Re: [mod-security-users] Excluding headers that contain a substring
Brought to you by:
victorhora,
zimmerletw
From: Nick G. <nic...@gm...> - 2024-12-19 08:51:22
|
<!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> </head> <body> Hello,<br> <br> The proper way would something like<br> <blockquote>SecRule REQUEST_HEADERS "@contains select" "...,chain"<br> SecRule MATCHED_VARS_NAMES @unconditionalMatch "ctl:ruleRemoveTargetById=942032;%{MATCHED_VAR}"<br> </blockquote> Unfortunately, ruleRemoveTargetById doesn't support macro expansion.<br> No solution for the moment I'm afraid.<br> <br> <div class="moz-cite-prefix">On 15/12/2024 04:05, Anant Mudambi via mod-security-users wrote:<br> </div> <blockquote type="cite" cite="mid:CALPdRR5W+ha6P=A1O...@ma..."> <div dir="ltr">Hello, <div>Is it possible to write a rule exclusion that finds all headers that have a certain string in them and exclude only those headers in subsequent rule? Would something like this work?</div> <div><br> </div> <div>SecRule REQUEST_HEADERS "@contains select" "..., ctl:ruleRemoveTargetById=942032;%{MATCHED_VARS_NAMES}"</div> <div><br> </div> <div>Thanks,</div> <div>Anant</div> </div> </blockquote> </body> </html> |