Re: Upgrade to owasp-coreruleset 4.13.0
Monah Baki <[email protected]> Sun, 6 Apr 2025 09:18:21 -0400
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CALP3=x8Mbh0r4bVJcMLuu3ciJ6rw+0fKk_p7c9E_CZyob5kjsA@mail.gmail.com> |
--===============5717127653074039567==
Content-Type: multipart/alternative; boundary="000000000000fb086906321bf430"
--000000000000fb086906321bf430
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
No custom rules.
What I did is I renamed my owasp 4.13.0 to a different folder and moved my
owasp crs 4.8.0 back to its original folder, restarted apache and from
another machine typed the following:
curl -I https://osisolutions.net/index.php?f=3D/../../../../../etc/passwd
root@waf:/usr/local/etc/modsecurity # tail -f
/var/log/httpd/osisolutions-error_log
[Sun Apr 06 09:10:54.062738 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))|%46)|5c|c(?:0%(?=
:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0%8)0%80%a)f|u(?:2=
21[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0x(?:2f|5c))(?:\\\=
\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2(
..." at REQUEST_URI_RAW. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "53"] [id "930100"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within REQUEST_URI_RAW:
/index.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"] [ver
"OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "language-multi"]
[tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "osisolutions.net"]
[uri "/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
[Sun Apr 06 09:10:54.063066 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))|%46)|5c|c(?:0%(?=
:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0%8)0%80%a)f|u(?:2=
21[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0x(?:2f|5c))(?:\\\=
\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2(
..." at ARGS:f. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "53"] [id "930100"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within ARGS:f: /../../../../../etc/passwd"]
[severity "CRITICAL"] [ver "OWASP_CRS/4.8.0-dev"] [tag "application-multi"]
[tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag
"paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"]
[hostname "osisolutions.net"] [uri "/index.php"] [unique_id
"Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
[Sun Apr 06 09:10:54.063240 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?:(?:^|[\\\\x5c/;])\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\\\\x5c=
/;]|$))"
at REQUEST_URI. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "86"] [id "930110"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within REQUEST_URI:
/index.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"] [ver
"OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "language-multi"]
[tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "osisolutions.net"]
[uri "/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
[Sun Apr 06 09:10:54.063389 2025] [security2:error] [pid 47174] [client
71.126.165.145:53450] ModSecurity: Warning. Pattern match
"(?:(?:^|[\\\\x5c/;])\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\\\\x5c=
/;]|$))"
at REQUEST_URI. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-930-APPLICA=
TION-ATTACK-LFI.conf"]
[line "86"] [id "930110"] [msg "Path Traversal Attack (/../) or (/.../)"]
[data "Matched Data: /../ found within REQUEST_URI:
/index.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"] [ver
"OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "language-multi"]
[tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "osisolutions.net"]
[uri "/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]
Went and reverted back my owasp 4.13.0 folder and ran the same curl command
and got
[Sun Apr 06 09:12:38.731325 2025] [security2:error] [pid 47228] [client
71.126.165.145:57026] ModSecurity: Access denied with code 500 (phase 1).
Operator EQ matched 0 at TX. [file
"/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUEST-901-INITIAL=
IZATION.conf"]
[line "64"] [id "901001"] [msg "CRS is deployed without configuration!
Please copy the crs-setup.conf.example template to crs-setup.conf, and
include the crs-setup.conf file in your webserver configuration before
including the CRS rules. See the INSTALL file in the CRS directory for
detailed instructions"] [severity "CRITICAL"] [ver "OWASP_CRS/4.13.0"] [tag
"OWASP_CRS"] [hostname "osisolutions.net"] [uri "/index.php"] [unique_id
"Z_J9xiNCfPcpnd_qywN4xQAAAAA"]
On Sun, Apr 6, 2025 at 9:08=E2=80=AFAM <[email protected]> wrote:
> Are you using any custom rules or CRS modifications?
>
>
>
>
>
> Cit=C3=A1t Monah Baki <[email protected]>:
>
> > Hi Ervin,
> >
> > Here is he output
> > root@waf:/usr/local/etc/apache24 # grep -A12 900990
> > /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf
> > "id:900990,\
> > phase:1,\
> > pass,\
> > t:none,\
> > nolog,\
> > tag:'OWASP_CRS',\
> > ver:'OWASP_CRS/4.13.0',\
> > setvar:tx.crs_setup_version=3D4130"
> >
> > As far as my apache using
> > /usr/local/etc/apache24/modules.d/280_mod_security.conf, I am sure
> because
> > if I were to comment
> > LoadModule unique_id_module libexec/apache24/mod_unique_id.so
> > LoadModule security2_module /usr/local/modsecurity/lib/mod_security2.so
> >
> > I get
> >
> > root@waf:/home/mbaki # apachectl restart
> > Performing sanity check on apache24 configuration:
> > AH00526: Syntax error on line 97 of
> > /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf:
> > Invalid command 'SecDefaultAction', perhaps misspelled or defined by a
> > module not included in the server configuration
> >
> > Thanks
> > Monah
> >
> > On Sun, Apr 6, 2025 at 4:54=E2=80=AFAM Ervin Heged=C3=BCs <airween@gmai=
l.com> wrote:
> >
> >> Hi Monan,
> >>
> >>
> >> On Sat, Apr 05, 2025 at 04:02:09PM -0400, Monah Baki wrote:
> >> >
> >> > ls /usr/local/etc/modsecurity/owasp-modsecurity-crs
> >> > crs-setup.conf
> >>
> >> as Christian wrote this is very strange.
> >>
> >> Anyway,
> >>
> >> are you sure your engine use this file?
> >>
> >> > cat /usr/local/etc/apache24/modules.d/280_mod_security.conf
> >>
> >> could you replace this line:
> >>
> >> > IncludeOptional
> >> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf
> >>
> >> by this one:
> >>
> >> Include /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.con=
f
> >>
> >> so just remote the "Optional" string.
> >>
> >> And could you show us the output of this command?
> >>
> >> grep -A12 900990
> >> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf
> >>
> >>
> >> Thanks,
> >>
> >>
> >> a.
> >>
> >>
> >>
> >> _______________________________________________
> >> mod-security-users mailing list
> >> [email protected]
> >> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> >> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> >> http://www.modsecurity.org/projects/commercial/rules/
> >> http://www.modsecurity.org/projects/commercial/support/
> >>
>
>
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>
--000000000000fb086906321bf430
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr">No custom rules.<div><br></div><div>What I did is I rename=
d my owasp 4.13.0 to a different folder and moved my owasp crs 4.8.0 back t=
o its original folder, restarted apache and from another machine typed the =
following:</div><div>curl -I <a href=3D"https://osisolutions.net/index.php?=
f=3D/../../../../../etc/passwd">https://osisolutions.net/index.php?f=3D/../=
../../../../etc/passwd</a><br></div><div><br></div><div>root@waf:/usr/local=
/etc/modsecurity # tail -f /var/log/httpd/osisolutions-error_log<br>[Sun Ap=
r 06 09:10:54.062738 2025] [security2:error] [pid 47174] [client <a href=3D=
"http://71.126.165.145:53450">71.126.165.145:53450</a>] ModSecurity: Warnin=
g. Pattern match "(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%2=
5af))|%46)|5c|c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8=
%8)?0%8)0%80%a)f|u(?:221[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|=
1u)|0x(?:2f|5c))(?:\\\\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2( ..." at R=
EQUEST_URI_RAW. [file "/usr/local/etc/modsecurity/owasp-modsecurity-cr=
s/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "53"=
] [id "930100"] [msg "Path Traversal Attack (/../) or (/.../=
)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /inde=
x.php?f=3D/../../../../../etc/passwd"] [severity "CRITICAL"]=
[ver "OWASP_CRS/4.8.0-dev"] [tag "application-multi"] =
[tag "language-multi"] [tag "platform-multi"] [tag &quo=
t;attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS=
"] [tag "capec/1000/255/153/126"] [hostname "<a href=3D=
"http://osisolutions.net">osisolutions.net</a>"] [uri "/index.php=
"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]<br>[Sun Apr 06 =
09:10:54.063066 2025] [security2:error] [pid 47174] [client <a href=3D"http=
://71.126.165.145:53450">71.126.165.145:53450</a>] ModSecurity: Warning. Pa=
ttern match "(?i)(?:[/\\\\x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))=
|%46)|5c|c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0=
%8)0%80%a)f|u(?:221[56]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0=
x(?:2f|5c))(?:\\\\.(?:%0[01]|\\\\?)?|\\\\?\\\\.?|%(?:2( ..." at ARGS:f=
. [file "/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/REQUES=
T-930-APPLICATION-ATTACK-LFI.conf"] [line "53"] [id "93=
0100"] [msg "Path Traversal Attack (/../) or (/.../)"] [data=
"Matched Data: /../ found within ARGS:f: /../../../../../etc/passwd&q=
uot;] [severity "CRITICAL"] [ver "OWASP_CRS/4.8.0-dev"]=
[tag "application-multi"] [tag "language-multi"] [tag =
"platform-multi"] [tag "attack-lfi"] [tag "paranoi=
a-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/=
126"] [hostname "<a href=3D"http://osisolutions.net">osisolutions=
.net</a>"] [uri "/index.php"] [unique_id "Z_J9XgOebQ1Fd=
mj9nC2ctgAAAAA"]<br>[Sun Apr 06 09:10:54.063240 2025] [security2:error=
] [pid 47174] [client <a href=3D"http://71.126.165.145:53450">71.126.165.14=
5:53450</a>] ModSecurity: Warning. Pattern match "(?:(?:^|[\\\\x5c/;])=
\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\\\\x5c/;]|$))" at REQU=
EST_URI. [file "/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules=
/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "86"] [id &=
quot;930110"] [msg "Path Traversal Attack (/../) or (/.../)"=
] [data "Matched Data: /../ found within REQUEST_URI: /index.php?f=3D/=
../../../../../etc/passwd"] [severity "CRITICAL"] [ver "=
;OWASP_CRS/4.8.0-dev"] [tag "application-multi"] [tag "=
language-multi"] [tag "platform-multi"] [tag "attack-lf=
i"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [ta=
g "capec/1000/255/153/126"] [hostname "<a href=3D"http://osi=
solutions.net">osisolutions.net</a>"] [uri "/index.php"] [un=
ique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]<br>[Sun Apr 06 09:10:54.06=
3389 2025] [security2:error] [pid 47174] [client <a href=3D"http://71.126.1=
65.145:53450">71.126.165.145:53450</a>] ModSecurity: Warning. Pattern match=
"(?:(?:^|[\\\\x5c/;])\\\\.{2,3}[\\\\x5c/;]|[\\\\x5c/;]\\\\.{2,3}(?:[\=
\\\x5c/;]|$))" at REQUEST_URI. [file "/usr/local/etc/modsecurity/=
owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] =
[line "86"] [id "930110"] [msg "Path Traversal Att=
ack (/../) or (/.../)"] [data "Matched Data: /../ found within RE=
QUEST_URI: /index.php?f=3D/../../../../../etc/passwd"] [severity "=
;CRITICAL"] [ver "OWASP_CRS/4.8.0-dev"] [tag "applicati=
on-multi"] [tag "language-multi"] [tag "platform-multi&=
quot;] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag=
"OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname =
"<a href=3D"http://osisolutions.net">osisolutions.net</a>"] [uri =
"/index.php"] [unique_id "Z_J9XgOebQ1Fdmj9nC2ctgAAAAA"]=
<br><br></div><div><br></div><div><br></div><div>Went and reverted back my =
owasp 4.13.0 folder and ran the same curl command and got=C2=A0</div><div><=
br></div><div>[Sun Apr 06 09:12:38.731325 2025] [security2:error] [pid 4722=
8] [client <a href=3D"http://71.126.165.145:57026">71.126.165.145:57026</a>=
] ModSecurity: Access denied with code 500 (phase 1). Operator EQ matched 0=
at TX. [file "/usr/local/etc/modsecurity/owasp-modsecurity-crs/rules/=
REQUEST-901-INITIALIZATION.conf"] [line "64"] [id "9010=
01"] [msg "CRS is deployed without configuration! Please copy the=
crs-setup.conf.example template to crs-setup.conf, and include the crs-set=
up.conf file in your webserver configuration before including the CRS rules=
. See the INSTALL file in the CRS directory for detailed instructions"=
] [severity "CRITICAL"] [ver "OWASP_CRS/4.13.0"] [tag &=
quot;OWASP_CRS"] [hostname "<a href=3D"http://osisolutions.net">o=
sisolutions.net</a>"] [uri "/index.php"] [unique_id "Z_=
J9xiNCfPcpnd_qywN4xQAAAAA"]<br></div></div><br><div class=3D"gmail_quo=
te gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Apr=
6, 2025 at 9:08=E2=80=AFAM <<a href=3D"mailto:[email protected]">azurit@p=
obox.sk</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"=
margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-lef=
t:1ex">Are you using any custom rules or CRS modifications?<br>
<br>
<br>
<br>
<br>
<br>
Cit=C3=A1t Monah Baki <<a href=3D"mailto:[email protected]" target=3D"=
_blank">[email protected]</a>>:<br>
<br>
> Hi Ervin,<br>
><br>
> Here is he output<br>
> root@waf:/usr/local/etc/apache24 #=C2=A0 grep -A12 900990<br>
> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf<br>
>=C2=A0 =C2=A0 =C2=A0"id:900990,\<br>
>=C2=A0 =C2=A0 =C2=A0phase:1,\<br>
>=C2=A0 =C2=A0 =C2=A0pass,\<br>
>=C2=A0 =C2=A0 =C2=A0t:none,\<br>
>=C2=A0 =C2=A0 =C2=A0nolog,\<br>
>=C2=A0 =C2=A0 =C2=A0tag:'OWASP_CRS',\<br>
>=C2=A0 =C2=A0 =C2=A0ver:'OWASP_CRS/4.13.0',\<br>
>=C2=A0 =C2=A0 =C2=A0setvar:tx.crs_setup_version=3D4130"<br>
><br>
> As far as my apache using<br>
> /usr/local/etc/apache24/modules.d/280_mod_security.conf, I am sure bec=
ause<br>
> if I were to comment<br>
> LoadModule unique_id_module libexec/apache24/mod_unique_id.so<br>
> LoadModule security2_module /usr/local/modsecurity/lib/mod_security2.s=
o<br>
><br>
> I get<br>
><br>
> root@waf:/home/mbaki # apachectl restart<br>
> Performing sanity check on apache24 configuration:<br>
> AH00526: Syntax error on line 97 of<br>
> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf:<br>
> Invalid command 'SecDefaultAction', perhaps misspelled or defi=
ned by a<br>
> module not included in the server configuration<br>
><br>
> Thanks<br>
> Monah<br>
><br>
> On Sun, Apr 6, 2025 at 4:54=E2=80=AFAM Ervin Heged=C3=BCs <<a href=
=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>> w=
rote:<br>
><br>
>> Hi Monan,<br>
>><br>
>><br>
>> On Sat, Apr 05, 2025 at 04:02:09PM -0400, Monah Baki wrote:<br>
>> ><br>
>> > ls /usr/local/etc/modsecurity/owasp-modsecurity-crs<br>
>> > crs-setup.conf<br>
>><br>
>> as Christian wrote this is very strange.<br>
>><br>
>> Anyway,<br>
>><br>
>> are you sure your engine use this file?<br>
>><br>
>> > cat /usr/local/etc/apache24/modules.d/280_mod_security.conf<b=
r>
>><br>
>> could you replace this line:<br>
>><br>
>> > IncludeOptional<br>
>> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf<br=
>
>><br>
>> by this one:<br>
>><br>
>> Include /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup=
.conf<br>
>><br>
>> so just remote the "Optional" string.<br>
>><br>
>> And could you show us the output of this command?<br>
>><br>
>> grep -A12 900990<br>
>> /usr/local/etc/modsecurity/owasp-modsecurity-crs/crs-setup.conf<br=
>
>><br>
>><br>
>> Thanks,<br>
>><br>
>><br>
>> a.<br>
>><br>
>><br>
>><br>
>> _______________________________________________<br>
>> mod-security-users mailing list<br>
>> <a href=3D"mailto:[email protected]" target=
=3D"_blank">[email protected]</a><br>
>> <a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-securi=
ty-users" rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.ne=
t/lists/listinfo/mod-security-users</a><br>
>> Commercial ModSecurity Rules and Support from Trustwave's Spid=
erLabs:<br>
>> <a href=3D"http://www.modsecurity.org/projects/commercial/rules/" =
rel=3D"noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/co=
mmercial/rules/</a><br>
>> <a href=3D"http://www.modsecurity.org/projects/commercial/support/=
" rel=3D"noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/=
commercial/support/</a><br>
>><br>
<br>
<br>
<br>
<br>
<br>
_______________________________________________<br>
mod-security-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-users"=
rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l=
istinfo/mod-security-users</a><br>
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:<b=
r>
<a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=3D"no=
referrer" target=3D"_blank">http://www.modsecurity.org/projects/commercial/=
rules/</a><br>
<a href=3D"http://www.modsecurity.org/projects/commercial/support/" rel=3D"=
noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/commercia=
l/support/</a><br>
</blockquote></div>
--000000000000fb086906321bf430--
--===============5717127653074039567==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============5717127653074039567==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
--===============5717127653074039567==--