logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> Third-party Modules View previous topic :: View next topic
Reply to topic   Topic: Rules for mod_security now maintained by OWASP
Author
Steffen
Moderator


Joined: 15 Oct 2005
Posts: 3118
Location: Hilversum, NL, EU

PostPosted: Fri 20 May '11 9:26    Post subject: Rules for mod_security now maintained by OWASP Reply with quote

Since mod_security 2.6.0 the rules are not included anymore in the original source. It is now maintained by others, you can download the latest rules at:

https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project#tab=Download


The CRS (Core Rule Set Project) is a Open Web Application Security Project (OWASP) project maintained by Ryan Barnett, see https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project


Steffen
Back to top
maskego



Joined: 16 Apr 2010
Posts: 238

PostPosted: Fri 20 May '11 14:40    Post subject: Reply with quote

steffen:

some rules show error when startting apache.
Such as:

optional_rules:

modsecurity_crs_16_session_hijacking.conf
It causes fail to open web page.403 message shows.

modsecurity_crs_55_application_defects.conf
line:49,50,51 error
invalide command "header"

modsecurity_crs_49_header_tagging.conf
lines 30~49
invalide command "requestheader"

Is there any idea to fix it?
regards.


Last edited by maskego on Sat 21 May '11 5:32; edited 1 time in total
Back to top
Steffen
Moderator


Joined: 15 Oct 2005
Posts: 3118
Location: Hilversum, NL, EU

PostPosted: Fri 20 May '11 19:31    Post subject: Reply with quote

Best is to discuss/report it at the ModSecurity mailing list https://lists.sourceforge.net/lists/listinfo/mod-security-users

A fix is to remove the faulty rules Smile

Steffen
Back to top


Reply to topic   Topic: Rules for mod_security now maintained by OWASP View previous topic :: View next topic
Post new topic   Forum Index -> Third-party Modules