Re: execute a script for all rules

Franziska Buehler <[email protected]> Thu, 21 Mar 2024 13:07:54 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CALrdzmLax_e=M7G3ACXQQF8LH+7TaJoQNh2Zv2PpN+KO5BpSFQ@mail.gmail.com>
--===============0901551500777386349==
Content-Type: multipart/alternative; boundary="000000000000597ba806142a8fc8"

--000000000000597ba806142a8fc8
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Hans!

To me, it's not clear what you're trying to achieve.
You would probably have to write a new rule that checks whether rules have
matched and therefore the blocking variables inbound or outbound (e.g.
tx.blocking_inbound_anomaly_score) are set. And then you "exec:" and call
your script in this new rule.
You can't test for individual rules, or at least I don't see how that could
work right now.

Best,
Franziska
# CRS dev-on-duty

Am Mi., 20. M=C3=A4rz 2024 um 21:03 Uhr schrieb Hans Mayer via
mod-security-users <[email protected]>:

>
> Dear All,
>
> I am using Apache/2.4.57 on Debian with the modsecurity-crs package
> which is Producer ModSecurity for Apache/2.9.3 and Rule Set
> OWASP_CRS/3.3.0
>
> With self written rules I have the possibility to execute a script with
> the "exec:" statement.
>
> Is there a way to execute a script for all these predefined rules if
> they are triggered ?
>
>
> Kind regards
>
> Hans
>
> --
>
>
>
>
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

--000000000000597ba806142a8fc8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr">Hi Hans!<div><br></div><=
div>To me, it&#39;s not clear what you&#39;re trying to achieve.</div><div>=
<div>You would probably have to write a new rule that checks whether rules =
have matched and therefore the blocking variables inbound or outbound (e.g.=
 tx.blocking_inbound_anomaly_score) are set. And then you &quot;exec:&quot;=
 and call your script in this new rule.=C2=A0</div><div>You can&#39;t test =
for individual rules, or at least I don&#39;t see how that could work right=
 now.</div></div><div><br></div><div>Best,</div><div>Franziska</div><div># =
CRS dev-on-duty</div></div></div></div><br><div class=3D"gmail_quote"><div =
dir=3D"ltr" class=3D"gmail_attr">Am Mi., 20. M=C3=A4rz 2024 um 21:03=C2=A0U=
hr schrieb Hans Mayer via mod-security-users &lt;<a href=3D"mailto:mod-secu=
[email protected]">[email protected]<=
/a>&gt;:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px=
 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><br>
Dear All,<br>
<br>
I am using Apache/2.4.57 on Debian with the modsecurity-crs package <br>
which is Producer ModSecurity for Apache/2.9.3 and Rule Set=C2=A0 OWASP_CRS=
/3.3.0<br>
<br>
With self written rules I have the possibility to execute a script with <br=
>
the &quot;exec:&quot; statement.<br>
<br>
Is there a way to execute a script for all these predefined rules if <br>
they are triggered ?<br>
<br>
<br>
Kind regards<br>
<br>
Hans<br>
<br>
-- <br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
_______________________________________________<br>
mod-security-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-users"=
 rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l=
istinfo/mod-security-users</a><br>
Commercial ModSecurity Rules and Support from Trustwave&#39;s SpiderLabs:<b=
r>
<a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=3D"no=
referrer" target=3D"_blank">http://www.modsecurity.org/projects/commercial/=
rules/</a><br>
<a href=3D"http://www.modsecurity.org/projects/commercial/support/" rel=3D"=
noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/commercia=
l/support/</a><br>
</blockquote></div>

--000000000000597ba806142a8fc8--


--===============0901551500777386349==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0901551500777386349==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============0901551500777386349==--