mod-security-developers Mailing List for ModSecurity (Page 29)
Brought to you by:
victorhora,
zimmerletw
You can subscribe to this list here.
2006 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(8) |
Aug
(2) |
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2008 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2009 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(9) |
Sep
|
Oct
(1) |
Nov
|
Dec
(3) |
2010 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(2) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2011 |
Jan
|
Feb
(12) |
Mar
(42) |
Apr
(68) |
May
(30) |
Jun
(50) |
Jul
(17) |
Aug
(3) |
Sep
(5) |
Oct
(7) |
Nov
(3) |
Dec
(4) |
2012 |
Jan
(11) |
Feb
(11) |
Mar
(37) |
Apr
|
May
(21) |
Jun
(21) |
Jul
(12) |
Aug
(41) |
Sep
(19) |
Oct
(31) |
Nov
(24) |
Dec
(10) |
2013 |
Jan
(12) |
Feb
(18) |
Mar
(3) |
Apr
(8) |
May
(35) |
Jun
(5) |
Jul
(38) |
Aug
(5) |
Sep
(2) |
Oct
(4) |
Nov
(11) |
Dec
(6) |
2014 |
Jan
(3) |
Feb
(12) |
Mar
(11) |
Apr
(18) |
May
(2) |
Jun
(1) |
Jul
(11) |
Aug
(5) |
Sep
|
Oct
(15) |
Nov
(13) |
Dec
(9) |
2015 |
Jan
(2) |
Feb
(8) |
Mar
(7) |
Apr
(3) |
May
|
Jun
(1) |
Jul
(1) |
Aug
(1) |
Sep
(11) |
Oct
(14) |
Nov
(4) |
Dec
(1) |
2016 |
Jan
(11) |
Feb
(19) |
Mar
(20) |
Apr
(6) |
May
(3) |
Jun
(17) |
Jul
(5) |
Aug
|
Sep
(7) |
Oct
(2) |
Nov
(2) |
Dec
(12) |
2017 |
Jan
(4) |
Feb
(1) |
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
(3) |
Oct
(1) |
Nov
|
Dec
(15) |
2018 |
Jan
(13) |
Feb
(2) |
Mar
(14) |
Apr
(9) |
May
|
Jun
(6) |
Jul
(3) |
Aug
(1) |
Sep
(3) |
Oct
|
Nov
(13) |
Dec
(1) |
2019 |
Jan
(2) |
Feb
(9) |
Mar
(28) |
Apr
(4) |
May
(2) |
Jun
|
Jul
|
Aug
|
Sep
(4) |
Oct
|
Nov
|
Dec
(2) |
2020 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(3) |
Aug
|
Sep
(4) |
Oct
|
Nov
|
Dec
|
2022 |
Jan
|
Feb
(10) |
Mar
(3) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2024 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(4) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Breno S. <bre...@gm...> - 2012-07-29 02:12:16
|
Could you please give us more information ? Thanks Breno On Sat, Jul 28, 2012 at 9:49 AM, Vivian Ho <qin...@ya...> wrote: > > > > A future fix would be great. > > Thanks, > -v > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Vivian Ho <qin...@ya...> - 2012-07-28 14:49:40
|
A future fix would be great. Thanks, -v |
From: Breno S. P. (JIRA) <no...@mo...> - 2012-07-27 01:39:06
|
[ https://www.modsecurity.org/tracker/browse/MODSEC-322?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Breno Silva Pinto resolved MODSEC-322. -------------------------------------- Resolution: Fixed > Add ctl:ruleRemoveTargetById > ---------------------------- > > Key: MODSEC-322 > URL: https://www.modsecurity.org/tracker/browse/MODSEC-322 > Project: ModSecurity > Issue Type: New Feature > Security Level: Normal > Components: Actions > Reporter: Breno Silva Pinto > Assignee: Breno Silva Pinto > Fix For: 2.6.7 > > -- This message is automatically generated by JIRA. For more information on JIRA, see: http://www.atlassian.com/software/jira |
From: Breno S. <bre...@gm...> - 2012-07-26 23:38:06
|
Thanks Peter I will take a look On Thu, Jul 26, 2012 at 5:24 PM, Peter Heimann <hei...@we...> wrote: > Environment: AIX 5.3, Apache 2.2.22, IBM C compiler > > AIX 5.3 does not supply a strcasestr() function: > > libtool: link: cc_r -qlanglvl=extc99 -I/usr/local/apache/include > -I/usr/local/apache/include -I/usr/local/apache/include > -I/home/user/tmp/httpd-2.2.22/srclib/pcre > -I/usr/local/libxml/include/libxml2 -I/usr/lib/nls/loc/include > -DWITH_PCRE_STUDY -DMODSEC_PCRE_MATCH_LIMIT=10000 > -DMODSEC_PCRE_MATCH_LIMIT_RECURSION=10000 -DREQUEST_EARLY -DMSC_TEST -o > msc_test msc_test-msc_test.o msc_test-re.o msc_test-re_operators.o > msc_test-re_actions.o msc_test-re_tfns.o msc_test-re_variables.o > msc_test-msc_logging.o msc_test-msc_xml.o msc_test-msc_multipart.o > msc_test-modsecurity.o msc_test-msc_parsers.o msc_test-msc_util.o > msc_test-msc_pcre.o msc_test-msc_unicode.o msc_test-persist_dbm.o > msc_test-msc_reqbody.o msc_test-msc_crypt.o msc_test-msc_tree.o > msc_test-msc_geo.o msc_test-msc_gsb.o msc_test-acmp.o msc_test-msc_lua.o > msc_test-msc_release.o -L/usr/local/apache/lib -laprutil-1 -lexpat > -lapr-1 -L/home/user/tmp/httpd-2.2.22/srclib/pcre > /home/user/tmp/httpd-2.2.22/srclib/pcre/.libs/libpcre.a > -L/usr/local/zlib/lib -L/usr/local/ssl/lib -L/usr/local/libxml/lib > /usr/local/libxml/lib/libxml2.a -L/usr/lib/nls/loc/lib -lz -lpthread > -liconv -lm > > -Wl,-blibpath:/usr/local/apache/lib:/usr/vac/lib:/usr/lib/threads:/usr/lib:/lib > ld: 0711-317 ERROR: Undefined symbol: .strcasestr > > There is a strcasestr replacement implementation in apache2/msc_util.c, > but ModSecurity uses it for Win32 only. configure should probe for > availability of strcasestr(). > > -- > Peter Heimann > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Peter H. <hei...@we...> - 2012-07-26 22:25:04
|
Environment: AIX 5.3, Apache 2.2.22, IBM C compiler AIX 5.3 does not supply a strcasestr() function: libtool: link: cc_r -qlanglvl=extc99 -I/usr/local/apache/include -I/usr/local/apache/include -I/usr/local/apache/include -I/home/user/tmp/httpd-2.2.22/srclib/pcre -I/usr/local/libxml/include/libxml2 -I/usr/lib/nls/loc/include -DWITH_PCRE_STUDY -DMODSEC_PCRE_MATCH_LIMIT=10000 -DMODSEC_PCRE_MATCH_LIMIT_RECURSION=10000 -DREQUEST_EARLY -DMSC_TEST -o msc_test msc_test-msc_test.o msc_test-re.o msc_test-re_operators.o msc_test-re_actions.o msc_test-re_tfns.o msc_test-re_variables.o msc_test-msc_logging.o msc_test-msc_xml.o msc_test-msc_multipart.o msc_test-modsecurity.o msc_test-msc_parsers.o msc_test-msc_util.o msc_test-msc_pcre.o msc_test-msc_unicode.o msc_test-persist_dbm.o msc_test-msc_reqbody.o msc_test-msc_crypt.o msc_test-msc_tree.o msc_test-msc_geo.o msc_test-msc_gsb.o msc_test-acmp.o msc_test-msc_lua.o msc_test-msc_release.o -L/usr/local/apache/lib -laprutil-1 -lexpat -lapr-1 -L/home/user/tmp/httpd-2.2.22/srclib/pcre /home/user/tmp/httpd-2.2.22/srclib/pcre/.libs/libpcre.a -L/usr/local/zlib/lib -L/usr/local/ssl/lib -L/usr/local/libxml/lib /usr/local/libxml/lib/libxml2.a -L/usr/lib/nls/loc/lib -lz -lpthread -liconv -lm -Wl,-blibpath:/usr/local/apache/lib:/usr/vac/lib:/usr/lib/threads:/usr/lib:/lib ld: 0711-317 ERROR: Undefined symbol: .strcasestr There is a strcasestr replacement implementation in apache2/msc_util.c, but ModSecurity uses it for Win32 only. configure should probe for availability of strcasestr(). -- Peter Heimann |
From: seema d. <see...@gm...> - 2012-07-25 06:54:45
|
Hi Breno, I was trying to run the regression tests and"config/10-misc-directives.t:SecWebAppId"was failing sporadically. Whenever it failed, in the server errors log I saw the following msg "Audit log: Failed writing (requested 15 bytes, written 0)" On tracing, I found that during "config/10-misc-directives.t:SecTmpDir/SecUploadDir/SecUploadKeepFiles" test, which was before SecWebAppId test, ModSecurity opened a multipart temp file, wrote some test data and closed it and during cleanup (called during the reconfiguration of the server to pick up the next test configuration) it was again trying to close the same file descriptor which was by then allocated for SecWebAppId test's audit log file. HTH, Seema. On Tue, Jul 24, 2012 at 6:49 PM, Breno Silva <bre...@gm...> wrote: > Thanks Seema i will take a look. > > What kind of effect are you seeing ? any error message ? > > Thanks > > Breno > > On Tue, Jul 24, 2012 at 7:52 AM, seema deepak <see...@gm...>wrote: > >> Hi, >> >> I came across a bug while using ModSecurity 2.6.5 with our server. >> Multipart code tries to close the descriptor more than once; once in >> multipart_process_boundary() and again in multipart_cleanup(). >> >> Below change in multipart_process_boundary() fixed the issue. >> ================================ >> --- modsecurity-apache/apache2/msc_multipart.c Fri Jul 20 06:08:39 2012 >> -0700 >> +++ modsecurity-apache/apache2/msc_multipart.c Fri Jul 20 06:11:42 2012 >> -0700 >> @@ -581,6 +581,7 @@ >> &&(msr->mpd->mpp->tmp_file_fd != 0)) >> { >> close(msr->mpd->mpp->tmp_file_fd); >> + msr->mpd->mpp->tmp_file_fd = -1; >> } >> ================================ >> >> I don't know if this has already been fixed in the latest version. >> >> Thanks and Regards, >> Seema. >> >> ------------------------------------------------------------------------------ >> Live Security Virtual Conference >> Exclusive live event will cover all the ways today's security and >> threat landscape has changed and how IT managers can respond. Discussions >> will include endpoint security, mobile security and the latest in malware >> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ >> _______________________________________________ >> mod-security-developers mailing list >> mod...@li... >> https://lists.sourceforge.net/lists/listinfo/mod-security-developers >> ModSecurity Services from Trustwave's SpiderLabs: >> https://www.trustwave.com/spiderLabs.php >> > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Breno S. <bre...@gm...> - 2012-07-24 13:19:19
|
Thanks Seema i will take a look. What kind of effect are you seeing ? any error message ? Thanks Breno On Tue, Jul 24, 2012 at 7:52 AM, seema deepak <see...@gm...>wrote: > Hi, > > I came across a bug while using ModSecurity 2.6.5 with our server. > Multipart code tries to close the descriptor more than once; once in > multipart_process_boundary() and again in multipart_cleanup(). > > Below change in multipart_process_boundary() fixed the issue. > ================================ > --- modsecurity-apache/apache2/msc_multipart.c Fri Jul 20 06:08:39 2012 > -0700 > +++ modsecurity-apache/apache2/msc_multipart.c Fri Jul 20 06:11:42 2012 > -0700 > @@ -581,6 +581,7 @@ > &&(msr->mpd->mpp->tmp_file_fd != 0)) > { > close(msr->mpd->mpp->tmp_file_fd); > + msr->mpd->mpp->tmp_file_fd = -1; > } > ================================ > > I don't know if this has already been fixed in the latest version. > > Thanks and Regards, > Seema. > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: seema d. <see...@gm...> - 2012-07-24 12:53:05
|
Hi, I came across a bug while using ModSecurity 2.6.5 with our server. Multipart code tries to close the descriptor more than once; once in multipart_process_boundary() and again in multipart_cleanup(). Below change in multipart_process_boundary() fixed the issue. ================================ --- modsecurity-apache/apache2/msc_multipart.c Fri Jul 20 06:08:39 2012 -0700 +++ modsecurity-apache/apache2/msc_multipart.c Fri Jul 20 06:11:42 2012 -0700 @@ -581,6 +581,7 @@ &&(msr->mpd->mpp->tmp_file_fd != 0)) { close(msr->mpd->mpp->tmp_file_fd); + msr->mpd->mpp->tmp_file_fd = -1; } ================================ I don't know if this has already been fixed in the latest version. Thanks and Regards, Seema. |
From: Breno S. P. (JIRA) <no...@mo...> - 2012-07-15 22:05:15
|
[ https://www.modsecurity.org/tracker/browse/MODSEC-319?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Breno Silva Pinto resolved MODSEC-319. -------------------------------------- Resolution: Fixed > Explicity replacement with SecUpdateTargetById > ---------------------------------------------- > > Key: MODSEC-319 > URL: https://www.modsecurity.org/tracker/browse/MODSEC-319 > Project: ModSecurity > Issue Type: Bug > Security Level: Normal > Components: Core > Affects Versions: 2.6.6 > Reporter: Breno Silva Pinto > Assignee: Breno Silva Pinto > Fix For: 2.6.7 > > -- This message is automatically generated by JIRA. For more information on JIRA, see: http://www.atlassian.com/software/jira |
From: Breno S. P. (JIRA) <no...@mo...> - 2012-07-15 21:36:38
|
[ https://www.modsecurity.org/tracker/browse/MODSEC-318?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Breno Silva Pinto resolved MODSEC-318. -------------------------------------- Resolution: Fixed > PCRE version mismatch > --------------------- > > Key: MODSEC-318 > URL: https://www.modsecurity.org/tracker/browse/MODSEC-318 > Project: ModSecurity > Issue Type: Bug > Security Level: Normal > Components: Core > Affects Versions: 2.6.6 > Reporter: Breno Silva Pinto > Assignee: Breno Silva Pinto > Fix For: 2.6.7 > > -- This message is automatically generated by JIRA. For more information on JIRA, see: http://www.atlassian.com/software/jira |
From: Breno S. <bre...@gm...> - 2012-07-03 19:46:26
|
Hello guys. Let me know if anybody here using SecUpdateTargetById and its ctl can test some small fixes i did for 2.6.7. Thanks Breno |
From: Enigma S. <su...@en...> - 2012-06-25 19:14:44
|
yes libxml2 installed not libxml as it is deprecated ????????? On 25 June 2012 20:11, Ryan Barnett <RBa...@tr...> wrote: > > > From: Enigma Support <su...@en...> > Reply-To: "mod...@li..." < > mod...@li...> > Date: Mon, 25 Jun 2012 13:57:02 -0500 > To: "mod...@li..." < > mod...@li...> > Subject: [Mod-security-developers] issue installing 2.6.6 as dso > > I am trying to install modsecurity with the command > /usr/local/apache2/bin/apxs -cia > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c > > > Using apxs directly is the deprecated way of compiling ModSecurity. Use > configure - > > https://sourceforge.net/apps/mediawiki/mod-security/index.php?title=Reference_Manual#Installation_Methods > > -- > Ryan Barnett > Trustwave SpiderLabs > ModSecurity Project Leader > OWASP ModSecurity CRS Project Leader > > > > I get the following error : I checked and the files xpath.h and > xmlschemas.h are on the box in /usr/include/libxml2/libxml/xpath.h > and /usr/include/libxml2/libxml/xmlschemas.h > > sr/local/apache2/build/libtool --silent --mode=compile gcc -prefer-pic > -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -g -O2 -pthread > -I/usr/local/apache2/include -I/usr/local/apache2/include > -I/usr/local/apache2/include -c -o > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.lo > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c && touch > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.slo > In file included from > /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, > from > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: > /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:21:31: error: > libxml/xmlschemas.h: No such file or directory > /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:22:26: error: > libxml/xpath.h: No such file or directory > In file included from > /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, > from > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: > /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:27: error: expected > specifier-qualifier-list before âxmlSAXHandlerâ > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c: In function > âversionâ: > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: > âLIBXML_DOTTED_VERSIONâ undeclared (first use in this function) > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: > (Each undeclared identifier is reported only once > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: for > each function it appears in.) > apxs:Error: Command failed with rc=65536 > > please let me know how to fix this > > > ------------------------------ > This transmission may contain information that is privileged, > confidential, and/or exempt from disclosure under applicable law. If you > are not the intended recipient, you are hereby notified that any > disclosure, copying, distribution, or use of the information contained > herein (including any reliance thereon) is STRICTLY PROHIBITED. If you > received this transmission in error, please immediately contact the sender > and destroy the material in its entirety, whether in electronic or hard > copy format. > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Ryan B. <RBa...@tr...> - 2012-06-25 19:11:28
|
From: Enigma Support <su...@en...<mailto:su...@en...>> Reply-To: "mod...@li...<mailto:mod...@li...>" <mod...@li...<mailto:mod...@li...>> Date: Mon, 25 Jun 2012 13:57:02 -0500 To: "mod...@li...<mailto:mod...@li...>" <mod...@li...<mailto:mod...@li...>> Subject: [Mod-security-developers] issue installing 2.6.6 as dso I am trying to install modsecurity with the command /usr/local/apache2/bin/apxs -cia /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c Using apxs directly is the deprecated way of compiling ModSecurity. Use configure - https://sourceforge.net/apps/mediawiki/mod-security/index.php?title=Reference_Manual#Installation_Methods -- Ryan Barnett Trustwave SpiderLabs ModSecurity Project Leader OWASP ModSecurity CRS Project Leader I get the following error : I checked and the files xpath.h and xmlschemas.h are on the box in /usr/include/libxml2/libxml/xpath.h and /usr/include/libxml2/libxml/xmlschemas.h sr/local/apache2/build/libtool --silent --mode=compile gcc -prefer-pic -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -g -O2 -pthread -I/usr/local/apache2/include -I/usr/local/apache2/include -I/usr/local/apache2/include -c -o /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.lo /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c && touch /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.slo In file included from /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, from /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:21:31: error: libxml/xmlschemas.h: No such file or directory /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:22:26: error: libxml/xpath.h: No such file or directory In file included from /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, from /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:27: error: expected specifier-qualifier-list before âxmlSAXHandlerâ /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c: In function âversionâ: /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: âLIBXML_DOTTED_VERSIONâ undeclared (first use in this function) /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: (Each undeclared identifier is reported only once /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: for each function it appears in.) apxs:Error: Command failed with rc=65536 please let me know how to fix this ________________________________ This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is STRICTLY PROHIBITED. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format. |
From: Josh Amishav-Z. <ja...@gm...> - 2012-06-25 19:09:04
|
On Mon, Jun 25, 2012 at 9:57 PM, Enigma Support <su...@en...> wrote: > I am trying to install modsecurity with the command > /usr/local/apache2/bin/apxs -cia > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c > > > I get the following error : I checked and the files xpath.h and > xmlschemas.h are on the box in /usr/include/libxml2/libxml/xpath.h > and /usr/include/libxml2/libxml/xmlschemas.h > > sr/local/apache2/build/libtool --silent --mode=compile gcc -prefer-pic > -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -g -O2 -pthread > -I/usr/local/apache2/include -I/usr/local/apache2/include > -I/usr/local/apache2/include -c -o > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.lo > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c && touch > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.slo > In file included from > /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, > from > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: > /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:21:31: error: > libxml/xmlschemas.h: No such file or directory > /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:22:26: error: > libxml/xpath.h: No such file or directory > Hi, Do you have LibXML installed? -- - Josh > In file included from > /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, > from > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: > /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:27: error: expected > specifier-qualifier-list before âxmlSAXHandlerâ > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c: In function > âversionâ: > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: > âLIBXML_DOTTED_VERSIONâ undeclared (first use in this function) > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: > (Each undeclared identifier is reported only once > /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: for > each function it appears in.) > apxs:Error: Command failed with rc=65536 > > please let me know how to fix this > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Enigma S. <su...@en...> - 2012-06-25 18:57:09
|
I am trying to install modsecurity with the command /usr/local/apache2/bin/apxs -cia /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c I get the following error : I checked and the files xpath.h and xmlschemas.h are on the box in /usr/include/libxml2/libxml/xpath.h and /usr/include/libxml2/libxml/xmlschemas.h sr/local/apache2/build/libtool --silent --mode=compile gcc -prefer-pic -DLINUX=2 -D_REENTRANT -D_GNU_SOURCE -g -O2 -pthread -I/usr/local/apache2/include -I/usr/local/apache2/include -I/usr/local/apache2/include -c -o /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.lo /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c && touch /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.slo In file included from /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, from /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:21:31: error: libxml/xmlschemas.h: No such file or directory /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:22:26: error: libxml/xpath.h: No such file or directory In file included from /Binaries/modsecurity-apache_2.6.6/apache2/modsecurity.h:38, from /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:20: /Binaries/modsecurity-apache_2.6.6/apache2/msc_xml.h:27: error: expected specifier-qualifier-list before âxmlSAXHandlerâ /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c: In function âversionâ: /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: âLIBXML_DOTTED_VERSIONâ undeclared (first use in this function) /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: (Each undeclared identifier is reported only once /Binaries/modsecurity-apache_2.6.6/apache2/mod_security2.c:104: error: for each function it appears in.) apxs:Error: Command failed with rc=65536 please let me know how to fix this |
From: Diego E. P. <fla...@gm...> - 2012-06-24 16:14:11
|
Il 14/06/2012 23:39, Breno Silva ha scritto: > FYI, i'm planning to write some blog post next week about some new 2.7.0 > new features. In the mean time thanks for the httpBL implementation :D -- Diego Elio Pettenò — Flameeyes fla...@fl... — http://blog.flameeyes.eu/ |
From: Breno S. <bre...@gm...> - 2012-06-22 14:26:13
|
The ModSecurity Development Team is pleased to announce the availability of ModSecurity 2.7.0-RC2 Release Candidate. This version includes small bug fixes specially under Windows platform. I want to thank Steffen (ApacheLounge) for that. Please see the release notes included into CHANGES<http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES>file. For known problems and more information about bug fixes, please see the online ModSecurity Jira <https://www.modsecurity.org/tracker/>. Please report any bug to mod...@li...<http://lists.sourceforge.net/lists/listinfo/mod-security-developers> . I'd like to ask community help specially to test the build under Solaris and AIX. A feedback is very appreciated. Thanks Breno Silva |
From: Breno S. P. (JIRA) <no...@mo...> - 2012-06-16 17:23:21
|
[ https://www.modsecurity.org/tracker/browse/MODSEC-242?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Breno Silva Pinto resolved MODSEC-242. -------------------------------------- Resolution: Incomplete Closing this as it is old and we don't have a confirmation if the problem is into latest modsecurity version > mlogc skips some entries > ------------------------ > > Key: MODSEC-242 > URL: https://www.modsecurity.org/tracker/browse/MODSEC-242 > Project: ModSecurity > Issue Type: Bug > Security Level: Normal > Affects Versions: 2.5.13 > Environment: Linux > Reporter: Jonathan Marcil > Assignee: Breno Silva Pinto > > I'm using mlogc-batch-load.pl and I'm not sure if this bug is mlogc, modsecurity or the perl script. > In my mlogc-error.log I get this error : > [Thu Apr 28 17:15:05 2011] [2] [587/80d6890] Invalid entry (failed to match regex): host 123.123.123.123 - - [21/Apr/2011:08:48:38 --0400] \"GET /\" - - \"-\" \"-\" TbAnpgoUAN4AAB0HXxcAAAAk \"-\" /20110421/20110421-0848/20110421-084838-TbAnpgoUAN4AAB0HXxcAAAAk 0 302 md5:14a030fec980272ed579d34c1fc330fb > And if if check the content of the file I have : > --4d3b0120-A--[21/Apr/2011:06:37:27 --0400] TbAI5woUAN4AAB-X8X0AAAAh 123.123.123.123 53503 123.123.123.124 443 --4d3b0120-B-- GET / --4d3b0120-F-- --4d3b0120-H-- Stopwatch: 1303382247803705 349 (- - -) Producer: ModSecurity for Apache/2.5.13 (http://www.modsecurity.org/). Server: Apache --4d3b0120-Z-- > Notice that the F part is empty and the B part only contains "GET /". > Current workaround : In mlogc-batch-load.pl I just change the default response_status to "400" and bytes_sent to "0" instead of "-" (around line 69). -- This message is automatically generated by JIRA. For more information on JIRA, see: http://www.atlassian.com/software/jira |
From: Breno S. <bre...@gm...> - 2012-06-14 21:39:31
|
FYI, i'm planning to write some blog post next week about some new 2.7.0 new features. Stay tuned : http://blog.spiderlabs.com/ Thanks Breno On Thu, Jun 14, 2012 at 4:23 PM, Breno Silva <bre...@gm...> wrote: > The ModSecurity Development Team is pleased to announce the availability > of ModSecurity 2.7.0-RC1 Release Candidate. > This version includes many security enhancements including the ability to > add cryptographic hash validation tokens to outbound data to prevent > parameter tampering. > The release also includes many performance enhancements to the Lua API and > PCRE code. > Please see the release notes included into CHANGES<http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES>file. > For known problems and more information about bug fixes, please see the > online ModSecurity Jira <https://www.modsecurity.org/tracker/>. Please > report any bug to mod...@li...<http://lists.sourceforge.net/lists/listinfo/mod-security-developers> > . > > Thanks > > Breno Silva > |
From: Breno S. <bre...@gm...> - 2012-06-14 21:23:55
|
The ModSecurity Development Team is pleased to announce the availability of ModSecurity 2.7.0-RC1 Release Candidate. This version includes many security enhancements including the ability to add cryptographic hash validation tokens to outbound data to prevent parameter tampering. The release also includes many performance enhancements to the Lua API and PCRE code. Please see the release notes included into CHANGES<http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES>file. For known problems and more information about bug fixes, please see the online ModSecurity Jira <https://www.modsecurity.org/tracker/>. Please report any bug to mod...@li...<http://lists.sourceforge.net/lists/listinfo/mod-security-developers> . Thanks Breno Silva |
From: Breno S. <bre...@gm...> - 2012-06-14 21:23:39
|
The ModSecurity Development Team has released version 2.6.6 in response to a multipart bypass vulnerability that was disclosed to us. Users are strongly encouraged to update. Please see the release notes included into CHANGES<http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.6.x/CHANGES>file. For known problems and more information about bug fixes, please see the online ModSecurity Jira <https://www.modsecurity.org/tracker/>. Please report any bug to mod...@li...<http://lists.sourceforge.net/lists/listinfo/mod-security-developers> . Thanks Breno Silva |
From: Breno S. <bre...@gm...> - 2012-06-05 17:04:52
|
Done. Thanks On Tue, Jun 5, 2012 at 10:15 AM, Alberto Gonzalez Iniesta <ag...@in...>wrote: > Hi Breno, > > Right. Just that in configure.ac > > Thanks, > > Alberto > > On Tue, Jun 05, 2012 at 10:07:43AM -0500, Breno Silva wrote: > > Hi Alberto, > > > > The has many unnecessary information making it difficult to read. > > As i understood looks like we just need to include: > > > > *-*-kfreebsd*) > > echo "Checking plataform... Identified as kFreeBSD, treating as > linux" > > linuxos=true > > ;; > > *-*-gnu*.*) > > echo "Checking plataform... Identified as HURD, treating as linux" > > linuxos=true > > ;; > > > > right ? > > > > Thanks > > > > Breno > > > > On Tue, Jun 5, 2012 at 9:18 AM, Alberto Gonzalez Iniesta < > ag...@in...>wrote: > > > > > Hi, > > > > > > A couple of months ago a bug was reported in the Debian BTS [1] on the > > > failure to build mod-security on non-Linux Debian systems (kfreebsd and > > > hurd). The patch included in the bug report has been successfully > tested > > > now and I'd like you (mod-security developers) to consider it (actually > > > just the configure.ac should be enough) for inclusion. > > > > > > Thanks, > > > > > > Alberto > > > > > > > > > [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654719 > > > -- > > > Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico > > > agi@(inittab.org|debian.org)| en GNU/Linux y software libre > > > Encrypted mail preferred | http://inittab.com > > > > > > Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 > > > > > > > > > > ------------------------------------------------------------------------------ > > > Live Security Virtual Conference > > > Exclusive live event will cover all the ways today's security and > > > threat landscape has changed and how IT managers can respond. > Discussions > > > will include endpoint security, mobile security and the latest in > malware > > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > _______________________________________________ > > > mod-security-developers mailing list > > > mod...@li... > > > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > > > ModSecurity Services from Trustwave's SpiderLabs: > > > https://www.trustwave.com/spiderLabs.php > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. Discussions > > will include endpoint security, mobile security and the latest in malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > _______________________________________________ > > mod-security-developers mailing list > > mod...@li... > > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > > ModSecurity Services from Trustwave's SpiderLabs: > > https://www.trustwave.com/spiderLabs.php > > > -- > Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico > agi@(inittab.org|debian.org)| en GNU/Linux y software libre > Encrypted mail preferred | http://inittab.com > > Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Alberto G. I. <ag...@in...> - 2012-06-05 15:15:19
|
Hi Breno, Right. Just that in configure.ac Thanks, Alberto On Tue, Jun 05, 2012 at 10:07:43AM -0500, Breno Silva wrote: > Hi Alberto, > > The has many unnecessary information making it difficult to read. > As i understood looks like we just need to include: > > *-*-kfreebsd*) > echo "Checking plataform... Identified as kFreeBSD, treating as linux" > linuxos=true > ;; > *-*-gnu*.*) > echo "Checking plataform... Identified as HURD, treating as linux" > linuxos=true > ;; > > right ? > > Thanks > > Breno > > On Tue, Jun 5, 2012 at 9:18 AM, Alberto Gonzalez Iniesta <ag...@in...>wrote: > > > Hi, > > > > A couple of months ago a bug was reported in the Debian BTS [1] on the > > failure to build mod-security on non-Linux Debian systems (kfreebsd and > > hurd). The patch included in the bug report has been successfully tested > > now and I'd like you (mod-security developers) to consider it (actually > > just the configure.ac should be enough) for inclusion. > > > > Thanks, > > > > Alberto > > > > > > [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654719 > > -- > > Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico > > agi@(inittab.org|debian.org)| en GNU/Linux y software libre > > Encrypted mail preferred | http://inittab.com > > > > Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. Discussions > > will include endpoint security, mobile security and the latest in malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > _______________________________________________ > > mod-security-developers mailing list > > mod...@li... > > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > > ModSecurity Services from Trustwave's SpiderLabs: > > https://www.trustwave.com/spiderLabs.php > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php -- Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred | http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 |
From: Breno S. <bre...@gm...> - 2012-06-05 15:07:51
|
Hi Alberto, The has many unnecessary information making it difficult to read. As i understood looks like we just need to include: *-*-kfreebsd*) echo "Checking plataform... Identified as kFreeBSD, treating as linux" linuxos=true ;; *-*-gnu*.*) echo "Checking plataform... Identified as HURD, treating as linux" linuxos=true ;; right ? Thanks Breno On Tue, Jun 5, 2012 at 9:18 AM, Alberto Gonzalez Iniesta <ag...@in...>wrote: > Hi, > > A couple of months ago a bug was reported in the Debian BTS [1] on the > failure to build mod-security on non-Linux Debian systems (kfreebsd and > hurd). The patch included in the bug report has been successfully tested > now and I'd like you (mod-security developers) to consider it (actually > just the configure.ac should be enough) for inclusion. > > Thanks, > > Alberto > > > [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654719 > -- > Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico > agi@(inittab.org|debian.org)| en GNU/Linux y software libre > Encrypted mail preferred | http://inittab.com > > Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > mod-security-developers mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-developers > ModSecurity Services from Trustwave's SpiderLabs: > https://www.trustwave.com/spiderLabs.php > |
From: Alberto G. I. <ag...@in...> - 2012-06-05 14:57:40
|
Hi, A couple of months ago a bug was reported in the Debian BTS [1] on the failure to build mod-security on non-Linux Debian systems (kfreebsd and hurd). The patch included in the bug report has been successfully tested now and I'd like you (mod-security developers) to consider it (actually just the configure.ac should be enough) for inclusion. Thanks, Alberto [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=654719 -- Alberto Gonzalez Iniesta | Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre Encrypted mail preferred | http://inittab.com Key fingerprint = 9782 04E7 2B75 405C F5E9 0C81 C514 AF8E 4BA4 01C3 |