Rule breaks access to website

"Madden, Joe via mod-security-users" <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <LNXP123MB1914215D7D97CF5DE153D43291950@LNXP123MB1914.GBRP123.PROD.OUTLOOK.COM>
Hi there,

I'm trying to hide passwords for being audited to the modsec_audit.log therefor I put this rule into modsecurity_crs_10_config.conf for apache:

# Never log passwords
#SecAction "nolog,phase:2,id:131,sanitiseArg:password,sanitiseArg:newPassword,sanitiseArg:oldPassword"

The website returns constant 403 when this rule is enabled, I can't seem to figure out why.

Is this the right way to achieve what I am trying to do? Am I putting it in the correct place?

Thanks

Joe.

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.