Re: Parsing SQL injection messages
mattia conversano <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <a146771a-01cf-48a9-b925-515488b0491f@Spark> |
Sorry for my late replay. Thanks you for reply; Have a good day, Mattia Il 21 ago 2019, 11:27 +0200, Christian Folini <[email protected]>, ha scritto: > Sure. > > It's in > https://www.netnea.com/cms/apache-tutorial-7_including-modsecurity-core-rules/ > step 5. > > The aliases can be found in > https://raw.githubusercontent.com/Apache-Labor/labor/master/bin/.apache-modsec.alias > > Cheers, > > Christian > > > On Wed, Aug 21, 2019 at 11:02:01AM +0200, mattia conversano wrote: > > Hi Christian, > > > > Thanks for the reply; > > i visited https://netnea.com but i don't find a specific link that help me. > > Can you help me to find it? > > Thanks so much, > > Mattia > > > > Il giorno mer 21 ago 2019 alle ore 10:40 Christian Folini < > > [email protected]> ha scritto: > > > > > Hey Mattia, > > > > > > Welcome to Modsec. > > > > > > Parsing the audit log can be annoying and the JSON support is fairly > > > limited. > > > > > > Personally, I concentrate on the error log that carries the alert message > > > with > > > the malicious parameters that you are looking for. > > > > > > I extract all the infos I need with the help of a set of aliases that are > > > part > > > of the series of ModSecurity tutorials that I host at https://netnea.com. > > > > > > It should be simple to extract it that or in a similar way and feed that > > > into > > > logstash. > > > > > > Best, > > > > > > Christian > > > > > > > > > > > > On Wed, Aug 21, 2019 at 10:16:49AM +0200, mattia conversano wrote: > > > > Hi team, > > > > > > > > Thanks for the tool. > > > > I’m new with Modsexurity; my goal is to extract code used for SQLi. > > > > I have activated logging with JSON format and i’m trying to extract > > > malicious parameter’s value used to injection using Logstash. > > > > But i failed because i don’t find a pattern in audit_data.messages. > > > > > > > > There is a way to set Modsecurity to parse in a better way logs? > > > > > > > > Sorry for the inconvenience and thanks for yourk work, > > > > Mattia > > > > > > > > > > _______________________________________________ > > > > mod-security-users mailing list > > > > [email protected] > > > > https://lists.sourceforge.net/lists/listinfo/mod-security-users > > > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > > > > http://www.modsecurity.org/projects/commercial/rules/ > > > > http://www.modsecurity.org/projects/commercial/support/ > > > > > > > > > > > > _______________________________________________ > > > mod-security-users mailing list > > > [email protected] > > > https://lists.sourceforge.net/lists/listinfo/mod-security-users > > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > > > http://www.modsecurity.org/projects/commercial/rules/ > > > http://www.modsecurity.org/projects/commercial/support/ > > > > > > > _______________________________________________ > > mod-security-users mailing list > > [email protected] > > https://lists.sourceforge.net/lists/listinfo/mod-security-users > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > > http://www.modsecurity.org/projects/commercial/rules/ > > http://www.modsecurity.org/projects/commercial/support/ > > > > _______________________________________________ > mod-security-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/