regular expression that checks the validity of the inputs  
in the REQUEST_BODY but then i saw this example where
one can use validateSchema and the XML processor. My problem is that the  
REQUEST_HEADER Content-type: is set to application/x-www-form-urlencoded
which does not allow me to fire the XML processor.

Is there an alternate way to go about running the XML processor on the  
REQUEST_BODY where the REQUE&lt;/pre&gt;</description>
    <dc:creator>Usman Waheed</dc:creator>
    <dc:date>2012-05-09T13:14:40</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9370">
    <title>SecFilter rules</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9370</link>
    <description>&lt;pre&gt;Have the SecFilter directives become obsolete?    The RHEL5 NSA
security guide mentions them but they don't see to exist anymore.


Thanks,

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

&lt;/pre&gt;</description>
    <dc:creator>solarflow99</dc:creator>
    <dc:date>2012-05-06T19:01:19</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9366">
    <title>how to turn off rule checking for specificfield</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9366</link>
    <description>&lt;pre&gt;All,

So we have a user that has put a % symbol in their password. This is
tripping up mod_security when the user tries to login. The relevant entry
is


Message: Pattern match "\%((?!$|\W)|[0-9a-fA-F]{2}|u[0-9a-fA-F]{4})"
at ARGS:j_password. [file
"D:/apps/Apache2.2/conf/modsecurity2/base_rules/modsecurity_crs_20_protocol_violations.conf"]
[line "185"] [id "950109"] [rev "2.1.1"] [msg "Multiple URL Encoding
Detected"] [severity "NOTICE"] [tag "PROTOCOL_VIOLATION/EVASION"]

So what I want to do is convince this rule to now check this parameter for
the specific url. I am guessing something along the lines of

    &amp;lt;LocationMatch "/loginUrl"&amp;gt;
        update 950109 such that it doesn't check j_password ARG
    &amp;lt;/LocationMatch&amp;gt;

Unfortunately my google skills only work when I know what key term to look
for. Any hints appreciated

Thanks

Chris
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's securit&lt;/pre&gt;</description>
    <dc:creator>chris derham</dc:creator>
    <dc:date>2012-05-04T11:21:04</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9361">
    <title>Modsecurity super slow whenSecRequestBodyAccess On</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9361</link>
    <description>&lt;pre&gt;I have installed, modsecurity-crs_2.2.4.tar.gz, and an ASP sign HTML form
is being processed super slow whenever  SecRequestBodyAccess is On. If I
set it to Off, the form processes very quickly.

I turned on debugging, and I see the usec are super high for the steps
below. How can this be fixed so that I can have much faster processing of
the form fill when  SecRequestBodyAccess is On?


[02/May/2012:19:16:59 --0700] [
www.constantmd.com/sid#7fc8efd152d8][rid#7fc8f01f3878][/][5] Rule
7fc8efd11730: SecRule "TX:OUTBOUND_ANOMALY_SCORE" "&amp;lt; at &amp;gt;ge
%{tx.outbound_anomaly_score_level}"
"phase:5,id:981205,t:none,log,noauditlog,pass,msg:'Outbound Anomaly Score
Exceeded (score %{TX.OUTBOUND_ANOMALY_SCORE}): %{tx.msg}'"
[02/May/2012:19:16:59 --0700] [
www.constantmd.com/sid#7fc8efd152d8][rid#7fc8f01f3878][/][4] Rule returned
0.
[02/May/2012:19:16:59 --0700] [
www.constantmd.com/sid#7fc8efd152d8][rid#7fc8f01f3878][/][4] Audit log:
Ignoring a non-relevant request.
[02/May/2012:19:17:01 --0700] [
www.constantmd.com/sid#7fc8efd2&lt;/pre&gt;</description>
    <dc:creator>Gil Vidals</dc:creator>
    <dc:date>2012-05-03T02:25:20</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9357">
    <title>mod_security not denying access</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9357</link>
    <description>&lt;pre&gt;Hi,
I've just installed mod_security on a Centos 5 system and I'm having
trouble to actually get it to deny certain requests. I've change the line:

SecDefaultAction "phase:2,pass"

to

SecDefaultAction "phase:2,deny"

in "/etc/httpd/modsecurity.d/modsecurity_crs_10_config.conf" and I get the
following in the audit log:

...
Message: Access denied with code 403 (phase 2). [file
"/etc/httpd/modsecurity.d/base_rules/modsecurity_crs_49_enforcement.conf"]
[line "25"] [msg "Anomaly Score Exceeded (score 40): SQL Injection Attack"]
...

but the request is responded to normally with a "200 ok" and the webpage.
Is there anything in particular that needs to be done to actually have
apache deny the request?

Regards,
   Dennis

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile se&lt;/pre&gt;</description>
    <dc:creator>Dennis Jacobfeuerborn</dc:creator>
    <dc:date>2012-04-30T18:32:39</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9355">
    <title>cpanel, mod_ruid2 and mod_sec</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9355</link>
    <description>&lt;pre&gt;Hi all,
I am having the following error in mod_sec log:

Audit log: Failed to lock global mutex: Permission denied

Do you know what is this error about?

Cpanel forum saids that it is an incompatibility issue among mod_ruid2 and
mod_sec, have you any idea what is this error about?

Thanks in advance.

Best Regards,

Sergio
------------------------------------------------------------------------------
For Developers, A Lot Can Happen In A Second.
Boundary is the first to Know...and Tell You.
Monitor Your Applications in Ultra-Fine Resolution. Try it FREE!
http://p.sf.net/sfu/Boundary-d2dvs2_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
&lt;/pre&gt;</description>
    <dc:creator>Sergio</dc:creator>
    <dc:date>2012-04-20T00:10:49</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9354">
    <title>limit secrule</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9354</link>
    <description>&lt;pre&gt;I was able to solve  a false positive with these two methods, but they
seemed to broad to me:

Method 1:
SecRule REQUEST_URI "/newthread.php.*"
phase:2,nolog,auditlog,allow,ctl:requestBodyAccess=Off

Method 2:
&amp;lt;Directory /hsphere/local/home/kamxxxx/ddddddk.com&amp;gt;
    SecRuleEngine DetectionOnly
&amp;lt;/Directory&amp;gt;

However, I am not able to limit the scope of this rule. I tried this, but
it doesn't prevent the false positive.

#&amp;lt;Directory /hsphere/local/home/kamxxxx/ddddddk.com&amp;gt;
#   SecRule REQUEST_URI "/newthread.php.*"
phase:2,nolog,auditlog,allow,ctl:requestBodyAccess=Off
#&amp;lt;/Directory&amp;gt;

Is it possible to limit the scope more on a server that has many virtual
hosted accounts?



&lt;/pre&gt;</description>
    <dc:creator>Gil Vidals</dc:creator>
    <dc:date>2012-04-19T19:06:41</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9352">
    <title>Rules Hierarchy &amp; Other Questions</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9352</link>
    <description>&lt;pre&gt;Hello List,

I am a new user (as in new to webadmin, mod_security and Apache), I’ve just installed mod_security (v. 2.5.12) on my Amazon Web Services EC2 instance and I am in need of guidance. I am slowly learning this stuff, so I beg your patience…

Right now I have things set up as described/prescribed in the ModSecurity Handbook; Im calling liblua and libxml2 in httpd.conf and loading the mod_security module there too. Then I’ve got the modsecurity.conf where the directory locations are laid out and some other options – all according to the Handbook.

When it comes to calling the rules (in their .conf files) what hierarchy is best? Does mod_security call everything (conf. files &amp;amp; rules themselves) in the order they are written/listed? If so, when is a good time to call a whitelist? First? Last?

I take it the SecRuleEngine call should be first in the modsecurity.conf file or does that go in the httpd.conf file?

Last but not least (for now) I’m going to be using the core rules (v.2.2.4). I see .&lt;/pre&gt;</description>
    <dc:creator>Matt</dc:creator>
    <dc:date>2012-04-06T17:20:15</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9350">
    <title>Updated mod_sec now lost all rules?</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9350</link>
    <description>&lt;pre&gt;Hi,

I updated from mod_sec 2.5.x to mod_security-2.6.4-1.el5.art on CentOS
5.x - yes I know is a bit out of date now but that's what the firm is
running :-)

Anyway, peeking into /etc/httpd/modsecurity.d/base_rules it became
evident that there were no rules within the folder.

Having a look at the changelog (ok this is for CentOS version 6), it
seems that rules are no longer being distributed with the package.

I had a go at scp'ing the old rules over from an old server to the
machine in question running the 2.6.4-1 update, when I came to
restarting Apache I got this error:

Starting httpd: Syntax error on line 47 of
/etc/httpd/modsecurity.d/base_rules/modsecurity_crs_21_protocol_anomalies.conf:
ModSecurity: SkipAfter actions can only be specified by chain starter rules.


.......and subsequently the httpd service would not start.


What I would like to understand is why the rules haven't been included
in new updates and additionally if it is possible to utilize the old
rules within the update?


Can anyone&lt;/pre&gt;</description>
    <dc:creator>Kaya Saman</dc:creator>
    <dc:date>2012-04-04T08:09:41</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.apache.mod-security.user/9349">
    <title>Conteúdo em português</title>
    <link>http://comments.gmane.org/gmane.comp.apache.mod-security.user/9349</link>
    <description>&lt;pre&gt;Pessoal, tem alguém que fala português na lista? Vocês podem me indicar
algum conteúdo, videos, textos em português?
------------------------------------------------------------------------------
Better than sec? Nothing is better than sec when it comes to
monitoring Big Data applications. Try Boundary one-second 
resolution app monitoring today. Free.
http://p.sf.net/sfu/Boundary-dev2dev_______________________________________________
mod-security-users mailing list
mod-security-users&amp;lt; at &amp;gt;lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
&lt;/pre&gt;</description>
    <dc:creator>Junior Castelli</dc:creator>
    <dc:date>2012-04-03T14:57:45</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.apache.mod-security.user">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.apache.mod-security.user</link>
  </textinput>
</rdf:RDF>

