Re: Messages are trimmed

[email protected]
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <20190829171458.Horde.9klbHCFkDE590wsc03b8_3r@webmail.inetadmin.eu>
Ok, so how am i supposed to write an exclusive rule for these?  
Information about arguments should be at the beggining of the message,  
so it won't gets trimmed.





Citát Robert Paprocki <[email protected]>:

> Yes, this is trimmed to 255 bytes, and it’s not configurable.
>
>> On Aug 29, 2019, at 07:17, [email protected] wrote:
>>
>> Hi,
>>
>> is it possible to bypass message trimming in logs? Sometimes,  
>> information which argument name which triggered a rule is trimmed  
>> so it's very hard to write an exclusive rule. Example:
>>
>>
>> Warning. detected XSS using libinjection. [file  
>> \"/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf\"] [line \"64\"] [id \"941100\"] [rev \"2\"] [msg \"XSS Attack Detected via libinjection\"] [data \"Matched Data: <script>\\x0d\\x0a  (function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){\\x0d\\x0a  (i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),\\x0d\\x0a  m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)\\x0d\\x0a  })(window,document,'script','https://www.google-analytics.com/analytics.js','ga');\\x0d\\x0a\\x0d\\x0a  ga('create', 'UA-0000000-00', 'auto');\\x0d\\x0a  ga('send', 'pageview');\\x0d\\x0a\\x0d\\x0a</script> found within ARGS...\"] [severity \"CRITICAL\"] [ver \"OWASP_CRS/3.0.0\"] [maturity \"1\"] [accuracy \"9\"] [tag \"application-multi\"] [tag \"language-multi\"] [tag \"platform-multi\"] [tag \"attack-xss\"] [tag \"OWASP_CRS/WEB_ATTACK/XSS\"] [tag \"WASCTC/WASC-8\"] [tag \"WASCTC/WASC-22\"] [tag \"OWASP_TOP_10/A3\"] [tag  
>> \"OWASP_AppSensor/IE1\"]
>>
>>
>> I'm talking about this: "found within ARGS..." - argument name was  
>> trimmed :( Thnks for info.
>>
>> azur
>>
>>
>>
>>
>> _______________________________________________
>> mod-security-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/mod-security-users
>> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
>> http://www.modsecurity.org/projects/commercial/rules/
>> http://www.modsecurity.org/projects/commercial/support/
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/





_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.