Re: How to exclude .com from restricted_extensions only for rule 920440

Franziska Buehler <[email protected]> Sat, 30 Apr 2022 20:47:39 +0200
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CALrdzmJaAyfaOoiVipSOnX2t5EsmG+9QchHzZSO83-QihZb9MA@mail.gmail.com>
Hi!

OWASP Core Rule Set Dev-On-Duty here.

The rule 920440 checks the variable tx.restricted_extensions (
https://github.com/coreruleset/coreruleset/blob/v4.0/dev/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf#L1064
).
This variable can be set in the crs-setup.conf file. So you have to
uncomment and edit (remove .com) the following rule 900240:
https://github.com/coreruleset/coreruleset/blob/v4.0/dev/crs-setup.conf.example#L473

Best regards,
Franziska


Am Fr., 29. Apr. 2022 um 19:07 Uhr schrieb s kwok <[email protected]>:

> Hi,
>
> I'd like to exclude .com from restricted_extensions only for rule 920440.
> Can someone please tell me how to do that? Thanks!
>
> Best
> skwok
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/