Skip to content
This repository was archived by the owner on May 14, 2020. It is now read-only.

Conversation

@emphazer
Copy link
Contributor

according to #1418

…UEST-903.9003-NEXTCLOUD-EXCLUSION-RULES.conf
@theMiddleBlue
Copy link
Contributor

thanks @emphazer

unfortunately, it seems that ruleRemoveById doesn't work properly when a range is given :( owasp-modsecurity/ModSecurity#2099 (comment) this makes useless a lot of CRS exclusion rules when using on libmodsecurity (v3).

@emphazer
Copy link
Contributor Author

okay @theMiddleBlue
i will fix that

@emphazer
Copy link
Contributor Author

@theMiddleBlue but that will fix just a part of the problem.
they must fix it in libmodsecurity or else we can't keep this rule exclusions in my opinion.

@theMiddleBlue
Copy link
Contributor

theMiddleBlue commented May 22, 2019

thanks!

they must fix it in libmodsecurity

yes, they must. Our exclusion rule set makes extensive use of ruleRemoveById with ranges and ruleRemoveByTag. This makes CRS incompatible with the current v3... I'm waiting for an answer here owasp-modsecurity/ModSecurity#2099

@theMiddleBlue theMiddleBlue added On Hold ModSec Issue related to ModSecurity labels May 23, 2019
@theMiddleBlue
Copy link
Contributor

A PR will be soon available on ModSecurity in order to fix this. Thanks!

@theMiddleBlue
Copy link
Contributor

fixed by owasp-modsecurity/ModSecurity#2102 (thanks @airween @zimmerle)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ModSec Issue related to ModSecurity

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants