Search found 5 matches

by darkestweb
Sat Nov 12, 2011 10:17 pm
Forum: Atomicorp Free Modsecurity Rules
Topic: How can I stop this rule from logging?
Replies: 2
Views: 9801

Re: How can I stop this rule from logging?

Thank you, I'm going to change it as you will see below, please let me know if this is not correct in syntax. I just want it to stop in the audit.log as I review that to find out if there are any new subnets that I need to block. SecRule REQUEST_HEADERS:REFERER "more-proxies" deny,noauditl...
by darkestweb
Sat Nov 12, 2011 5:39 pm
Forum: Atomicorp Free Modsecurity Rules
Topic: How can I stop this rule from logging?
Replies: 2
Views: 9801

How can I stop this rule from logging?

I've made a referrer.conf file to stop some of the proxies that are evidently allowing the countries I'm blocking through. The rule looks like this and is blocking them but I'd rather it block and not log. I've tried some combinations after searching for the solutions but everything I've tried doesn...
by darkestweb
Sun Oct 23, 2011 12:23 am
Forum: Atomicorp Free Modsecurity Rules
Topic: Question on entry in audit_log
Replies: 4
Views: 12017

Re: Question on entry in audit_log

As you said and you were correct there were entries in the .htaccess that were filtering for known bad events and returning and redirecting to the index with a 403 error. Thank you very much for your advice/assistance.
by darkestweb
Sat Oct 22, 2011 9:25 pm
Forum: Atomicorp Free Modsecurity Rules
Topic: Question on entry in audit_log
Replies: 4
Views: 12017

Re: Question on entry in audit_log

Perfect sir I was wondering why it wasn't telling me the ruleset that was what was confusing me. Sorry I didn't know that it logged other 403's that way and thank you very much for the explanation.
by darkestweb
Sat Oct 22, 2011 7:59 pm
Forum: Atomicorp Free Modsecurity Rules
Topic: Question on entry in audit_log
Replies: 4
Views: 12017

Question on entry in audit_log

modsecurity 2.5.13 - most recent delayed rules I hope this shouldn't be obvious to me but I'm trying to track down an entry that is found very frequently in my audit_log. The following entry with little but time and sequence variation makes up 9/10ths of my audit log. I'm going to paste two that cam...