Rule breaks access to website
"Madden, Joe via mod-security-users" <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <LNXP123MB1914215D7D97CF5DE153D43291950@LNXP123MB1914.GBRP123.PROD.OUTLOOK.COM> |
Hi there, I'm trying to hide passwords for being audited to the modsec_audit.log therefor I put this rule into modsecurity_crs_10_config.conf for apache: # Never log passwords #SecAction "nolog,phase:2,id:131,sanitiseArg:password,sanitiseArg:newPassword,sanitiseArg:oldPassword" The website returns constant 403 when this rule is enabled, I can't seem to figure out why. Is this the right way to achieve what I am trying to do? Am I putting it in the correct place? Thanks Joe. _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/