I have installed modsecurity 2.7.3 on Nginx 1.4.1 and just about everything appears to work correctly with the exception of images over around 50K in size.  I added some of the OWASP rules and started testing my site and found that images larger that 50k wouldn’t display. 

 

I checked the nginx and modsecurity rules and found no alerts when accessing the pages that serve images larger than 50, so I started removing the rules.  I ended up removing all rules and still have the same problem.  All other content works, blocking works, etc other than images > 50k in size.

 

I then tried just setting modsecurity to detection only mode with and without any rules enabled with the same results.

 

What am I missing?

 

 

Thanks,

 

Josh Berry