Parse JSON response and put ip on blacklist for xy minutes

Boris Kočar <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CA+Ty2fm9zefiqXqvb31w1-jk1crUqmgQJJy+p8U+m+grSB1j-Q@mail.gmail.com>
Hello,

I'm digging through internet to find out about how to parse JSON response
and create the rule.

To be more specific here is a layout:
1. Layer 1 Nginx with Modsecurity
2. Layer 2 Application server
3. Layer 3 ....

Scenario:
when user try to do some illegal things which is known only to application
server where is all the business. Let say for example spray password
attack.

What I like to establish on Modsecurity:
Application server will send back json response with code 401 and json {IP:
a.t.t.a.c.k.e.r i.p}, Modsecurity would catch response, see code (e.g.
401), parse json body and put that IP on black list for xy minutes.

Thanks in front for your time to reply.

Boris

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.