Re: Info update rules CRS OWASP

Marcello Lorenzi <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CACT02+55uacujRAzRRS7FvgJENBS8F+3fpc3weU14JedOA9otA@mail.gmail.com>
Hi Christian,
thanks for the response. I read your tutorial but ideally we have to put
the removal and update of the new rule into RESPONSE-999-EXCLUSION-RULES-
AFTER-CRS.conf?

Thanks,
Marcello

On Wed, Dec 12, 2018 at 5:53 PM Christian Folini <
[email protected]> wrote:

> Hey Marcello,
>
> That's very tricky or impossible at all.
>
> People generally write a rule exclusion for a false positive that
> skips the rule under certain conditions or they drop the rule and
> add it anew in a different form (like you have in mind).
>
> If you are unfamiliar with the handling of false positives, I suggest
> you read through my tutorials at https://netnea.com/apache-tutorials.
>
> Best,
>
> Christian
>
>
> On Wed, Dec 12, 2018 at 05:40:52PM +0100, Marcello Lorenzi wrote:
> > Hi All,
> > we have configured a Nginx webserver with mod_security 2.9.2 and OWASP
> CRS
> > 3.0.2 and during our tests we noticed that some rules blocked some
> requests
> > from external clients. We would update the rule with ID 920420 adding the
> > POST method into the SecRule section without rewriting the entire rule.
> >
> > Is it possible to override only a little part of a rule in a clean way?
> >
> > Thanks,
> > Marcello
>
>
> > _______________________________________________
> > mod-security-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > http://www.modsecurity.org/projects/commercial/rules/
> > http://www.modsecurity.org/projects/commercial/support/
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.