Re: [mod-security-users] Core Rule 960911 and SSL
Brought to you by:
victorhora,
zimmerletw
From: Jim H. - U. H. <hos...@uu...> - 2007-10-28 12:18:29
|
> Hey all-- > > I'm trying to use mod_security on an Apache 2.2 server that > handles a > fair amount of SSL traffic, but mod_security keeps throwing errors > about rule 960911 (from the core rule set), and causing the SSL > connection to fail. The audit logs contain messages like this: I'm having problems with rule 960911 also. They are very generic: GET /public_files/uploads/sermons/Closer%20to%20Fine%20(March%2020,%202005).doc HTTP/1.0 GET /social.htm#additional HTTP/1.1 GET /dispatch/dis9-1'htm/Export6.htm HTTP/1.0 Is this rule objecting to the parenthesis, the pound sign, and the apostophe in these three URIs? I thought the pound sign was used for anchors in URIs. Jim |