Re: Recommended rule exclusions for W YSIWYG editor editing

Filip Bartmann <[email protected]> Sun, 31 Oct 2021 13:57:16 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
Hello thanks,
so I do this, I thought, that core rule set can be enabled even if i want to POST HTML content.
 
With best regards,
Filip Bartmann
 
______________________________________________________________
> Od: "Reindl Harald" <[email protected]>
> Komu: [email protected]
> Datum: 31.10.2021 13:41
> Předmět: Re: [mod-security-users] Recommended rule exclusions for WYSIWYG editor editing
>

 
 Am 31.10.21 um 13:34 schrieb Filip Bartmann:
 > I'm discovering mod_security with core rule set as very usefull, but I'm going in to trouble with editing HTML via admin part of my CMS including file uploads other parts works well.
 >   
 > Is there any recomendations for minimal rule exlusions for allowing this, but with as many as possible rules enabled. In editing html in forms I get many detections in this as XSS attacks or so on.
 
 you started that topic already afew weeks ago
 
 there is nothing like post HTML and enable as much as possible rules at 
 the same time - you will have a fulltimejob adding more and more rules 
 to exceptions and a minimal WYSIWG change can hit another rule tomorrow
 
 forget it, been there, done that many years ago - it's not worth
 
 <IfModule mod_security2.c>
  <LocationMatch "(.*)\/editor\/plugins\/preview\.php$">
   SecRequestBodyAccess Off
  </LocationMatch>
 </IfModule>
 
 
 _______________________________________________
 mod-security-users mailing list
 [email protected]
 https://lists.sourceforge.net/lists/listinfo/mod-security-users <https://lists.sourceforge.net/lists/listinfo/mod-security-users>
 Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
 http://www.modsecurity.org/projects/commercial/rules/ <http://www.modsecurity.org/projects/commercial/rules/>
 http://www.modsecurity.org/projects/commercial/support/ <http://www.modsecurity.org/projects/commercial/support/>

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/