Audit data messages
mattia conversano <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CADQ0tnUSLv2aARw-mS2twqdSZz6RLLZHHzEyVYnpBBH+QyaVfw@mail.gmail.com> |
Hi Guys, I'm interested in how messages are formatted in audit data (json or native) logs. my question is: When some rule detects some threat, does it always insert in *[data "text of the threat"]* ? For example when i try to do a sql injection, the malicius string in inserted in something like this: [data \"Matched Data: s&1c found within ARGS:username: [email protected]' and 1=1 -- \"] Thanks in advance, Mattia _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/