Re: [Prelude Hybrid IDS] #216: mod_security cleanup, and compatibility with version 2.0

"Prelude Hybrid IDS" <[email protected]> Tue, 12 Aug 2008 12:48:30 -0000
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#216: mod_security cleanup, and compatibility with version 2.0
-------------------------+--------------------------------------------------
 Reporter:  gegomez      |        Owner:  Peter Vrabec <[email protected]>
     Type:  defect       |       Status:  assigned                         
 Priority:  normal       |    Milestone:  Prelude-LML 0.9.13               
Component:  prelude-lml  |      Version:  0.9                              
 Severity:  normal       |   Resolution:                                   
 Keywords:               |  
-------------------------+--------------------------------------------------

Comment(by [email protected]):

 Replying to [comment:16 yoann]:
 > Overall, the generated alert look good! Here are some feedback &
 questions:
 >
 >  * IDMEF require the Reference name and url to not be empty.

 See last attachment.

 >  * What is ModSec Rule ID?

 This is the ID of the mod_security rule that generated the log entry.

 >  * What is UniqueID?

 I don't know what this is exactly, but I think that apache identifies
 sessions with this. mod_unique_id is a separate apache module and
 mod_security requires it.

 >  * What exactly is the log format used in the ruleset log sample
 (doesn't look like raw log entry, there is no timestamp)?

 I changed the format back to the version with timestamp (apache
 error_log). See last attachment.

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/216#comment:17>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel