Re: Mod security rule
Christian Folini <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <20190129050936.GD13069@leander> |
Hello Matthijs, Manuel Spartan's advice is very sound. Here a bit of additional info: On Mon, Jan 28, 2019 at 04:23:08PM +0100, Matthijs Möhlmann wrote: > I am obviously missing something but I cannot find why. I already tried > adding 'setvar:anomaly_score-=5' and other parts. In my opinion one should > not disable the rules 949110 and 980130, then SQL injections won't be > detected properly (as example)? 949110 is a crucial rule as it makes the blocking decision. You were probably referring to 942110. I agree that this rule is best left intact, but sometimes, I have to disable it for a given path on a given parameter. If I do, I try to do this in a very granular way. 980130 is just a statistics rule. It can be ignored, or axes completely, if you do not have any use for it. Good luck! Christian -- If liberty means anything at all, it means the right to tell people what they do not want to hear. -- George Orwell _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/