Re: [Prelude Hybrid IDS] #216: mod_security cleanup, and compatibility with version 2.0
"Prelude Hybrid IDS" <[email protected]> Thu, 14 Aug 2008 16:20:08 -0000
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#216: mod_security cleanup, and compatibility with version 2.0 -------------------------+-------------------------------------------------- Reporter: gegomez | Owner: Peter Vrabec <[email protected]> Type: defect | Status: assigned Priority: normal | Milestone: Prelude-LML 0.9.13 Component: prelude-lml | Version: 0.9 Severity: normal | Resolution: Keywords: | -------------------------+-------------------------------------------------- Comment(by yoann): Replying to [comment:19 dkopecek@…]: > Replying to [comment:18 yoann]: > > > > * What is ModSec Rule ID? > > > > > > This is the ID of the mod_security rule that generated the log entry. > > > > Is the RuleID tied to the "msg" part of the log (aka: one ID per msg)? > > Yes. > > > I am wondering whether we should use the "msg" part directly within classification.text. > > ... > > Do you have any opinion on the matter? > > The msg part can be very long and very specific. For example: > > "Injection of Undocumented ColdFusion Tags. Matched signature <%{TX.0}>" > > In error_log %{TX.0} is substituted with data from the session that triggered this alert. I thought that the classification.text should contain the 2 main alerts that modsecurity generates: warning and access denied. Should it be more specific? Thanks for the update, I guess we will keep your normalized version then. The ruleset now look ready to be included in the Prelude-LML repository, should I process with it now, or would you like to perform other modification before this is done? Thanks for your great work! -- Ticket URL: <https://trac.prelude-ids.org/ticket/216#comment:21> Prelude Hybrid IDS <http://www.prelude-ids.org> The Prelude Hybrid Intrusion Detection System suite _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel