Re: ambiguous statements in CRS-SetUP.conf
Ted Talaiti <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <SLXP216MB036641736D24A54BCEFA7A42FC1C0@SLXP216MB0366.KORP216.PROD.OUTLOOK.COM> |
Hey Chaim 1) What if I just uncomment them and change nothing? Will the redundancy cause problem? Which one works during the exacuations? 2) Increasing paranoia add extra rule. But in following example it only effects to "id:900000" but not others. Are the two statements contrary? Could you please tell the exact place where I can set paranoi level that effects to all CRS or part of it? SecAction \ "id:900000,\ phase:1,\ nolog,\ pass,\ t:none,\ setvar:tx.paranoia_level=1" Sincerely Thanks in advance. ________________________________ From: Chaim Sanders <[email protected]> Sent: Saturday, May 25, 2019 1:01 AM To: [email protected] Subject: Re: [mod-security-users] ambiguous statements in CRS-SetUP.conf Hey Ted, if you leave that commented, the default applies. The confusing portion may be that the example enables the same effect as the default. However, you can extend or restrict the details farther by uncomment and modifying that rule. Let us know if you have any other questions. Thanks, - Chaim On Fri, May 24, 2019, 10:23 AM Ted Talaiti <[email protected]<mailto:[email protected]>> wrote: Dear friends HOW/WHY Uncomment this rule can change the default? Because it says by default it supports 4type of HTTP anyway. On the other hand, if do not uncomment the rule, then it does not the support the 4type of HTTP? [cid:cd9346a7-98d9-4d0d-9b06-d953163653f7] I am confused of what happens if I uncomment the rule or leave it as commented? Sincerely _______________________________________________ mod-security-users mailing list [email protected]<mailto:[email protected]> https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/