Once the IP collection is enabled in the ruleset (in addtion to the blocking rules), the server still runs
fine… at least for a couple of hours. But after approx. 5-12 hours the logs begin to throw messages
There are some issues opened on GitHub related to similar problems. It seems that this problem is trigged in specific scenarios, so thanks for your detailed report, it is valuable.
While debugging those issues we have created the modsec-sdbm-util, which is able to open the collection file and interpret its content as ModSecurity does.
Similar problems have been reported in the following issues:
We are also working in alternatives to SDBM:
Felipe "Zimmerle" Costa
Security Researcher, SpiderLabs
Trustwave | SMART SECURITY ON DEMAND
This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information
contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format.