logo
Apache Lounge
Webmasters

 

About Forum Index Downloads Search Register Log in RSS X


Keep Server Online

If you find the Apache Lounge, the downloads and overall help useful, please express your satisfaction with a donation.

or

Bitcoin

A donation makes a contribution towards the costs, the time and effort that's going in this site and building.

Thank You! Steffen

Your donations will help to keep this site alive and well, and continuing building binaries. Apache Lounge is not sponsored.
Post new topic   Forum Index -> News & Hangout View previous topic :: View next topic
Reply to topic   Topic: ModSecurity 2.5.10 released
Author
Steffen
Moderator


Joined: 15 Oct 2005
Posts: 3058
Location: Hilversum, NL, EU

PostPosted: Sat 26 Sep '09 18:51    Post subject: ModSecurity 2.5.10 released Reply with quote

ModSecurity 2.5.10 is now available, build with the newest Windows SDK v7.0 and against the newest libxml2-2.7.4.

This release fixes a number of small issues and contains the latest Core Rules 2.0.2.

Steffen


Change log 2.5.10

* Cleanup mlogc so that it builds on Windows.

* Added more detailed messages to replace "Unknown error" in filters.

* Added SecAuditLogDirMode and SecAuditLogFileMode to allow fine tuning
auditlog permissions (especially with mpm-itk).

* Cleanup SecUploadFileMode implementation.

* Cleanup build scripts.

* Fixed crash on configuration if SecMarker is used before any rules.

* Fixed SecRuleUpdateActionById so that it will work on chain starters.

* Cleanup build system for mlogc.

* Allow mlogc to periodically flush memory pools.

* Using nolog,auditlog will now log the "Message:" line to the auditlog, but
nothing to the error log. Prior versions dropped the "Message:" line from
both logs. To do this now, just use "nolog" or "nolog,noauditlog".

* Forced mlogc to use SSLv3 to avoid some potential auto negotiation
issues with some libcurl versions.

* Fixed mlogc issue seen on big endian machines where content type
could be listed as zero.

* Removed extra newline from audit log message line when logging XML errors.
This was causing problems parsing audit logs.

* Fixed @pm/@pmFromFile case insensitivity.

* Truncate long parameters in log message for "Match of ... against ...
required" messages.

* Correctly resolve chained rule actions in logs.

* Cleanup some code for portability.

* AIX does not support hidden visibility with xlc compiler.

* Allow specifying EXTRA_CFLAGS during configure to override gcc specific
values for non-gcc compilers.

* Populate GEO:COUNTRY_NAME and GEO:COUNTRY_CONTINENT as documented.

* Handle a newer geo database more gracefully, avoiding a potential crash for
new countries that ModSecurity is not yet aware.

* Allow checking &GEO "@eq 0" for a failed @geoLookup.

* Fixed mlogc global mutex locking issue and added more debugging output.

* Cleaned up build dependencies and configure options.
Back to top


Reply to topic   Topic: ModSecurity 2.5.10 released View previous topic :: View next topic
Post new topic   Forum Index -> News & Hangout