Re: alternatives for waf-fle
Hans Mayer via mod-security-users <[email protected]> Thu, 8 Feb 2024 17:57:11 +0100
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============3967446748550043549==
Content-Type: multipart/alternative;
boundary="------------6xnThueiqVU7b9vGfWtzdDFA"
Content-Language: de-DE, en-GB
This is a multi-part message in MIME format.
--------------6xnThueiqVU7b9vGfWtzdDFA
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Hi Ervin,
many thanks for your swift reply.
> (actually I don't understand what does it mean "by klaubert")
Sorry, if I didn't explain understandable what's the issue. The
maintainer for "waf-fle" is klaubert. Here the link at GitHub:
https://github.com/klaubert/waf-fle
> could you explain what's wrong with your setup? I mean what does
it mean "doesn't work".
Apache with mod-sec is working fine. But waf-fle is not working any more.
"waf-fle" was the tool to display the alerts coming from mod-sec.
"waf-fle" is written in PHP and obviously using calls, which are not supported any more, like "apache_setenv()"
So I am looking for an alternative to view the log entries generated by "mod-sec"
I hope this explains a little bit more my issue.
Kind regards
Hans
--
On 07.02.24 23:33, Ervin Hegedüs wrote:
> Hi Hans,
>
> On Wed, Feb 07, 2024 at 11:15:27PM +0100, Hans Mayer via mod-security-users wrote:
>> Dear All,
>>
>> Over years I am using modsec and Apache with mlogc sending the alerts to
>> waf-fle.
>>
>> With the last upgrade to Debian bookworm and PHP 8.2 waf-fle by klaubert
>> doesn't work any more.
> (actually I don't understand what does it mean "by klaubert")
>
> could you explain what's wrong with your setup? I mean what does
> it mean "doesn't work".
>
> (Note that I'm the maintainer of libapache2-mod-security2 package
> in Debian, so it's important to know me what's the issue.)
>
>> Actually I am wondering how long it was running as the last update is 10
>> years ago.
>>
>> Now I am looking for an alternative to view the alert logs.
>>
>> I liked waf-fle as it didn't use a lot of resources. Is there something
>> similar available ?
> If your package does not work (for some reason) could you try
> this repository?
>
> https://modsecurity.digitalwave.hu
>
> Thanks,
>
>
> a.
>
--------------6xnThueiqVU7b9vGfWtzdDFA
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p><br>
</p>
<p><font face="monospace"><br>
</font></p>
<p><font face="monospace">Hi Ervin, <br>
</font></p>
<p><font face="monospace">many thanks for your swift reply. </font></p>
<p><font face="monospace">> <span style="white-space: pre-wrap">(actually I don't understand what does it mean "by klaubert")</span></font></p>
<pre><font face="monospace"><span style="white-space: pre-wrap">Sorry, if I didn't explain understandable what's the issue.
The maintainer for "waf-fle" is klaubert. Here the link at GitHub:
<a class="moz-txt-link-freetext" href="https://github.com/klaubert/waf-fle">https://github.com/klaubert/waf-fle</a>
</span></font></pre>
<p><font face="monospace"><span style="white-space: pre-wrap"></span><span
style="white-space: pre-wrap">
</span></font></p>
<pre class="moz-quote-pre" wrap="">> could you explain what's wrong with your setup? I mean what does
it mean "doesn't work".
Apache with mod-sec is working fine. But waf-fle is not working any more.
"waf-fle" was the tool to display the alerts coming from mod-sec.
"waf-fle" is written in PHP and obviously using calls, which are not supported any more, like "apache_setenv()"
So I am looking for an alternative to view the log entries generated by "mod-sec"
I hope this explains a little bit more my issue.
Kind regards
Hans
-- <font face="Courier New, Courier, monospace">
</font>
</pre>
<div class="moz-cite-prefix">On 07.02.24 23:33, Ervin Hegedüs wrote:<br>
</div>
<blockquote type="cite"
cite="mid:[email protected]">
<pre class="moz-quote-pre" wrap="">Hi Hans,
On Wed, Feb 07, 2024 at 11:15:27PM +0100, Hans Mayer via mod-security-users wrote:
</pre>
<blockquote type="cite">
<pre class="moz-quote-pre" wrap="">
Dear All,
Over years I am using modsec and Apache with mlogc sending the alerts to
waf-fle.
With the last upgrade to Debian bookworm and PHP 8.2 waf-fle by klaubert
doesn't work any more.
</pre>
</blockquote>
<pre class="moz-quote-pre" wrap="">
(actually I don't understand what does it mean "by klaubert")
could you explain what's wrong with your setup? I mean what does
it mean "doesn't work".
(Note that I'm the maintainer of libapache2-mod-security2 package
in Debian, so it's important to know me what's the issue.)
</pre>
<blockquote type="cite">
<pre class="moz-quote-pre" wrap="">Actually I am wondering how long it was running as the last update is 10
years ago.
Now I am looking for an alternative to view the alert logs.
I liked waf-fle as it didn't use a lot of resources. Is there something
similar available ?
</pre>
</blockquote>
<pre class="moz-quote-pre" wrap="">
If your package does not work (for some reason) could you try
this repository?
<a class="moz-txt-link-freetext" href="https://modsecurity.digitalwave.hu">https://modsecurity.digitalwave.hu</a>
Thanks,
a.
</pre>
</blockquote>
</body>
</html>
--------------6xnThueiqVU7b9vGfWtzdDFA--
--===============3967446748550043549==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============3967446748550043549==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
--===============3967446748550043549==--