Current time: 11-25-2024, 04:05 AM Hello There, Guest! (LoginRegister)


Post Reply 
[HowTo] Mod Security on debian
Author Message
prale Offline
Junior Member
*

Posts: 92
Joined: Feb 2008
Reputation: 1
Post: #10
RE: Mod Security on debian
I also needed to set ServerTokens from Prod to Full in /etc/apache2/apache2.conf

And I have some problems after enabling mod_security2:

- HTTP 501/HTTP 505 response when editing a record in PMA
- HTTP 400 response when using my ip-adres instead of my main-domain.
(before I always saw the ISPCP login)

I see many entry's like this in /var/log/apache2/error.log:

Code:
[Sun Apr 20 20:40:08 2008] [error] [client 127.0.0.1] ModSecurity: Warning. Match of "rx ^OPTIONS$" against "REQUEST_METHOD" required. [file "/etc/modsecurity2/modsecurity_crs_21_protocol_anomalies.conf"] [line "41"] [id "960015"] [msg "Request Missing an Accept Header"] [severity "CRITICAL"] [tag "PROTOCOL_VIOLATION/MISSING_HEADER"] [hostname "localhost"] [uri "/watch-list"] [unique_id "T-tpl1GpgkIAAD@pFY4AAAAA"]

[Sun Apr 20 20:40:08 2008] [error] [client 127.0.0.1] ModSecurity: Warning. Match of "rx ^apache.*perl" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/modsecurity2/modsecurity_crs_35_bad_robots.conf"] [line "29"] [id "990011"] [msg "Request Indicates an automated program explored the site"] [severity "NOTICE"] [tag "AUTOMATION/MISC"] [hostname "localhost"] [uri "/watch-list"] [unique_id "T-tpl1GpgkIAAD@pFY4AAAAA"]

I think it's the munin/monit daemon checking 127.0.0.1 for the apache service.
How can I allow it for 127.0.0.1 only? I don't want to uncomment te whole rule.

Sad I also get a error 500 when browsing my SVN with tortoise
(This post was last modified: 04-21-2008 06:40 AM by prale.)
04-21-2008 03:30 AM
Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
[HowTo] Mod Security on debian - hxbro - 03-28-2008, 01:10 AM
RE: Mod Security on debian - gOOvER - 03-28-2008, 01:53 AM
RE: Mod Security on debian - Viktor - 04-18-2008, 07:42 AM
RE: Mod Security on debian - prale - 04-19-2008, 08:59 AM
RE: Mod Security on debian - fulltilt - 04-19-2008, 07:51 PM
RE: Mod Security on debian - Viktor - 04-19-2008, 09:43 PM
RE: Mod Security on debian - fulltilt - 04-19-2008, 09:52 PM
RE: Mod Security on debian - Viktor - 04-19-2008, 10:23 PM
RE: Mod Security on debian - fulltilt - 04-19-2008, 10:38 PM
RE: Mod Security on debian - prale - 04-21-2008 03:30 AM
RE: Mod Security on debian - hxbro - 04-22-2008, 01:57 AM
RE: Mod Security on debian - hYemac - 05-03-2008, 11:08 AM
RE: Mod Security on debian - hxbro - 05-03-2008, 11:02 PM
RE: Mod Security on debian - Quemeros - 05-08-2008, 10:45 AM
RE: Mod Security on debian - mafia - 05-10-2008, 04:09 AM
RE: Mod Security on debian - Zothos - 05-10-2008, 04:52 AM
RE: Mod Security on debian - mafia - 05-10-2008, 06:25 PM
RE: Mod Security on debian - greatman - 05-12-2008, 02:15 AM
RE: Mod Security on debian - fulltilt - 05-12-2008, 08:41 PM
RE: Mod Security on debian - tassoman - 06-03-2008, 05:30 AM
RE: Mod Security on debian - DaSilva - 06-15-2008, 05:01 AM
RE: Mod Security on debian - Zothos - 06-15-2008, 06:02 PM
RE: [HowTo] Mod Security on debian - r3r3 - 12-24-2008, 12:20 AM
RE: [HowTo] Mod Security on debian - Lucan - 01-07-2009, 03:36 AM
RE: [HowTo] Mod Security on debian - Lucan - 10-25-2009, 09:26 PM
RE: [HowTo] Mod Security on debian - Lucan - 10-28-2009, 03:05 AM
RE: [HowTo] Mod Security on debian - Lucan - 11-01-2009, 02:23 AM

Forum Jump:


User(s) browsing this thread: 16 Guest(s)