Re: Parsing SQL injection messages

mattia conversano <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <a146771a-01cf-48a9-b925-515488b0491f@Spark>
Sorry for my late replay.
Thanks you for reply;

Have a good day,
Mattia
Il 21 ago 2019, 11:27 +0200, Christian Folini <[email protected]>, ha scritto:
> Sure.
>
> It's in
> https://www.netnea.com/cms/apache-tutorial-7_including-modsecurity-core-rules/
> step 5.
>
> The aliases can be found in
> https://raw.githubusercontent.com/Apache-Labor/labor/master/bin/.apache-modsec.alias
>
> Cheers,
>
> Christian
>
>
> On Wed, Aug 21, 2019 at 11:02:01AM +0200, mattia conversano wrote:
> > Hi Christian,
> >
> > Thanks for the reply;
> > i visited https://netnea.com but i don't find a specific link that help me.
> > Can you help me to find it?
> > Thanks so much,
> > Mattia
> >
> > Il giorno mer 21 ago 2019 alle ore 10:40 Christian Folini <
> > [email protected]> ha scritto:
> >
> > > Hey Mattia,
> > >
> > > Welcome to Modsec.
> > >
> > > Parsing the audit log can be annoying and the JSON support is fairly
> > > limited.
> > >
> > > Personally, I concentrate on the error log that carries the alert message
> > > with
> > > the malicious parameters that you are looking for.
> > >
> > > I extract all the infos I need with the help of a set of aliases that are
> > > part
> > > of the series of ModSecurity tutorials that I host at https://netnea.com.
> > >
> > > It should be simple to extract it that or in a similar way and feed that
> > > into
> > > logstash.
> > >
> > > Best,
> > >
> > > Christian
> > >
> > >
> > >
> > > On Wed, Aug 21, 2019 at 10:16:49AM +0200, mattia conversano wrote:
> > > > Hi team,
> > > >
> > > > Thanks for the tool.
> > > > I’m new with Modsexurity; my goal is to extract code used for SQLi.
> > > > I have activated logging with JSON format and i’m trying to extract
> > > malicious parameter’s value used to injection using Logstash.
> > > > But i failed because i don’t find a pattern in audit_data.messages.
> > > >
> > > > There is a way to set Modsecurity to parse in a better way logs?
> > > >
> > > > Sorry for the inconvenience and thanks for yourk work,
> > > > Mattia
> > >
> > >
> > > > _______________________________________________
> > > > mod-security-users mailing list
> > > > [email protected]
> > > > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > > > http://www.modsecurity.org/projects/commercial/rules/
> > > > http://www.modsecurity.org/projects/commercial/support/
> > >
> > >
> > >
> > > _______________________________________________
> > > mod-security-users mailing list
> > > [email protected]
> > > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > > http://www.modsecurity.org/projects/commercial/rules/
> > > http://www.modsecurity.org/projects/commercial/support/
> > >
>
>
> > _______________________________________________
> > mod-security-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > http://www.modsecurity.org/projects/commercial/rules/
> > http://www.modsecurity.org/projects/commercial/support/
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.