[Mod-security-report-false-positives] False positive in SimpleMachines Forum
Brought to you by:
victorhora,
zimmerletw
From: WHK <yan...@gm...> - 2016-04-05 18:23:43
|
The simplemachines system: http://download.simplemachines.org/ The false positive in cookies: SecRuleUpdateTargetById 981172 "!REQUEST_COOKIES:smf_session_data" But new false positive: [Tue Apr 05 15:01:25.067849 2016] [:error] [pid 26326] [client 190.101.13.170] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\W{4,}" at ARGS:admin_pass. [file "/home/androidlatinos/crs/activated_rules/modsecurity_crs_40_generic_attacks.conf"] [line "37"] [id "960024"] [rev "2"] [msg "Meta-Character Anomaly Detection Alert - Repetative Non-Word Characters"] [data "Matched Data: ********** found within ARGS:admin_pass: **********"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "8"] [hostname "androidlatinos.com"] [uri "/index.php"] [unique_id "VwP9dRs57cRZtOmSKcwYtwAAABs"] |