Re: Mod security rule

Christian Folini <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <20190129050936.GD13069@leander>
Hello Matthijs,

Manuel Spartan's advice is very sound.

Here a bit of additional info:

On Mon, Jan 28, 2019 at 04:23:08PM +0100, Matthijs Möhlmann wrote:
> I am obviously missing something but I cannot find why. I already tried
> adding 'setvar:anomaly_score-=5' and other parts. In my opinion one should
> not disable the rules 949110 and 980130, then SQL injections won't be
> detected properly (as example)?

949110 is a crucial rule as it makes the blocking decision. You were probably
referring to 942110. I agree that this rule is best left intact, but
sometimes, I have to disable it for a given path on a given parameter. If I
do, I try to do this in a very granular way.

980130 is just a statistics rule. It can be ignored, or axes completely, if
you do not have any use for it.

Good luck!

Christian


-- 
If liberty means anything at all, it means the right to tell people
what they do not want to hear.
-- George Orwell


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.