Re: [mod-security-users] Locking issue with enabled persistent collection
Brought to you by:
victorhora,
zimmerletw
From: Felipe C. <FC...@tr...> - 2014-04-16 17:39:21
|
Hi Winfried, On Apr 16, 2014, at 5:41 AM, Winfried Neessen <ne...@cl...<mailto:ne...@cl...>> wrote: Once the IP collection is enabled in the ruleset (in addtion to the blocking rules), the server still runs fine… at least for a couple of hours. But after approx. 5-12 hours the logs begin to throw messages There are some issues opened on GitHub related to similar problems. It seems that this problem is trigged in specific scenarios, so thanks for your detailed report, it is valuable. Low values for SecCollectionTimeout (https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#SecCollectionTimeout) may help you to minimize it. While debugging those issues we have created the modsec-sdbm-util, which is able to open the collection file and interpret its content as ModSecurity does. The utility can be downloaded here: https://github.com/SpiderLabs/modsec-sdbm-util. The full list of functionalities: https://github.com/SpiderLabs/modsec-sdbm-util/blob/master/README.md Similar problems have been reported in the following issues: https://github.com/SpiderLabs/ModSecurity/issues/558 https://github.com/SpiderLabs/ModSecurity/issues/314 https://github.com/SpiderLabs/ModSecurity/issues/574 https://github.com/SpiderLabs/ModSecurity/issues/473 We are also working in alternatives to SDBM: https://github.com/SpiderLabs/ModSecurity/issues/378 Br., Felipe "Zimmerle" Costa Security Researcher, SpiderLabs Trustwave | SMART SECURITY ON DEMAND www.trustwave.com<http://www.trustwave.com/> ________________________________ This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format. |