Re: Recommended rule exclusions for WYSIWYG editor editing

Reindl Harald <[email protected]> Sun, 31 Oct 2021 13:39:57 +0100
Newsgroups gmane.comp.apache.mod-security.user
Organization the lounge interactive design
Message-ID <[email protected]>

Am 31.10.21 um 13:34 schrieb Filip Bartmann:
> I'm discovering mod_security with core rule set as very usefull, but I'm going in to trouble with editing HTML via admin part of my CMS including file uploads other parts works well.
>   
> Is there any recomendations for minimal rule exlusions for allowing this, but with as many as possible rules enabled. In editing html in forms I get many detections in this as XSS attacks or so on.

you started that topic already afew weeks ago

there is nothing like post HTML and enable as much as possible rules at 
the same time - you will have a fulltimejob adding more and more rules 
to exceptions and a minimal WYSIWG change can hit another rule tomorrow

forget it, been there, done that many years ago - it's not worth

<IfModule mod_security2.c>
  <LocationMatch "(.*)\/editor\/plugins\/preview\.php$">
   SecRequestBodyAccess Off
  </LocationMatch>
</IfModule>


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/