Re: Trying out "early blocking"
Andrew Howe via mod-security-users <[email protected]> Thu, 19 Jun 2025 14:01:28 +0100
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CAO2fWAZH9mTQ1sBVgEV5dYuWLA5fjZHN_ty0y6VZMmBqRQiS3g@mail.gmail.com> |
Hi Rakesh, That is a separate issue to the early blocking discussion thread. But you could try taking a look at your Apache logs and see what is causing your '400 Bad Request' responses. Likely, the bad requests are fundamentally malformed and cause an immediate 400 response from Apache. You could move the enforcement of your IP address deny list to somewhere before the ModSecurity stage if this is a problem and you need to ensure a consistent response. As early as possible is ideal, e.g. at a perimeter firewall. Thanks, Andrew _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/