On Wed, Oct 30, 2013 at 11:08 AM, Jan Phillip Greimann <jg@softjury.de> wrote:

Hi Josh,

that's not quite the answer to my question. My question is about the
ARGS which are used within the Action


Not for the rule-filter itself.

Hi Jan,

Sorry for the confusion. To exclude multiple variables, try using multiple ctl directives within the action. For example the following rules return a 403 if the string 'jojo' is in a parameter value unless the parameter name is 't' or 'y'.

SecRule REQUEST_FILENAME "^/$" "phase:2,id:2,t:none,pass,ctl:ruleRemoveTargetByTag=test;ARGS:t,ctl:ruleRemoveTargetByTag=test;ARGS:y"

SecRule ARGS jojo "phase:2,t:none,deny,id:1,tag:'test'"
 - Josh

- Jan

