| Newsgroups |
gmane.comp.apache.mod-security.user |
| Message-ID |
<20190829171458.Horde.9klbHCFkDE590wsc03b8_3r@webmail.inetadmin.eu> |
Ok, so how am i supposed to write an exclusive rule for these?
Information about arguments should be at the beggining of the message,
so it won't gets trimmed.
Citát Robert Paprocki <[email protected]>:
> Yes, this is trimmed to 255 bytes, and it’s not configurable.
>
>> On Aug 29, 2019, at 07:17, [email protected] wrote:
>>
>> Hi,
>>
>> is it possible to bypass message trimming in logs? Sometimes,
>> information which argument name which triggered a rule is trimmed
>> so it's very hard to write an exclusive rule. Example:
>>
>>
>> Warning. detected XSS using libinjection. [file
>> \"/usr/share/modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf\"] [line \"64\"] [id \"941100\"] [rev \"2\"] [msg \"XSS Attack Detected via libinjection\"] [data \"Matched Data: <script>\\x0d\\x0a (function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){\\x0d\\x0a (i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),\\x0d\\x0a m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)\\x0d\\x0a })(window,document,'script','https://www.google-analytics.com/analytics.js','ga');\\x0d\\x0a\\x0d\\x0a ga('create', 'UA-0000000-00', 'auto');\\x0d\\x0a ga('send', 'pageview');\\x0d\\x0a\\x0d\\x0a</script> found within ARGS...\"] [severity \"CRITICAL\"] [ver \"OWASP_CRS/3.0.0\"] [maturity \"1\"] [accuracy \"9\"] [tag \"application-multi\"] [tag \"language-multi\"] [tag \"platform-multi\"] [tag \"attack-xss\"] [tag \"OWASP_CRS/WEB_ATTACK/XSS\"] [tag \"WASCTC/WASC-8\"] [tag \"WASCTC/WASC-22\"] [tag \"OWASP_TOP_10/A3\"] [tag
>> \"OWASP_AppSensor/IE1\"]
>>
>>
>> I'm talking about this: "found within ARGS..." - argument name was
>> trimmed :( Thnks for info.
>>
>> azur
>>
>>
>>
>>
>> _______________________________________________
>> mod-security-users mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/mod-security-users
>> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
>> http://www.modsecurity.org/projects/commercial/rules/
>> http://www.modsecurity.org/projects/commercial/support/
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/