mod-security-users Mailing List for ModSecurity (Page 559)
Brought to you by:
victorhora,
zimmerletw
You can subscribe to this list here.
| 2003 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(17) |
Aug
(7) |
Sep
(8) |
Oct
(11) |
Nov
(14) |
Dec
(19) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2004 |
Jan
(46) |
Feb
(14) |
Mar
(20) |
Apr
(48) |
May
(15) |
Jun
(20) |
Jul
(36) |
Aug
(24) |
Sep
(31) |
Oct
(28) |
Nov
(23) |
Dec
(12) |
| 2005 |
Jan
(69) |
Feb
(61) |
Mar
(82) |
Apr
(53) |
May
(26) |
Jun
(71) |
Jul
(27) |
Aug
(52) |
Sep
(28) |
Oct
(49) |
Nov
(104) |
Dec
(74) |
| 2006 |
Jan
(61) |
Feb
(148) |
Mar
(82) |
Apr
(139) |
May
(65) |
Jun
(116) |
Jul
(92) |
Aug
(101) |
Sep
(84) |
Oct
(103) |
Nov
(174) |
Dec
(102) |
| 2007 |
Jan
(166) |
Feb
(161) |
Mar
(181) |
Apr
(152) |
May
(192) |
Jun
(250) |
Jul
(127) |
Aug
(165) |
Sep
(97) |
Oct
(135) |
Nov
(206) |
Dec
(56) |
| 2008 |
Jan
(160) |
Feb
(135) |
Mar
(98) |
Apr
(89) |
May
(115) |
Jun
(95) |
Jul
(188) |
Aug
(167) |
Sep
(153) |
Oct
(84) |
Nov
(82) |
Dec
(85) |
| 2009 |
Jan
(139) |
Feb
(133) |
Mar
(128) |
Apr
(105) |
May
(135) |
Jun
(79) |
Jul
(92) |
Aug
(134) |
Sep
(73) |
Oct
(112) |
Nov
(159) |
Dec
(80) |
| 2010 |
Jan
(100) |
Feb
(116) |
Mar
(130) |
Apr
(59) |
May
(88) |
Jun
(59) |
Jul
(69) |
Aug
(67) |
Sep
(82) |
Oct
(76) |
Nov
(59) |
Dec
(34) |
| 2011 |
Jan
(84) |
Feb
(74) |
Mar
(81) |
Apr
(94) |
May
(188) |
Jun
(72) |
Jul
(118) |
Aug
(109) |
Sep
(111) |
Oct
(80) |
Nov
(51) |
Dec
(44) |
| 2012 |
Jan
(80) |
Feb
(123) |
Mar
(46) |
Apr
(12) |
May
(40) |
Jun
(62) |
Jul
(95) |
Aug
(66) |
Sep
(65) |
Oct
(53) |
Nov
(42) |
Dec
(60) |
| 2013 |
Jan
(96) |
Feb
(96) |
Mar
(108) |
Apr
(72) |
May
(115) |
Jun
(111) |
Jul
(114) |
Aug
(87) |
Sep
(93) |
Oct
(97) |
Nov
(104) |
Dec
(82) |
| 2014 |
Jan
(96) |
Feb
(77) |
Mar
(71) |
Apr
(40) |
May
(48) |
Jun
(78) |
Jul
(54) |
Aug
(44) |
Sep
(58) |
Oct
(79) |
Nov
(51) |
Dec
(52) |
| 2015 |
Jan
(55) |
Feb
(59) |
Mar
(48) |
Apr
(40) |
May
(45) |
Jun
(63) |
Jul
(36) |
Aug
(49) |
Sep
(35) |
Oct
(58) |
Nov
(21) |
Dec
(47) |
| 2016 |
Jan
(35) |
Feb
(81) |
Mar
(43) |
Apr
(41) |
May
(77) |
Jun
(52) |
Jul
(39) |
Aug
(34) |
Sep
(107) |
Oct
(67) |
Nov
(54) |
Dec
(20) |
| 2017 |
Jan
(99) |
Feb
(37) |
Mar
(86) |
Apr
(47) |
May
(57) |
Jun
(55) |
Jul
(34) |
Aug
(31) |
Sep
(16) |
Oct
(49) |
Nov
(53) |
Dec
(33) |
| 2018 |
Jan
(25) |
Feb
(11) |
Mar
(79) |
Apr
(77) |
May
(5) |
Jun
(19) |
Jul
(17) |
Aug
(7) |
Sep
(13) |
Oct
(22) |
Nov
(13) |
Dec
(68) |
| 2019 |
Jan
(44) |
Feb
(17) |
Mar
(40) |
Apr
(39) |
May
(18) |
Jun
(14) |
Jul
(20) |
Aug
(31) |
Sep
(11) |
Oct
(35) |
Nov
(3) |
Dec
(10) |
| 2020 |
Jan
(32) |
Feb
(16) |
Mar
(10) |
Apr
(22) |
May
(2) |
Jun
(34) |
Jul
(1) |
Aug
(8) |
Sep
(36) |
Oct
(16) |
Nov
(13) |
Dec
(10) |
| 2021 |
Jan
(16) |
Feb
(23) |
Mar
(45) |
Apr
(28) |
May
(6) |
Jun
(17) |
Jul
(8) |
Aug
(1) |
Sep
(2) |
Oct
(35) |
Nov
|
Dec
(5) |
| 2022 |
Jan
|
Feb
(17) |
Mar
(23) |
Apr
(23) |
May
(9) |
Jun
(8) |
Jul
|
Aug
|
Sep
(7) |
Oct
(5) |
Nov
(16) |
Dec
(4) |
| 2023 |
Jan
|
Feb
|
Mar
(3) |
Apr
|
May
(1) |
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(2) |
Oct
(1) |
Nov
|
Dec
|
| 2024 |
Jan
(7) |
Feb
(13) |
Mar
(18) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(2) |
Oct
(1) |
Nov
(5) |
Dec
(3) |
| 2025 |
Jan
|
Feb
|
Mar
|
Apr
(12) |
May
(12) |
Jun
(2) |
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Ivan R. <iv...@we...> - 2005-06-17 07:43:04
|
m0nkey wrote: > I've installed mini_sendmail and dropped it in my jail: > > /var/chroot/apache/usr/sbin/mini_sendmail > > I then changed the sendmail_path in /etc/php/apache2-php4/php.ini to either: > /var/chroot/apache/usr/sbin/mini_sendmail > or > /usr/sbin/mini_sendmail > > I get the exact same result.. which is no mail.. no error. Just to > clarify, I restart the service with every change. > > I also noticed in your box (Apache Security p.47).. that you mention > adding SMTP=localhost for this case.. I also have that set with no luck. Unfortunatelly that's an error, which I failed to spot in time to correct. Delivery through SMTP only works on Windows (and Netware I think). > Any ideas how to get this working is greatly appreciated. Use strace to figure out what PHP wants to do. My guess is that it tries to execute sendmail through a shell, so you'll probably need /bin/sh there as well. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: m0nkey <poo...@wa...> - 2005-06-17 04:45:53
|
I've installed mini_sendmail and dropped it in my jail: /var/chroot/apache/usr/sbin/mini_sendmail I then changed the sendmail_path in /etc/php/apache2-php4/php.ini to either: /var/chroot/apache/usr/sbin/mini_sendmail or /usr/sbin/mini_sendmail I get the exact same result.. which is no mail.. no error. Just to clarify, I restart the service with every change. I also noticed in your box (Apache Security p.47).. that you mention adding SMTP=localhost for this case.. I also have that set with no luck. Any ideas how to get this working is greatly appreciated. Thanks pb > m0nkey wrote: >> Hello All >> >> I have a server using mod_security with chroot enabled. I have php/mysql >> working fine.. except for one piece. the mail function. Anyone know how >> to >> get >> around this? When this fails.. nothing is written to messages or >> error_log. >> Removing chroot option, mail() works again. > > The problem is not related to mod_security. PHP uses sendmail to > send email on Unix. Since there is no sendmail in jail the mail() > function does not work. It's somewhat ironic that PHP knows how > to send email SMTP but only when it's running on Windows. > > My suggestion is to install mini_sendmail: > http://www.acme.com/software/mini_sendmail/ > > (Installing sendmail would also work but that would defy the whole > point of having chroot in the first place.) > > >> Current versions of packages I'm running: >> >> mod_security-1.8.6 > > Why not upgrade to 1.8.7? Have a look at the list of things > fixed: > > http://www.modsecurity.org/documentation/known-issues.html > > -- > Ivan Ristic > Apache Security (O'Reilly) - http://www.apachesecurity.net > Open source web application firewall - http://www.modsecurity.org > > ______________________________________ Get your FREE 100MB email today at http://www.wapda.com |
|
From: Ivan R. <iv...@we...> - 2005-06-16 21:50:56
|
m0nkey wrote: > Hello All > > I have a server using mod_security with chroot enabled. I have php/mysql > working fine.. except for one piece. the mail function. Anyone know how to > get > around this? When this fails.. nothing is written to messages or error_log. > Removing chroot option, mail() works again. The problem is not related to mod_security. PHP uses sendmail to send email on Unix. Since there is no sendmail in jail the mail() function does not work. It's somewhat ironic that PHP knows how to send email SMTP but only when it's running on Windows. My suggestion is to install mini_sendmail: http://www.acme.com/software/mini_sendmail/ (Installing sendmail would also work but that would defy the whole point of having chroot in the first place.) > Current versions of packages I'm running: > > mod_security-1.8.6 Why not upgrade to 1.8.7? Have a look at the list of things fixed: http://www.modsecurity.org/documentation/known-issues.html -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: m0nkey <poo...@wa...> - 2005-06-16 21:37:51
|
Hello All I have a server using mod_security with chroot enabled. I have php/mysql working fine.. except for one piece. the mail function. Anyone know how to get around this? When this fails.. nothing is written to messages or error_log. Removing chroot option, mail() works again. Any help is greatly appreciated. Current versions of packages I'm running: mod_security-1.8.6 apache-2.0.54-r7 mod_php-4.3.11 Thanks pb ______________________________________ Get your FREE 100MB email today at http://www.wapda.com |
|
From: Basavaraj, U. <uma...@ci...> - 2005-06-16 16:30:47
|
Thank you I got it -----Original Message----- From: Eli [mailto:eli...@ex...] Sent: Thursday, June 16, 2005 11:28 AM To: 'Ivan Ristic'; Basavaraj, Umakanth Cc: mod...@li... Subject: RE: [mod-security-users] Where can i get mod_security.dll Ivan wrote: > I think you've done the right thing, but if you can't find nmake in > the installation that probably means Microsoft are not giving it = away > with the free version of the compiler. I seem to have a copy of nmake that apparently is included with ActiveState's Perl installation. If you download ActiveState Perl = (free), in the bin folder is nmake.exe and nmake.err which I assume are all you = need for nmake? I haven't done a compile test though :) Eli. |
|
From: Eli <eli...@ex...> - 2005-06-16 15:29:16
|
Ivan wrote: > I think you've done the right thing, but if you can't find nmake in > the installation that probably means Microsoft are not giving it = away > with the free version of the compiler. I seem to have a copy of nmake that apparently is included with ActiveState's Perl installation. If you download ActiveState Perl = (free), in the bin folder is nmake.exe and nmake.err which I assume are all you = need for nmake? I haven't done a compile test though :) Eli. |
|
From: Ivan R. <iv...@we...> - 2005-06-15 17:17:38
|
Basavaraj, Umakanth wrote: > I am new to all this could you help me out here is what I did > > Installed VC++ toolkit, Intalled apache 1.3.3 for windows on my local machine > > tried to call nmake and it says unrecongized command, Am I doing anything wrong? > > I did look for nmake file on my machine and none exists. I think you've done the right thing, but if you can't find nmake in the installation that probably means Microsoft are not giving it away with the free version of the compiler. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Ivan R. <iv...@we...> - 2005-06-15 15:51:52
|
Terry Dooher wrote:
>
> Just an aside about the above filters: I'm using a similar model to
> protect a a small service that talks to a custom application. Only POST,
> only one arg (m) and the parameter must at least _look_ like an md5
> hash. My method uses just one regexp on the payload:
>
> SecFilterSelective REQUEST_METHOD "!^(POST)$
> SecFilterSelective POST_PAYLOAD "!^m=[0-9a-f]{32}$"
>
> This works, but am I losing something important by using this one regexp
> instead of specific references to ARGS_NAMES and ARG_m?
No, you're fine.
--
Ivan Ristic
Apache Security (O'Reilly) - http://www.apachesecurity.net
Open source web application firewall - http://www.modsecurity.org
|
|
From: Terry D. <tdo...@na...> - 2005-06-15 14:57:30
|
Ivan Ristic wrote:
>
>
> <Location /user_view.php>
> # This script only accepts GET
> SecFilterSelective REQUEST_METHOD !^GET$
> # Accept only one parameter: id
> SecFilterSelective ARGS_NAMES !^id$
> # Parameter id is mandatory, and it must be
> # a number, 4-14 digits long
> SecFilterSelective ARG_id !^[[:digit:]]{4,14}$
> </Location>
Just an aside about the above filters: I'm using a similar model to protect a
a small service that talks to a custom application. Only POST, only one arg
(m) and the parameter must at least _look_ like an md5 hash. My method uses
just one regexp on the payload:
SecFilterSelective REQUEST_METHOD "!^(POST)$
SecFilterSelective POST_PAYLOAD "!^m=[0-9a-f]{32}$"
This works, but am I losing something important by using this one regexp
instead of specific references to ARGS_NAMES and ARG_m?
Cheers,
Terry.
|
|
From: Ivan R. <iv...@we...> - 2005-06-15 13:19:20
|
Basavaraj, Umakanth wrote: > Can we skip step 2 in your process and have a compiler installed on local machine > and unzip the source and do the nmake I am not sure I follow. You don't have to have a compiler on the server. Compiling on a local machine is fine. You can then copy the DLL wherever you need it. But you can't skip step two. To compile you'll need the header files that come with Apache. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Ivan R. <iv...@we...> - 2005-06-15 13:17:08
|
David ROBERT wrote:
> Hi,
>
> I'm interested in mod_security concept. I would like to use a positive security model.
> I've heard about mod_eaccess and mod_parmguard for this model (anyone has experience with this two modules ?).
This is a provocation, right?
(I am just kidding :)
I've never used either in production. I did inspect the source code of
mod_parmguard when I was researching this module for my book and I
wasn't convinced it would work in production. (I informed the author
about my findings.)
mod_security can be used for a positive security model as well. For
example:
<Location /user_view.php>
# This script only accepts GET
SecFilterSelective REQUEST_METHOD !^GET$
# Accept only one parameter: id
SecFilterSelective ARGS_NAMES !^id$
# Parameter id is mandatory, and it must be
# a number, 4-14 digits long
SecFilterSelective ARG_id !^[[:digit:]]{4,14}$
</Location>
<Location /user_add.php>
# This script only accepts POST
SecFilterSelective REQUEST_METHOD !^POST$
# Accept three parameters: firstname, lastname, and email
SecFilterSelective ARGS_NAMES !^(firstname|lastname|email)$
# Parameter firstname is mandatory, and it must
# contain text 1-64 characters long
SecFilterSelective ARG_firstname !^[[:alnum:][:space:]]{1,64}$
# Parameter lastname is mandatory, and it must
# contain text 1-64 characters long
SecFilterSelective ARG_lastname !^[ [:alnum:][:space:]]{1,64}$
# Parameter email is optional, but if it is present
# it must consist only of characters that are
# allowed in an email address
SecFilterSelective ARG_email !(^$|^[[:alnum:].@]{1,64}$)
</Location>
If the product you want to protect is not changing much then you may
be able to write a set of rules once and use them for ever. But it is
very difficult to maintain a set of positive security rules for
a changing product. Some sort of real-time engine is needed to make
this task easier.
--
Ivan Ristic
Apache Security (O'Reilly) - http://www.apachesecurity.net
Open source web application firewall - http://www.modsecurity.org
|
|
From: David R. <da...@om...> - 2005-06-15 12:54:08
|
Hi, I'm interested in mod_security concept. I would like to use a positive security model. I've heard about mod_eaccess and mod_parmguard for this model (anyone has experience with this two modules ?). I don't find a lot of information about using mod_security denied all by default. It look's like it can be done, but I'd like to have user experience return ? Anyone here use mod_security with positive security ? -- David ROBERT http://www.ombrepixel.com/drobert/ |
|
From: K V. <kva...@se...> - 2005-06-14 23:25:55
|
Thai Duong <thaidn <at> gmail.com> writes: > > Hi guys, > When I chroot my Apache 1.3.x with mod_security, it kept reporting that > error. I have searched through this list and found that this error had > been reported one but still there is no solution rite? > It seems that this problem only occurs in Apache 1.3, I have > sucessfully chroot Apache 2.0 with mod_ssl without any problem before. > Here is my modsec.conf which is included at the end of httpd.conf > -----------snip------------- > # Yes, we want to use mod_security > ClearModuleList > AddModule mod_security.c > AddModule ... > SecFilterEngine On > > SecServerSignature "Microsoft IIS/5.0" > > SecChrootDir /chroot/jail > ---snip------------ > Any suggestion? > TIA, > -T Our local guru solved this by creating a symbolic link in the chroot jail directory, to itself, called the same (magic, don't ask me). So, chroot jail directory is /XXX, so we cd /XXX ln -s . XXX It works. |
|
From: Ivan R. <iv...@we...> - 2005-06-14 21:16:45
|
Basavaraj, Umakanth wrote: > I do not have a compiler, is there a website where I can get one and are there any steps > listed on the net to do this installation. I've used Visual Studio in the past. There is a free compiler from Microsoft available here: http://msdn.microsoft.com/visualc/vctoolkit2003/ But I never tried it. To compile mod_security on Windows you need to: 1) Have a compiler installed 2) Install the Apache branch you want to compile for (just the binary version, the source code is not necessary). Make sure you use the default path. (If you change the installation path you will need to edit the file makefile.win, see below.) 3) Unpack the mod_security source code, open the command prompt, go to the folder where the source code is and type: nmake -f makefile.win That's it. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: <bu...@cg...> - 2005-06-14 18:10:23
|
I have published a book review for "Apache Security" By O'Reilly that may be of interest to the list. "This book was written by Ivan Ristic, the author of the popular Apache web application firewall module mod_security. Naturally this book does discuss how to use mod_security to harden your system, but I'm happy to report it isn't his main area of focus. One of the first things that I do while reviewing a book is to find all the things that the text doesn't cover that it *really* should have and point them out in my review. Simply put this book has everything, and I do mean everything. H ere's the low down on a per chapter basis." http://www.cgisecurity.com/articles/apachesecurity.shtml - ad...@cg... |
|
From: Ivan R. <iv...@we...> - 2005-06-14 18:07:42
|
Basavaraj, Umakanth wrote: > Nowhere, as far I know. Guenter used to have a version at http://www.gknw.com/development/apache/httpd-2.0/ but I can't access his web site right now. If you have a compiler it's trivial to compile. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Ivan R. <iv...@we...> - 2005-06-14 18:05:40
|
Thai Duong wrote: > Hi guys, > > When I turned SecFilterScanPOST on and tried to send an email with > SquirrelMail, mod-sec reported that error. Just that? What is the exact error message you get? Make a test with debug logging enabled on level 9 - there may be additional messages in the debug log. However, fatal errors are all logged to the Apache error log. > As fas as I know, this error > occured due to the fact that SquirrelMail (and many other webmail apps) > compose-form has "multipart/form-data" as request encoding even if you > dont attach files with your email. When mod-sec sees > "multipart/form-data", it expects to see the long POST_PAYLOAD > containing the attachments, and ends up with that error when there is no > attachment. No, that's not the problem. It's something else. Are you using a recent version of mod_security? I suspect file permissions, but you should find out for sure from the debug log. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Christian M. <cma...@is...> - 2005-06-14 16:49:40
|
> Hi Christian, > > Sorry for not responding earlier - I've been swamped with work. > > I think it's very functional. Let me know when you have something > others can download and use, and I'll post it on the home page. > Hi all, I will send the first version during this week, im polishing some=20 details. :) Cheers --=20 _________________________________ Christian Martorella e-Security Engineer cma...@is... Internet Security Auditors, S.L. c. Santander, 101. Edif. A. 2=BA 1=AA. 08030 Barcelona Tel: 93 305 13 18 Fax: 93 278 22 48 www.isecauditors.com ____________________________________ Este mensaje y los documentos que, en su caso lleve anexos, pueden contener informaci=F3n confidencial. Por ello, se informa a quien lo reciba por error que la informaci=F3n contenida en el mismo es reservada y su uso no autorizado est=E1 prohibido legalmente, por lo que en tal caso le rogamos que nos lo comunique por la misma v=EDa o por tel=E9fono (93 305 13 18), se abstenga de realizar copias del mensaje o remitirlo o entregarlo a otra persona y proceda a borrarlo de inmediato. En cumplimiento de la Ley Org=E1nica 15/1999 de 13 de diciembre de protecci=F3n de datos de car=E1cter personal, Internet Security Auditors S.L., le informa de que sus datos personales se han incluido en ficheros informatizados titularidad de Internet Security Auditors S.L., que ser=E1 el =FAnico destinatario de dichos datos, y cuya finalida= d exclusiva es la gesti=F3n de clientes y acciones de comunicaci=F3n comercial, y de que tiene la posibilidad de ejercer los derechos de acceso, rectificaci=F3n, cancelaci=F3n y oposici=F3n previstos en la ley mediante carta dirigida a Internet Security Auditors, c. Santander, 101. Edif. A. 2=BA 1=AA, 08030 Barcelona, o v=EDa e-mail a la siguiente direcci=F3n de correo: le...@is... |
|
From: Thai D. <th...@gm...> - 2005-06-14 16:34:25
|
Hi guys, When I turned SecFilterScanPOST on and tried to send an email with=20 SquirrelMail, mod-sec reported that error. As fas as I know, this error=20 occured due to the fact that SquirrelMail (and many other webmail apps)=20 compose-form has "multipart/form-data" as request encoding even if you dont= =20 attach files with your email. When mod-sec sees "multipart/form-data", it= =20 expects to see the long POST_PAYLOAD containing the attachments, and ends u= p=20 with that error when there is no attachment. The quick solution is...to tur= n=20 SecFilterScanPOST off :). How about a real solution? Any suggestion?=20 Regards, Thai Duong. |
|
From: Basavaraj, U. <uma...@ci...> - 2005-06-14 14:26:12
|
|
From: Ivan R. <iv...@we...> - 2005-06-09 21:59:38
|
Christian Martorella wrote: > Hi all, i saw Modseclogwatch ,and i thought it was ok, but i wanted > something more like > ACID or BASE, so I used the code of Evert Daman as a base for a console > like those. > I did some work this weekend here is a demo: > > http://laramies.no-ip.org/mod_sec_test/ > > My Todo list have: > > -A Search form > -A delete field in the table > -Some graphics bars/pies with GD > -Configuration screen for the install/setup > -Multiple language version > -Use css for everything > -Beautify some outputs > -Session control > > I will work in the frontend and Evert will keep working on the parser > > The code will be available as soon as i finish the first version, and Evert > correct a problem with the parsing of some headers. > > Tell me what you think.. Hi Christian, Sorry for not responding earlier - I've been swamped with work. I think it's very functional. Let me know when you have something others can download and use, and I'll post it on the home page. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Ivan R. <iv...@we...> - 2005-06-06 15:47:47
|
Yair wrote: > Hi! > > I'm using FC2 (apache 1.3) with mod_security, I wanted to ask if there > is a way to "block" words via mod_security. Yes, there is. You'll find more information in the manual. Also, you can look at the example rules distributed with mod_security, the converted Snort rules, or the rules available elsewhere: http://www.gotroot.com/mod_security+rules http://www.infiltrated.net/modsecrules mod_security rule generator: http://leavesrustle.com/tools/modsecurity/ > For example: > > If somebody make a post with a board that is hosted on my server with > the word "wget" or "su root" then it will redirect the page to abuse.*my > domain*.com (but for every site, html / php ). Sure, but FYI if you are running a forum of some kind it is usually difficult to distinguish such attacks from people discussing Unix tools. -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Ivan R. <iv...@we...> - 2005-06-06 14:22:53
|
Adrian Wilford wrote: > Hi, > Anyone know if there is any effort to get mod_security to work with Tomcat? It already does, provided you are using Apache as a frontend. > If not, does anyone know where I can get the source code of mod_security for > java? On the download page? :) http://www.modsecurity.org/download/ -- Ivan Ristic Apache Security (O'Reilly) - http://www.apachesecurity.net Open source web application firewall - http://www.modsecurity.org |
|
From: Adrian W. <ad...@pe...> - 2005-06-06 14:20:20
|
Hi, Anyone know if there is any effort to get mod_security to work with Tomcat? If not, does anyone know where I can get the source code of mod_security for java? thanks, Adrian ---------------------------------------------------------------- Adrian Wilford Email (Home): awi...@gm... Email (Work): ad...@pe... Work: +27 11 722 7498 Cell: +27 83 260 4034 ---------------------------------------------------------------- |
|
From: Christian M. <cma...@is...> - 2005-06-06 14:12:08
|
Hi all, i saw Modseclogwatch ,and i thought it was ok, but i wanted somet= hing more like ACID or BASE, so I used the code of Evert Daman as a base for a console l= ike those. I did some work this weekend here is a demo: http://laramies.no-ip.org/mod_sec_test/ My Todo list have: -A Search form -A delete field in the table -Some graphics bars/pies with GD -Configuration screen for the install/setup -Multiple language version -Use css for everything -Beautify some outputs -Session control I will work in the frontend and Evert will keep working on the parser The code will be available as soon as i finish the first version, and Eve= rt correct a problem with the parsing of some headers. =20 Tell me what you think.. --=20 _________________________________ Christian Martorella e-Security Engineer cma...@is... Internet Security Auditors, S.L. c. Santander, 101. Edif. A. 2=BA 1=AA. 08030 Barcelona Tel: 93 305 13 18 Fax: 93 278 22 48 www.isecauditors.com ____________________________________ Este mensaje y los documentos que, en su caso lleve anexos, pueden contener informaci=F3n confidencial. Por ello, se informa a quien lo reciba por error que la informaci=F3n contenida en el mismo es reservada y su uso no autorizado est=E1 prohibido legalmente, por lo que en tal caso le rogamos que nos lo comunique por la misma v=EDa o por tel=E9fono (93 305 13 18), se abstenga de realizar copias del mensaje o remitirlo o entregarlo a otra persona y proceda a borrarlo de inmediato. En cumplimiento de la Ley Org=E1nica 15/1999 de 13 de diciembre de protecci=F3n de datos de car=E1cter personal, Internet Security Auditors S.L., le informa de que sus datos personales se han incluido en ficheros informatizados titularidad de Internet Security Auditors S.L., que ser=E1 el =FAnico destinatario de dichos datos, y cuya finalida= d exclusiva es la gesti=F3n de clientes y acciones de comunicaci=F3n comercial, y de que tiene la posibilidad de ejercer los derechos de acceso, rectificaci=F3n, cancelaci=F3n y oposici=F3n previstos en la ley mediante carta dirigida a Internet Security Auditors, c. Santander, 101. Edif. A. 2=BA 1=AA, 08030 Barcelona, o v=EDa e-mail a la siguiente direcci=F3n de correo: le...@is... |