mod-security-users Mailing List for ModSecurity
Brought to you by:
victorhora,
zimmerletw
You can subscribe to this list here.
2003 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(17) |
Aug
(7) |
Sep
(8) |
Oct
(11) |
Nov
(14) |
Dec
(19) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2004 |
Jan
(46) |
Feb
(14) |
Mar
(20) |
Apr
(48) |
May
(15) |
Jun
(20) |
Jul
(36) |
Aug
(24) |
Sep
(31) |
Oct
(28) |
Nov
(23) |
Dec
(12) |
2005 |
Jan
(69) |
Feb
(61) |
Mar
(82) |
Apr
(53) |
May
(26) |
Jun
(71) |
Jul
(27) |
Aug
(52) |
Sep
(28) |
Oct
(49) |
Nov
(104) |
Dec
(74) |
2006 |
Jan
(61) |
Feb
(148) |
Mar
(82) |
Apr
(139) |
May
(65) |
Jun
(116) |
Jul
(92) |
Aug
(101) |
Sep
(84) |
Oct
(103) |
Nov
(174) |
Dec
(102) |
2007 |
Jan
(166) |
Feb
(161) |
Mar
(181) |
Apr
(152) |
May
(192) |
Jun
(250) |
Jul
(127) |
Aug
(165) |
Sep
(97) |
Oct
(135) |
Nov
(206) |
Dec
(56) |
2008 |
Jan
(160) |
Feb
(135) |
Mar
(98) |
Apr
(89) |
May
(115) |
Jun
(95) |
Jul
(188) |
Aug
(167) |
Sep
(153) |
Oct
(84) |
Nov
(82) |
Dec
(85) |
2009 |
Jan
(139) |
Feb
(133) |
Mar
(128) |
Apr
(105) |
May
(135) |
Jun
(79) |
Jul
(92) |
Aug
(134) |
Sep
(73) |
Oct
(112) |
Nov
(159) |
Dec
(80) |
2010 |
Jan
(100) |
Feb
(116) |
Mar
(130) |
Apr
(59) |
May
(88) |
Jun
(59) |
Jul
(69) |
Aug
(67) |
Sep
(82) |
Oct
(76) |
Nov
(59) |
Dec
(34) |
2011 |
Jan
(84) |
Feb
(74) |
Mar
(81) |
Apr
(94) |
May
(188) |
Jun
(72) |
Jul
(118) |
Aug
(109) |
Sep
(111) |
Oct
(80) |
Nov
(51) |
Dec
(44) |
2012 |
Jan
(80) |
Feb
(123) |
Mar
(46) |
Apr
(12) |
May
(40) |
Jun
(62) |
Jul
(95) |
Aug
(66) |
Sep
(65) |
Oct
(53) |
Nov
(42) |
Dec
(60) |
2013 |
Jan
(96) |
Feb
(96) |
Mar
(108) |
Apr
(72) |
May
(115) |
Jun
(111) |
Jul
(114) |
Aug
(87) |
Sep
(93) |
Oct
(97) |
Nov
(104) |
Dec
(82) |
2014 |
Jan
(96) |
Feb
(77) |
Mar
(71) |
Apr
(40) |
May
(48) |
Jun
(78) |
Jul
(54) |
Aug
(44) |
Sep
(58) |
Oct
(79) |
Nov
(51) |
Dec
(52) |
2015 |
Jan
(55) |
Feb
(59) |
Mar
(48) |
Apr
(40) |
May
(45) |
Jun
(63) |
Jul
(36) |
Aug
(49) |
Sep
(35) |
Oct
(58) |
Nov
(21) |
Dec
(47) |
2016 |
Jan
(35) |
Feb
(81) |
Mar
(43) |
Apr
(41) |
May
(77) |
Jun
(52) |
Jul
(39) |
Aug
(34) |
Sep
(107) |
Oct
(67) |
Nov
(54) |
Dec
(20) |
2017 |
Jan
(99) |
Feb
(37) |
Mar
(86) |
Apr
(47) |
May
(57) |
Jun
(55) |
Jul
(34) |
Aug
(31) |
Sep
(16) |
Oct
(49) |
Nov
(53) |
Dec
(33) |
2018 |
Jan
(25) |
Feb
(11) |
Mar
(79) |
Apr
(77) |
May
(5) |
Jun
(19) |
Jul
(17) |
Aug
(7) |
Sep
(13) |
Oct
(22) |
Nov
(13) |
Dec
(68) |
2019 |
Jan
(44) |
Feb
(17) |
Mar
(40) |
Apr
(39) |
May
(18) |
Jun
(14) |
Jul
(20) |
Aug
(31) |
Sep
(11) |
Oct
(35) |
Nov
(3) |
Dec
(10) |
2020 |
Jan
(32) |
Feb
(16) |
Mar
(10) |
Apr
(22) |
May
(2) |
Jun
(34) |
Jul
(1) |
Aug
(8) |
Sep
(36) |
Oct
(16) |
Nov
(13) |
Dec
(10) |
2021 |
Jan
(16) |
Feb
(23) |
Mar
(45) |
Apr
(28) |
May
(6) |
Jun
(17) |
Jul
(8) |
Aug
(1) |
Sep
(2) |
Oct
(35) |
Nov
|
Dec
(5) |
2022 |
Jan
|
Feb
(17) |
Mar
(23) |
Apr
(23) |
May
(9) |
Jun
(8) |
Jul
|
Aug
|
Sep
(7) |
Oct
(5) |
Nov
(16) |
Dec
(4) |
2023 |
Jan
|
Feb
|
Mar
(3) |
Apr
|
May
(1) |
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(2) |
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
(7) |
Feb
(13) |
Mar
(18) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(2) |
Oct
(1) |
Nov
(5) |
Dec
(3) |
2025 |
Jan
|
Feb
|
Mar
|
Apr
(12) |
May
(10) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
|
|
1
|
2
(6) |
3
(1) |
4
|
5
|
6
|
7
(1) |
8
(10) |
9
|
10
(7) |
11
(4) |
12
|
13
|
14
|
15
(3) |
16
(2) |
17
(3) |
18
(4) |
19
(3) |
20
(2) |
21
(1) |
22
|
23
|
24
|
25
|
26
|
27
|
28
|
29
|
30
|
31
|
|
|
From: Felipe C. <FC...@tr...> - 2015-12-21 12:10:44
|
Hi toufik, Are you talking about the Google summer of code project? Br., Felipe “Zimmerle” Costa Security Researcher, SpiderLabs Trustwave | SMART SECURITY ON DEMAND www.trustwave.com<http://www.trustwave.com/> From: "tou...@gm...<mailto:tou...@gm...>" <tou...@gm...<mailto:tou...@gm...>> Reply-To: "mod...@li...<mailto:mod...@li...>" <mod...@li...<mailto:mod...@li...>> Date: Sunday, December 20, 2015 at 6:26 AM To: "mod...@li...<mailto:mod...@li...>" <mod...@li...<mailto:mod...@li...>> Subject: [mod-security-users] Modsecurity snifer mode build a sniffer mode for ModSecurity ________________________________ This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format. |
From: Christian F. <chr...@ti...> - 2015-12-20 09:57:42
|
Toufik, It's very hard to understand what you want. Probably a language problem. If it is a sniffer mode for ModSecurity you want, then there is a sniffer mode already. At least according to my understanding to the term. Just deploy it inline in detectionmode. Best regards, Christian On Sun, Dec 20, 2015 at 10:26:57AM +0100, tou...@gm... wrote: > Hello > I'm student, I'm interested to the project of "build a sniffer mode for ModSecurity." > I would like to help me please > > Thanks > Provenance : Courrier pour Windows 10 > > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ |
From: <tou...@gm...> - 2015-12-20 09:27:11
|
Hello I'm student, I'm interested to the project of "build a sniffer mode for ModSecurity." I would like to help me please Thanks Provenance : Courrier pour Windows 10 |
From: Bill D. <bil...@ya...> - 2015-12-19 12:50:50
|
Ubuntu 15.04 - The install went fine and the site is blocking the crawlers I expected it too. However, the defaults are blocking too much since we use the Revive ad server on one of this boxes IP's to serve ads to hosts on other IP's on the same box and elsewhere. Also, we only need mod_security to apply to one of *our* IP's. I followed just the mod_security part of this: http://blog.mattbrock.co.uk/hardening-the-security-on-ubuntu-server-14-04/ The scenario is that there are several vhosts sharing the same IP which are each backed by large MySQL db's. They are growing all the time, and the crawlers are hammering each page constantly. The hosts on the other IP's don't have this volume MySQL data, so they can be left alone. It's not just that, I found I was now denied some joomla admin functions, so reckon it would be cleaner just to apply mod_security to the IP I am concerned about. So I'd like to make 2 changes: 1. Whitelist ads.example1.com (or its IP) so all inbound traffic from there is allowed 2. Only apply mod_security to IP w.x.y.z, which is one of the IP's on our server which several vhosts share. I got into a fix trying myself and after too many resets realised it must be easy for someone on this list. Thanks! |
From: SADDAR T. <tou...@gm...> - 2015-12-19 09:58:18
|
Hello I want to help me to deploy Modsecurity in sniffer mode Thanks |
From: Reindl H. <h.r...@th...> - 2015-12-19 01:26:50
|
Am 18.12.2015 um 21:07 schrieb Oliver Habicht: > Hi, > > pleas remove me from your mailinglist. WTF don't you unubscribe yourself? who subscribed you? the list - footer and headers are not just for fun List-Unsubscribe: <https://lists.sourceforge.net/lists/listinfo/mod-security-users> <mailto:mod...@li...?subject=unsubscribe> > Kind regards > Oliver Habicht > > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ |
From: Robert P. <rpa...@fe...> - 2015-12-18 23:21:04
|
Doing this type of parsing out of the error log would be time consuming and wasteful. May I recommend checking out the JSON audit logging branch available from the fork at https://github.com/p0pr0ck5/ModSecurity/tree/json_audit_logging This allows you to produce audit logs in a standardized, programmatic format. > On Dec 18, 2015, at 11:59, Sasi Sasivarenan <sas...@gm...> wrote: > > Hi, > > > I want to separate the error log file by formatting the line as a column. Just we need to display timestamp, client ip, id , uri, unique id, msg...... > > > how to do using linux command > > > > > >> On Wed, Dec 16, 2015 at 9:06 PM, Margason, Jacob <j.m...@va...> wrote: >> I’m happy to help out, email me here, ja...@jk... and we can discuss outside the mailing list if you’d like. >> >> From: Sasi Sasivarenan <sas...@gm...> >> Reply-To: "mod...@li..." <mod...@li...> >> Date: Wednesday, December 16, 2015 at 8:17 AM >> To: "mod...@li..." <mod...@li...> >> Subject: Re: [mod-security-users] Modsecurity log report >> >> Thanks for the quick reply guys... >> >> >> Yes jacob, we just want to automate the report. Normally, >> >> >>> On Wed, Dec 16, 2015 at 2:05 AM, Jacob Margason <j.m...@va...> wrote: >>> I would look into log aggregation tools like Sumo Logic. Why can't you collect the Apache logs daily? or do you just mean you'd like to automate some report building? >>> >>>> On 12/15/2015 02:31 PM, Sasi Sasivarenan wrote: >>>> Hi, >>>> >>>> we have launched Modsecurity recently which is now in a detection mode. We need a help in log monitoring. we found many pattern matches in the apache error log but unable collect those data on daily basis. Please help how to collect those data and analyse. >>> >>> -- >>> Jacob Margason >>> Application Server Administrator >>> VUIT Linux Applications | Vanderbilt University >>> 615.380.1013 | j.m...@va... >>> >>> ------------------------------------------------------------------------------ >>> >>> _______________________________________________ >>> mod-security-users mailing list >>> mod...@li... >>> https://lists.sourceforge.net/lists/listinfo/mod-security-users >>> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: >>> http://www.modsecurity.org/projects/commercial/rules/ >>> http://www.modsecurity.org/projects/commercial/support/ >> >> >> ------------------------------------------------------------------------------ >> >> _______________________________________________ >> mod-security-users mailing list >> mod...@li... >> https://lists.sourceforge.net/lists/listinfo/mod-security-users >> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: >> http://www.modsecurity.org/projects/commercial/rules/ >> http://www.modsecurity.org/projects/commercial/support/ > > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ |
From: Oliver H. <oha...@t-...> - 2015-12-18 20:07:51
|
Hi, pleas remove me from your mailinglist. Kind regards Oliver Habicht |
From: Sasi S. <sas...@gm...> - 2015-12-18 19:59:39
|
Hi, I want to separate the error log file by formatting the line as a column. Just we need to display timestamp, client ip, id , uri, unique id, msg...... how to do using linux command On Wed, Dec 16, 2015 at 9:06 PM, Margason, Jacob <j.m...@va...> wrote: > I’m happy to help out, email me here, ja...@jk... and we can discuss > outside the mailing list if you’d like. > > From: Sasi Sasivarenan <sas...@gm...> > Reply-To: "mod...@li..." < > mod...@li...> > Date: Wednesday, December 16, 2015 at 8:17 AM > To: "mod...@li..." < > mod...@li...> > Subject: Re: [mod-security-users] Modsecurity log report > > Thanks for the quick reply guys... > > > Yes jacob, we just want to automate the report. Normally, > > > On Wed, Dec 16, 2015 at 2:05 AM, Jacob Margason <j.m...@va... > > wrote: > >> I would look into log aggregation tools like Sumo Logic. Why can't you >> collect the Apache logs daily? or do you just mean you'd like to automate >> some report building? >> >> On 12/15/2015 02:31 PM, Sasi Sasivarenan wrote: >> >> Hi, >> >> we have launched Modsecurity recently which is now in a detection mode. >> We need a help in log monitoring. we found many pattern matches in the >> apache error log but unable collect those data on daily basis. Please help >> how to collect those data and analyse. >> >> >> -- >> Jacob Margason >> Application Server Administrator >> VUIT Linux Applications | Vanderbilt University >> 615.380.1013 | j.m...@va... >> >> >> >> ------------------------------------------------------------------------------ >> >> _______________________________________________ >> mod-security-users mailing list >> mod...@li... >> https://lists.sourceforge.net/lists/listinfo/mod-security-users >> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: >> http://www.modsecurity.org/projects/commercial/rules/ >> http://www.modsecurity.org/projects/commercial/support/ >> >> > > > ------------------------------------------------------------------------------ > > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ > > |
Hi Gyana, The log entries you provided has already addressed the main problem with the blocking. According to the first line of given log from you as below: [Thu Dec 17 08:27:56.553114 2015] [proxy_http:error] [pid 7148:tid 904] [client 10.134.13.178:57752[1]] AH01114: HTTP: failed to make connection to backend: pangy01-w2k8vm1.ca.com[2] Apache told that it was unable to connect to the backend, and an 503 error was returned from proxy module that captured by modsecurity and triggered rule 970901. You may be able to use curl or other tools to help you to diagnose the connection issue happend at your modsecurity instance. -- BR, Morris On Thu, Dec 17, 2015, at 10:11 PM, Gyana Ranjan Panigrahi wrote: > This is my error.log which i captured when i tried to launch URL. > [Thu Dec 17 08:27:56.553114 2015] [proxy_http:error] [pid 7148:tid 904] [client 10.134.13.178:57752] AH01114: HTTP: failed to make connection to backend: pangy01-w2k8vm1.ca.com > [Thu Dec 17 08:27:56.553114 2015] [:error] [pid 7148:tid 904] [client 10.134.13.178] ModSecurity: Access denied with code 403 (phase 4). Pattern match "^5\\\\d{2}$" at RESPONSE_STATUS. [file "C:/win32app/Spectrum/apache/modsecurity-crs/base_rules/modsecurity_crs_50_outbound.conf"] [line "53"] [id "970901"] [rev "2"] [msg "The application is not available"] [data "Matched Data: 503 found within RESPONSE_STATUS: 503"] [severity "ERROR"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "WASCTC/WASC-13"] [tag "OWASP_TOP_10/A6"] [tag "PCI/6.5.6"] [hostname "pangy01-w2k8vm1"] [uri "/spectrum"] [unique_id "VnK4WQrxATYAABvsgIgAAAA-"] > [Thu Dec 17 08:27:56.553114 2015] [:error] [pid 7148:tid 904] [client 10.134.13.178] ModSecurity: Warning. Operator GE matched 4 at TX:outbound_anomaly_score. [file "C:/win32app/Spectrum/apache/modsecurity-crs/base_rules/modsecurity_crs_60_correlation.conf"] [line "40"] [id "981205"] [msg "Outbound Anomaly Score Exceeded (score 4): The application is not available"] [hostname "pangy01-w2k8vm1"] [uri "/spectrum"] [unique_id "VnK4WQrxATYAABvsgIgAAAA-"] > [Thu Dec 17 08:27:56.771519 2015] [authz_core:error] [pid 7148:tid 904] [client 10.134.13.178:57753] AH01630: client denied by server configuration: C:/apache, referer: http://pangy01-w2k8vm1:8081/spectrum > > > Thanks Gyana > > On Thu, Dec 17, 2015 at 7:28 PM, Reindl Harald <h.r...@th...> wrote: >> >> >> Am 17.12.2015 um 14:49 schrieb Gyana Ranjan Panigrahi: >>> <Connector port="8080" address="127.0.0.1" URIEncoding="UTF-8" >>> maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" >>> enableLookups="true" redirectPort="8443" acceptCount="100" >>> connectionTimeout="20000" disableUploadTimeout="true" tcpNoDelay="true" /> >>> >>> When i tried to launch URL it says Forbidden You don't have permission >>> to access /spectrum on this server. Additionally, a 503 Service >>> Unavailable error was encountered while trying to use an ErrorDocument >>> to handle the request >> >> that's hardly a mod_security question and without logs nobody can help you >> >> >> >> >> >> ------------------------------------------------------------------------------ >> >> _______________________________________________ >> mod-security-users mailing list >> mod...@li... >> https://lists.sourceforge.net/lists/listinfo/mod-security-users >> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: >> http://www.modsecurity.org/projects/commercial/rules/ >> http://www.modsecurity.org/projects/commercial/support/ >> > > > > -- > *Best & Regards > Gyana Ranjan Panigrahi**** * > > > > > > > > > > ------------------------------------------------------------------------------ > _________________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ Links: 1. http://10.134.13.178:57752/ 2. http://pangy01-w2k8vm1.ca.com/ |
From: Gyana R. P. <mai...@gm...> - 2015-12-17 14:11:42
|
This is my error.log which i captured when i tried to launch URL. [Thu Dec 17 08:27:56.553114 2015] [proxy_http:error] [pid 7148:tid 904] [client 10.134.13.178:57752] AH01114: HTTP: failed to make connection to backend: pangy01-w2k8vm1.ca.com [Thu Dec 17 08:27:56.553114 2015] [:error] [pid 7148:tid 904] [client 10.134.13.178] ModSecurity: Access denied with code 403 (phase 4). Pattern match "^5\\\\d{2}$" at RESPONSE_STATUS. [file "C:/win32app/Spectrum/apache/modsecurity-crs/base_rules/modsecurity_crs_50_outbound.conf"] [line "53"] [id "970901"] [rev "2"] [msg "The application is not available"] [data "Matched Data: 503 found within RESPONSE_STATUS: 503"] [severity "ERROR"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "WASCTC/WASC-13"] [tag "OWASP_TOP_10/A6"] [tag "PCI/6.5.6"] [hostname "pangy01-w2k8vm1"] [uri "/spectrum"] [unique_id "VnK4WQrxATYAABvsgIgAAAA-"] [Thu Dec 17 08:27:56.553114 2015] [:error] [pid 7148:tid 904] [client 10.134.13.178] ModSecurity: Warning. Operator GE matched 4 at TX:outbound_anomaly_score. [file "C:/win32app/Spectrum/apache/modsecurity-crs/base_rules/modsecurity_crs_60_correlation.conf"] [line "40"] [id "981205"] [msg "Outbound Anomaly Score Exceeded (score 4): The application is not available"] [hostname "pangy01-w2k8vm1"] [uri "/spectrum"] [unique_id "VnK4WQrxATYAABvsgIgAAAA-"] [Thu Dec 17 08:27:56.771519 2015] [authz_core:error] [pid 7148:tid 904] [client 10.134.13.178:57753] AH01630: client denied by server configuration: C:/apache, referer: http://pangy01-w2k8vm1:8081/spectrum Thanks Gyana On Thu, Dec 17, 2015 at 7:28 PM, Reindl Harald <h.r...@th...> wrote: > > > Am 17.12.2015 um 14:49 schrieb Gyana Ranjan Panigrahi: > >> <Connector port="8080" address="127.0.0.1" URIEncoding="UTF-8" >> maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" >> enableLookups="true" redirectPort="8443" acceptCount="100" >> connectionTimeout="20000" disableUploadTimeout="true" tcpNoDelay="true" /> >> >> When i tried to launch URL it says Forbidden You don't have permission >> to access /spectrum on this server. Additionally, a 503 Service >> Unavailable error was encountered while trying to use an ErrorDocument >> to handle the request >> > > that's hardly a mod_security question and without logs nobody can help you > > > > > > > ------------------------------------------------------------------------------ > > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ > > -- *Best & RegardsGyana Ranjan Panigrahi* |
Am 17.12.2015 um 14:49 schrieb Gyana Ranjan Panigrahi: > <Connector port="8080" address="127.0.0.1" URIEncoding="UTF-8" > maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" > enableLookups="true" redirectPort="8443" acceptCount="100" > connectionTimeout="20000" disableUploadTimeout="true" tcpNoDelay="true" /> > > When i tried to launch URL it says Forbidden You don't have permission > to access /spectrum on this server. Additionally, a 503 Service > Unavailable error was encountered while trying to use an ErrorDocument > to handle the request that's hardly a mod_security question and without logs nobody can help you |
From: Gyana R. P. <mai...@gm...> - 2015-12-17 13:49:55
|
Hi All, I currently have a Tomcat server hosting a web app with apache proxy in front of it. The Tomcat server is also terminating Client Authenticated SSL connections to the web application.I configured a new instance of apache, install mod_security, reconfigure my web app so that the ssl connections terminate at apache, and then use mod_proxyto connect to tomcat. My VirtaulHost configuration looks like below: Listen 8081 <VirtualHost *:8081> ProxyPass /spectrum http://pangy01-w2k8vm1:8080/spectrum ProxyPassReverse /spectrum http://pangy01-w2k8vm1:8080/spectrum </VirtualHost> where pangy01-w2k8vm1 is my host and apache runs on 8081 port and tomcat on 8080.and i blocked the tomcat port for outside acess because i want every URL should first hit apache then go through modsecurity and hits tomcat. SO for blocking tomcat i added the loopback address in the server.xml file like below: <Connector port="8080" address="127.0.0.1" URIEncoding="UTF-8" maxHttpHeaderSize="8192" maxThreads="150" minSpareThreads="25" enableLookups="true" redirectPort="8443" acceptCount="100" connectionTimeout="20000" disableUploadTimeout="true" tcpNoDelay="true" /> When i tried to launch URL it says Forbidden You don't have permission to access /spectrum on this server. Additionally, a 503 Service Unavailable error was encountered while trying to use an ErrorDocument to handle the request. Plase help me on this!!! -- *Best & RegardsGyana Ranjan Panigrahi* |
From: Margason, J. <j.m...@va...> - 2015-12-16 15:52:45
|
I’m happy to help out, email me here, ja...@jk... and we can discuss outside the mailing list if you’d like. From: Sasi Sasivarenan <sas...@gm...<mailto:sas...@gm...>> Reply-To: "mod...@li...<mailto:mod...@li...>" <mod...@li...<mailto:mod...@li...>> Date: Wednesday, December 16, 2015 at 8:17 AM To: "mod...@li...<mailto:mod...@li...>" <mod...@li...<mailto:mod...@li...>> Subject: Re: [mod-security-users] Modsecurity log report Thanks for the quick reply guys... Yes jacob, we just want to automate the report. Normally, On Wed, Dec 16, 2015 at 2:05 AM, Jacob Margason <j.m...@va...<mailto:j.m...@va...>> wrote: I would look into log aggregation tools like Sumo Logic. Why can't you collect the Apache logs daily? or do you just mean you'd like to automate some report building? On 12/15/2015 02:31 PM, Sasi Sasivarenan wrote: Hi, we have launched Modsecurity recently which is now in a detection mode. We need a help in log monitoring. we found many pattern matches in the apache error log but unable collect those data on daily basis. Please help how to collect those data and analyse. -- Jacob Margason Application Server Administrator VUIT Linux Applications | Vanderbilt University 615.380.1013 | j.m...@va...<mailto:j.m...@va...> ------------------------------------------------------------------------------ _______________________________________________ mod-security-users mailing list mod...@li...<mailto:mod...@li...> https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ |
From: Sasi S. <sas...@gm...> - 2015-12-16 14:17:29
|
Thanks for the quick reply guys... Yes jacob, we just want to automate the report. Normally, On Wed, Dec 16, 2015 at 2:05 AM, Jacob Margason <j.m...@va...> wrote: > I would look into log aggregation tools like Sumo Logic. Why can't you > collect the Apache logs daily? or do you just mean you'd like to automate > some report building? > > On 12/15/2015 02:31 PM, Sasi Sasivarenan wrote: > > Hi, > > we have launched Modsecurity recently which is now in a detection mode. We > need a help in log monitoring. we found many pattern matches in the apache > error log but unable collect those data on daily basis. Please help how to > collect those data and analyse. > > > -- > Jacob Margason > Application Server Administrator > VUIT Linux Applications | Vanderbilt University > 615.380.1013 | j.m...@va... > > > > ------------------------------------------------------------------------------ > > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ > > |
From: Jacob M. <j.m...@va...> - 2015-12-15 20:50:56
|
I would look into log aggregation tools like Sumo Logic. Why can't you collect the Apache logs daily? or do you just mean you'd like to automate some report building? On 12/15/2015 02:31 PM, Sasi Sasivarenan wrote: > Hi, > > we have launched Modsecurity recently which is now in a detection mode. We need a help in log monitoring. we found many pattern matches in the apache error log but unable collect those data on daily basis. Please help how to collect those data and analyse. -- Jacob Margason Application Server Administrator VUIT Linux Applications | Vanderbilt University 615.380.1013 | j.m...@va... |
From: Christian F. <chr...@ti...> - 2015-12-15 20:42:37
|
Sasi, What you need to perform is the tuning of your installation. This is a time-consuming process, but it will make sure that you end up with a setup that brings only few pattern matches which are easier to review. Please google to find ModSec tuning advice. Good luck! Christian On Wed, Dec 16, 2015 at 02:01:44AM +0530, Sasi Sasivarenan wrote: > Hi, > > we have launched Modsecurity recently which is now in a detection mode. We > need a help in log monitoring. we found many pattern matches in the apache > error log but unable collect those data on daily basis. Please help how to > collect those data and analyse. > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ |
From: Sasi S. <sas...@gm...> - 2015-12-15 20:31:50
|
Hi, we have launched Modsecurity recently which is now in a detection mode. We need a help in log monitoring. we found many pattern matches in the apache error log but unable collect those data on daily basis. Please help how to collect those data and analyse. |
From: Christian F. <chr...@ti...> - 2015-12-11 20:35:02
|
Guillermo, Divide et Impera - or in English: Divide and Rule. I let that roman motto be my guide in things server and instances. For a RP setup, I think you want at least a pair, so you have redundancy, can update them one by one without downtime and generally feel better. As you have a pair, you need a simple deployment tool and if you have a simple deployment tool, there is not much difference, if you 1, 2, 4 or 8 RP instances. Ahoj, Christian On Fri, Dec 11, 2015 at 04:37:02PM -0300, Guillermo Caminer wrote: > Hi list! > > What would be best, in a multiple WebServer environment: use one ModSec instance per Web Server, or > use one instance in a reverse proxy in front of all the Web Servers? Each has it owns cons and pros: > multiple instances requires higher administration work, but would be more efficient. In the other > hand, having one instance in a reverse proxy could create a bottle-neck but will ease administration. > > What do you think? > > Thanks in advance? > > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ |
From: Brian K. <bp...@gm...> - 2015-12-11 20:34:06
|
In a system I helped develop, we used a series or reverse proxies to handle modsec across many backends. In part what we found was that the rules required a not insignificant amount of memory so it was actually more efficient from that standpoint to have fewer modsec instances. Your constraints may be different, best to measure. Cheers, Brian On Fri, Dec 11, 2015, 13:42 Guillermo Caminer <fla...@gm...> wrote: > Hi list! > > What would be best, in a multiple WebServer environment: use one ModSec > instance per Web Server, or > use one instance in a reverse proxy in front of all the Web Servers? Each > has it owns cons and pros: > multiple instances requires higher administration work, but would be more > efficient. In the other > hand, having one instance in a reverse proxy could create a bottle-neck > but will ease administration. > > What do you think? > > Thanks in advance? > > > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ > |
From: Jacob M. <j.m...@va...> - 2015-12-11 20:33:16
|
We are currently deploying about 25 web servers behind a set of reverse proxies with mod security. So that's what I would recommend. The bottleneck is not a problem, just make sure you architect for high availability, make sure logging is reasonable, and that the proxies have enough resources. Advantages: * Easily put ALL of your rules into a single VCS repository and then load that into the proxies via chef etc. * Harden the reverse proxies without worrying about making your devs angry because you broke something enabling PaX >:) * Have a legacy application that requires an older kernel version? you need not worry about having to set up mod-security on some dinosaur like an old version of Oracle Linux or something. * Forward requests temporarily somewhere else even if the application server is down because the devs borked it on the last update. * Use a single IP/CNAME for EVERYTHING :D * Use a single SSL SAN cert and terminate it at the proxies; now you can use compression on the back end and save some CPU by not encrypting things for no good reason, as well as using advanced proxy functionality like mod_proxy_html. * Set caching headers for certain kinds of assets (.jpg etc.) regardless of what the devs want/forgot to do automatically for everything. In summary, you can just create whatever your dev's want/need in the back-end while maintaining absolute control over your mod security install to ensure that it is up to date and running well. This also gives you the opportunity to use the same proxies for things like Varnish and other performance magic. There are probably more advantages, but if you can swing it, keep them separate, you can be much more agile that way. -- Jacob Margason Application Server Administrator VUIT Linux Applications | Vanderbilt University 615.380.1013 | j.m...@va... On 12/11/2015 01:37 PM, Guillermo Caminer wrote: > Hi list! > > What would be best, in a multiple WebServer environment: use one ModSec instance per Web Server, or > use one instance in a reverse proxy in front of all the Web Servers? Each has it owns cons and pros: > multiple instances requires higher administration work, but would be more efficient. In the other > hand, having one instance in a reverse proxy could create a bottle-neck but will ease administration. > > What do you think? > > Thanks in advance? > > ------------------------------------------------------------------------------ > _______________________________________________ > mod-security-users mailing list > mod...@li... > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ |
From: Guillermo C. <fla...@gm...> - 2015-12-11 19:37:23
|
Hi list! What would be best, in a multiple WebServer environment: use one ModSec instance per Web Server, or use one instance in a reverse proxy in front of all the Web Servers? Each has it owns cons and pros: multiple instances requires higher administration work, but would be more efficient. In the other hand, having one instance in a reverse proxy could create a bottle-neck but will ease administration. What do you think? Thanks in advance? |
From: Chaim S. <CSa...@tr...> - 2015-12-10 18:06:57
|
Thank you clarification Reindl :) Chaim Sanders Security Researcher, SpiderLabs Trustwave | SMART SECURITY ON DEMAND www.trustwave.com -----Original Message----- From: Reindl Harald [mailto:h.r...@th...] Sent: Thursday, December 10, 2015 1:05 PM To: mod...@li... Subject: Re: [mod-security-users] Problem with SecRemoteRules Am 10.12.2015 um 18:31 schrieb Chaim Sanders: > This looks like a separate problem, in the future please change > subject lines. no - don't use reply at all on a mailing-list when you start a different question - changing the subject breaks the thread identical ________________________________ This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format. |
From: Reindl H. <h.r...@th...> - 2015-12-10 18:04:56
|
Am 10.12.2015 um 18:31 schrieb Chaim Sanders: > This looks like a separate problem, in the future please change subject > lines. no - don't use reply at all on a mailing-list when you start a different question - changing the subject breaks the thread identical |
From: Chaim S. <CSa...@tr...> - 2015-12-10 17:31:26
|
Bienvenu, This looks like a separate problem, in the future please change subject lines. We can in fact help you however this platform has precompiled binaries available. See the fine folks over at ApacheHaus for details (https://www.apachehaus.com/cgi-bin/download.plx) Chaim Sanders Security Researcher, SpiderLabs Trustwave | SMART SECURITY ON DEMAND www.trustwave.com<http://www.trustwave.com/> From: Bienvenu Ngoma [mailto:bev...@gm...] Sent: Thursday, December 10, 2015 5:25 AM To: mod...@li... Subject: Re: [mod-security-users] Problem with SecRemoteRules Hello, I need to configure mod_security in Apache 2 on windows, cn you help me please? _____________________________________________________________________________ Bienvenu NGOMA Tél: +243 81 192 9554 e-mail: bev...@gm...<mailto:bev...@gm...> skype: bvngoma Kinshasa République Démocratique du Congo On Thu, Dec 10, 2015 at 9:54 AM, Amos Beh <amo...@iz...<mailto:amo...@iz...>> wrote: Hi all, ModSecurity: Loaded 0 rules from: 'https://dashboard.modsecurity.org/rules/download/plain<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7X8dGOfkMg&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttps%2fdashboard%2emodsecurity%2eorg%2frules%2fdownload%2fplain>'. ModSecurity: Problems loading external resources: Failed to download: "https://dashboard.modsecurity.org/rules/download/plain<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7X8dGOfkMg&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttps%2fdashboard%2emodsecurity%2eorg%2frules%2fdownload%2fplain>" error: Problem with the SSL CA cert (path? access rights?). I have enabled SecRemoteRules to download rules, but having this error. Any idea on this? Amazon Linux 2015.09 Apache 2.2.31 Mod_security 2.9 -- Best regards, Amos Beh Senior System Consultant [Image removed by sender. iZeno Pte Ltd]<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7XgWSOCxMA&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttp%2fwww%2eizeno%2ecom> iZeno Pte Ltd | 72 Bendemeer Road Luzerne #05-28 Singapore 339941 M (65) 9853 9084 | T (65) 6100 2788 | www.izeno.com<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7XgWSOCxMA&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttp%2fwww%2eizeno%2ecom> [Image removed by sender. facebook]<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7S1MHLezNQ&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttps%2fwww%2efacebook%2ecom%2fiZenoPL> Red Hat Certified Engineer (100-176-239) | AWS Certified Solutions Architect – Professional Level (AWS-PSA-1445) [Image removed by sender. iZeno Pte Ltd]<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7XgWSOCxMA&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttp%2fwww%2eizeno%2ecom> This communication contains information which may be confidential or privileged. The information is intended solely for the use of the individual or entity named above. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited. If you have received this communication in error, please notify me by telephone immediately. ------------------------------------------------------------------------------ _______________________________________________ mod-security-users mailing list mod...@li...<mailto:mod...@li...> https://lists.sourceforge.net/lists/listinfo/mod-security-users<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7S1MGbPhMw&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttps%2flists%2esourceforge%2enet%2flists%2flistinfo%2fmod-security-users> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7X8eTeq1Nw&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttp%2fwww%2emodsecurity%2eorg%2fprojects%2fcommercial%2frules%2f> http://www.modsecurity.org/projects/commercial/support/<http://scanmail.trustwave.com/?c=4062&d=otPp1tjUeqCEJGH_DY7fteI5a_PmgUyT7X4aH-bhYg&s=5&u=https%3a%2f%2fround-lake.dustinice.workers.dev%3a443%2fhttp%2fwww%2emodsecurity%2eorg%2fprojects%2fcommercial%2fsupport%2f> ________________________________ This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format. |