Re: Upgrade to owasp-coreruleset 4.13.0

Monah Baki <[email protected]> Sun, 6 Apr 2025 09:18:21 -0400
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CALP3=x8Mbh0r4bVJcMLuu3ciJ6rw+0fKk_p7c9E_CZyob5kjsA@mail.gmail.com>
--===============5717127653074039567==
Content-Type: multipart/alternative; boundary="000000000000fb086906321bf430"

--000000000000fb086906321bf430
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

No custom rules.

What I did is I renamed my owasp 4.13.0 to a different folder and moved my
owasp crs 4.8.0 back to its original folder, restarted apache and from
another machine typed the following:
curl -I https://osisolutions.net/index.php?f=3D/../../../../../etc/passwd

root@waf:/usr/local/etc/modsecurity # tail -f
/var/log/httpd/osisolutions-error_log
[Sun Apr 06 09:10:54.062738 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))|%46)|5c|c(?:0%(?=
:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0%8)0%80%a)f|u(?:2=
21[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0x(?:2f|5c))(?:\\\=
\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2(
..." at REQUEST_URI_RAW. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "53"] [id "930100"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within REQUEST_URI_RAW:
/index.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"] [ver
"OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "language-multi"]
[tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "osisolutions.net"]
[uri "/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
[Sun Apr 06 09:10:54.063066 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))|%46)|5c|c(?:0%(?=
:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0%8)0%80%a)f|u(?:2=
21[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0x(?:2f|5c))(?:\\\=
\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2(
..." at ARGS:f. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "53"] [id "930100"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within ARGS:f: /../../../../../etc/passwd"]
[severity "CRITICAL"] [ver "OWASP_CRS/4.8.0-dev"] [tag "application-multi"]
[tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag
"paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"]
[hostname "osisolutions.net"] [uri "/index.php"] [unique_id
"Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
[Sun Apr 06 09:10:54.063240 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?:(?:^|[\\\\x5c/;])\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\\\\x5c=
/;]|$))"
at REQUEST_URI. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "86"] [id "930110"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within REQUEST_URI:
/index.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"] [ver
"OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "language-multi"]
[tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "osisolutions.net"]
[uri "/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
[Sun Apr 06 09:10:54.063389 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?:(?:^|[\\\\x5c/;])\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\\\\x5c=
/;]|$))"
at REQUEST_URI. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "86"] [id "930110"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within REQUEST_URI:
/index.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"] [ver
"OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "language-multi"]
[tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "osisolutions.net"]
[uri "/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]



Went and reverted back my owasp 4.13.0 folder and ran the same curl command
and got

[Sun Apr 06 09:12:38.731325 2025] [security2:error] [pid 47228] [client
71.126.165.145:57026] ModSecurity: Access denied with code 500 (phase 1).
Operator EQ matched 0 at TX. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-901-INITIAL=
IZATION.conf"]
[line "64"] [id "901001"] [msg "CRS is deployed without configuration!
Please copy the crs-setup.conf.example template to crs-setup.conf, and
include the crs-setup.conf file in your webserver configuration before
including the CRS rules. See the INSTALL file in the CRS directory for
detailed instructions"] [severity "CRITICAL"] [ver "OWASP_CRS/4.13.0"] [tag
"OWASP_CRS"] [hostname "osisolutions.net"] [uri "/index.php"] [unique_id
"Z_J9xiNCfPcpnd_qywN4xQAAAAA"]

On Sun, Apr 6, 2025 at 9:08=E2=80=AFAM <[email protected]> wrote:

> Are you using any custom rules or CRS modifications?
>
>
>
>
>
> Cit=C3=A1t Monah Baki <[email protected]>:
>
> > Hi Ervin,
> >
> > Here is he output
> > root@waf:/usr/local/etc/apache24 #  grep -A12 900990
> > /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf
> >     "id:900990,\
> >     phase:1,\
> >     pass,\
> >     t:none,\
> >     nolog,\
> >     tag:'OWASP_CRS',\
> >     ver:'OWASP_CRS/4.13.0',\
> >     setvar:tx.crs_setup_version=3D4130"
> >
> > As far as my apache using
> > /usr/local/etc/apache24/modules.d/280_mod_security.conf, I am sure
> because
> > if I were to comment
> > LoadModule unique_id_module libexec/apache24/mod_unique_id.so
> > LoadModule security2_module /usr/local/modsecurity/lib/mod_security2.so
> >
> > I get
> >
> > root@waf:/home/mbaki # apachectl restart
> > Performing sanity check on apache24 configuration:
> > AH00526: Syntax error on line 97 of
> > /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf:
> > Invalid command 'SecDefaultAction', perhaps misspelled or defined by a
> > module not included in the server configuration
> >
> > Thanks
> > Monah
> >
> > On Sun, Apr 6, 2025 at 4:54=E2=80=AFAM Ervin Heged=C3=BCs <airween@gmai=
l.com> wrote:
> >
> >> Hi Monan,
> >>
> >>
> >> On Sat, Apr 05, 2025 at 04:02:09PM -0400, Monah Baki wrote:
> >> >
> >> > ls /usr/local/etc/modsecurity/owasp-modsecurity-crs
> >> > crs-setup.conf
> >>
> >> as Christian wrote this is very strange.
> >>
> >> Anyway,
> >>
> >> are you sure your engine use this file?
> >>
> >> > cat /usr/local/etc/apache24/modules.d/280_mod_security.conf
> >>
> >> could you replace this line:
> >>
> >> > IncludeOptional
> >> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf
> >>
> >> by this one:
> >>
> >> Include /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.con=
f
> >>
> >> so just remote the "Optional" string.
> >>
> >> And could you show us the output of this command?
> >>
> >> grep -A12 900990
> >> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf
> >>
> >>
> >> Thanks,
> >>
> >>
> >> a.
> >>
> >>
> >>
> >> _______________________________________________
> >> mod-security-users mailing list
> >> [email protected]
> >> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> >> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> >> http://www.modsecurity.org/projects/commercial/rules/
> >> http://www.modsecurity.org/projects/commercial/support/
> >>
>
>
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

--000000000000fb086906321bf430
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">No custom rules.<div><br></div><div>What I did is I rename=
d my owasp 4.13.0 to a different folder and moved my owasp crs 4.8.0 back t=
o its original folder, restarted apache and from another machine typed the =
following:</div><div>curl -I <a href=3D"https://osisolutions.net/index.php?=
f=3D/../../../../../etc/passwd">https://osisolutions.net/index.php?f=3D/../=
../../../../etc/passwd</a><br></div><div><br></div><div>root@waf:/usr/local=
/etc/modsecurity # tail -f /var/log/httpd/osisolutions-error_log<br>[Sun Ap=
r 06 09:10:54.062738 2025] [security2:error] [pid 47174] [client <a href=3D=
"http://71.126.165.145:53450">71.126.165.145:53450</a>] ModSecurity: Warnin=
g. Pattern match &quot;(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%2=
5af))|%46)|5c|c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8=
%8)?0%8)0%80%a)f|u(?:221[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|=
1u)|0x(?:2f|5c))(?:\\\\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2( ...&quot; at R=
EQUEST_URI_RAW. [file &quot;/usr/local/etc/modsecurity/owasp-modsecurity-cr=
s/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf&quot;] [line &quot;53&quot;=
] [id &quot;930100&quot;] [msg &quot;Path Traversal Attack (/../) or (/.../=
)&quot;] [data &quot;Matched Data: /../ found within REQUEST_URI_RAW: /inde=
x.php?f=3D/../../../../../etc/passwd&quot;] [severity &quot;CRITICAL&quot;]=
 [ver &quot;OWASP_CRS/4.8.0-dev&quot;] [tag &quot;application-multi&quot;] =
[tag &quot;language-multi&quot;] [tag &quot;platform-multi&quot;] [tag &quo=
t;attack-lfi&quot;] [tag &quot;paranoia-level/1&quot;] [tag &quot;OWASP_CRS=
&quot;] [tag &quot;capec/1000/255/153/126&quot;] [hostname &quot;<a href=3D=
"http://osisolutions.net">osisolutions.net</a>&quot;] [uri &quot;/index.php=
&quot;] [unique_id &quot;Z_J9XgOebQ1Fdmj9nC2ctgAAAAA&quot;]<br>[Sun Apr 06 =
09:10:54.063066 2025] [security2:error] [pid 47174] [client <a href=3D"http=
://71.126.165.145:53450">71.126.165.145:53450</a>] ModSecurity: Warning. Pa=
ttern match &quot;(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))=
|%46)|5c|c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0=
%8)0%80%a)f|u(?:221[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0=
x(?:2f|5c))(?:\\\\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2( ...&quot; at ARGS:f=
. [file &quot;/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUES=
T-930-APPLICATION-ATTACK-LFI.conf&quot;] [line &quot;53&quot;] [id &quot;93=
0100&quot;] [msg &quot;Path Traversal Attack (/../) or (/.../)&quot;] [data=
 &quot;Matched Data: /../ found within ARGS:f: /../../../../../etc/passwd&q=
uot;] [severity &quot;CRITICAL&quot;] [ver &quot;OWASP_CRS/4.8.0-dev&quot;]=
 [tag &quot;application-multi&quot;] [tag &quot;language-multi&quot;] [tag =
&quot;platform-multi&quot;] [tag &quot;attack-lfi&quot;] [tag &quot;paranoi=
a-level/1&quot;] [tag &quot;OWASP_CRS&quot;] [tag &quot;capec/1000/255/153/=
126&quot;] [hostname &quot;<a href=3D"http://osisolutions.net">osisolutions=
.net</a>&quot;] [uri &quot;/index.php&quot;] [unique_id &quot;Z_J9XgOebQ1Fd=
mj9nC2ctgAAAAA&quot;]<br>[Sun Apr 06 09:10:54.063240 2025] [security2:error=
] [pid 47174] [client <a href=3D"http://71.126.165.145:53450">71.126.165.14=
5:53450</a>] ModSecurity: Warning. Pattern match &quot;(?:(?:^|[\\\\x5c/;])=
\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\\\\x5c/;]|$))&quot; at REQU=
EST_URI. [file &quot;/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules=
/REQUEST-930-APPLICATION-ATTACK-LFI.conf&quot;] [line &quot;86&quot;] [id &=
quot;930110&quot;] [msg &quot;Path Traversal Attack (/../) or (/.../)&quot;=
] [data &quot;Matched Data: /../ found within REQUEST_URI: /index.php?f=3D/=
../../../../../etc/passwd&quot;] [severity &quot;CRITICAL&quot;] [ver &quot=
;OWASP_CRS/4.8.0-dev&quot;] [tag &quot;application-multi&quot;] [tag &quot;=
language-multi&quot;] [tag &quot;platform-multi&quot;] [tag &quot;attack-lf=
i&quot;] [tag &quot;paranoia-level/1&quot;] [tag &quot;OWASP_CRS&quot;] [ta=
g &quot;capec/1000/255/153/126&quot;] [hostname &quot;<a href=3D"http://osi=
solutions.net">osisolutions.net</a>&quot;] [uri &quot;/index.php&quot;] [un=
ique_id &quot;Z_J9XgOebQ1Fdmj9nC2ctgAAAAA&quot;]<br>[Sun Apr 06 09:10:54.06=
3389 2025] [security2:error] [pid 47174] [client <a href=3D"http://71.126.1=
65.145:53450">71.126.165.145:53450</a>] ModSecurity: Warning. Pattern match=
 &quot;(?:(?:^|[\\\\x5c/;])\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\=
\\\x5c/;]|$))&quot; at REQUEST_URI. [file &quot;/usr/local/etc/modsecurity/=
owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf&quot;] =
[line &quot;86&quot;] [id &quot;930110&quot;] [msg &quot;Path Traversal Att=
ack (/../) or (/.../)&quot;] [data &quot;Matched Data: /../ found within RE=
QUEST_URI: /index.php?f=3D/../../../../../etc/passwd&quot;] [severity &quot=
;CRITICAL&quot;] [ver &quot;OWASP_CRS/4.8.0-dev&quot;] [tag &quot;applicati=
on-multi&quot;] [tag &quot;language-multi&quot;] [tag &quot;platform-multi&=
quot;] [tag &quot;attack-lfi&quot;] [tag &quot;paranoia-level/1&quot;] [tag=
 &quot;OWASP_CRS&quot;] [tag &quot;capec/1000/255/153/126&quot;] [hostname =
&quot;<a href=3D"http://osisolutions.net">osisolutions.net</a>&quot;] [uri =
&quot;/index.php&quot;] [unique_id &quot;Z_J9XgOebQ1Fdmj9nC2ctgAAAAA&quot;]=
<br><br></div><div><br></div><div><br></div><div>Went and reverted back my =
owasp 4.13.0 folder and ran the same curl command and got=C2=A0</div><div><=
br></div><div>[Sun Apr 06 09:12:38.731325 2025] [security2:error] [pid 4722=
8] [client <a href=3D"http://71.126.165.145:57026">71.126.165.145:57026</a>=
] ModSecurity: Access denied with code 500 (phase 1). Operator EQ matched 0=
 at TX. [file &quot;/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/=
REQUEST-901-INITIALIZATION.conf&quot;] [line &quot;64&quot;] [id &quot;9010=
01&quot;] [msg &quot;CRS is deployed without configuration! Please copy the=
 crs-setup.conf.example template to crs-setup.conf, and include the crs-set=
up.conf file in your webserver configuration before including the CRS rules=
. See the INSTALL file in the CRS directory for detailed instructions&quot;=
] [severity &quot;CRITICAL&quot;] [ver &quot;OWASP_CRS/4.13.0&quot;] [tag &=
quot;OWASP_CRS&quot;] [hostname &quot;<a href=3D"http://osisolutions.net">o=
sisolutions.net</a>&quot;] [uri &quot;/index.php&quot;] [unique_id &quot;Z_=
J9xiNCfPcpnd_qywN4xQAAAAA&quot;]<br></div></div><br><div class=3D"gmail_quo=
te gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Apr=
 6, 2025 at 9:08=E2=80=AFAM &lt;<a href=3D"mailto:[email protected]">azurit@p=
obox.sk</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"=
margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-lef=
t:1ex">Are you using any custom rules or CRS modifications?<br>
<br>
<br>
<br>
<br>
<br>
Cit=C3=A1t Monah Baki &lt;<a href=3D"mailto:[email protected]" target=3D"=
_blank">[email protected]</a>&gt;:<br>
<br>
&gt; Hi Ervin,<br>
&gt;<br>
&gt; Here is he output<br>
&gt; root@waf:/usr/local/etc/apache24 #=C2=A0 grep -A12 900990<br>
&gt; /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf<br>
&gt;=C2=A0 =C2=A0 =C2=A0&quot;id:900990,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0phase:1,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0pass,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0t:none,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0nolog,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0tag:&#39;OWASP_CRS&#39;,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0ver:&#39;OWASP_CRS/4.13.0&#39;,\<br>
&gt;=C2=A0 =C2=A0 =C2=A0setvar:tx.crs_setup_version=3D4130&quot;<br>
&gt;<br>
&gt; As far as my apache using<br>
&gt; /usr/local/etc/apache24/modules.d/280_mod_security.conf, I am sure bec=
ause<br>
&gt; if I were to comment<br>
&gt; LoadModule unique_id_module libexec/apache24/mod_unique_id.so<br>
&gt; LoadModule security2_module /usr/local/modsecurity/lib/mod_security2.s=
o<br>
&gt;<br>
&gt; I get<br>
&gt;<br>
&gt; root@waf:/home/mbaki # apachectl restart<br>
&gt; Performing sanity check on apache24 configuration:<br>
&gt; AH00526: Syntax error on line 97 of<br>
&gt; /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf:<br>
&gt; Invalid command &#39;SecDefaultAction&#39;, perhaps misspelled or defi=
ned by a<br>
&gt; module not included in the server configuration<br>
&gt;<br>
&gt; Thanks<br>
&gt; Monah<br>
&gt;<br>
&gt; On Sun, Apr 6, 2025 at 4:54=E2=80=AFAM Ervin Heged=C3=BCs &lt;<a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt; w=
rote:<br>
&gt;<br>
&gt;&gt; Hi Monan,<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; On Sat, Apr 05, 2025 at 04:02:09PM -0400, Monah Baki wrote:<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; ls /usr/local/etc/modsecurity/owasp-modsecurity-crs<br>
&gt;&gt; &gt; crs-setup.conf<br>
&gt;&gt;<br>
&gt;&gt; as Christian wrote this is very strange.<br>
&gt;&gt;<br>
&gt;&gt; Anyway,<br>
&gt;&gt;<br>
&gt;&gt; are you sure your engine use this file?<br>
&gt;&gt;<br>
&gt;&gt; &gt; cat /usr/local/etc/apache24/modules.d/280_mod_security.conf<b=
r>
&gt;&gt;<br>
&gt;&gt; could you replace this line:<br>
&gt;&gt;<br>
&gt;&gt; &gt; IncludeOptional<br>
&gt;&gt; /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf<br=
>
&gt;&gt;<br>
&gt;&gt; by this one:<br>
&gt;&gt;<br>
&gt;&gt; Include /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup=
.conf<br>
&gt;&gt;<br>
&gt;&gt; so just remote the &quot;Optional&quot; string.<br>
&gt;&gt;<br>
&gt;&gt; And could you show us the output of this command?<br>
&gt;&gt;<br>
&gt;&gt; grep -A12 900990<br>
&gt;&gt; /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf<br=
>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; Thanks,<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; a.<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; _______________________________________________<br>
&gt;&gt; mod-security-users mailing list<br>
&gt;&gt; <a href=3D"mailto:[email protected]" target=
=3D"_blank">[email protected]</a><br>
&gt;&gt; <a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-securi=
ty-users" rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.ne=
t/lists/listinfo/mod-security-users</a><br>
&gt;&gt; Commercial ModSecurity Rules and Support from Trustwave&#39;s Spid=
erLabs:<br>
&gt;&gt; <a href=3D"http://www.modsecurity.org/projects/commercial/rules/" =
rel=3D"noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/co=
mmercial/rules/</a><br>
&gt;&gt; <a href=3D"http://www.modsecurity.org/projects/commercial/support/=
" rel=3D"noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/=
commercial/support/</a><br>
&gt;&gt;<br>
<br>
<br>
<br>
<br>
<br>
_______________________________________________<br>
mod-security-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-users"=
 rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l=
istinfo/mod-security-users</a><br>
Commercial ModSecurity Rules and Support from Trustwave&#39;s SpiderLabs:<b=
r>
<a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=3D"no=
referrer" target=3D"_blank">http://www.modsecurity.org/projects/commercial/=
rules/</a><br>
<a href=3D"http://www.modsecurity.org/projects/commercial/support/" rel=3D"=
noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/commercia=
l/support/</a><br>
</blockquote></div>

--000000000000fb086906321bf430--


--===============5717127653074039567==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============5717127653074039567==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============5717127653074039567==--