[Modsecurity] Breach core rules blocks plesk API and others
segun
Segun at Combotek.com
Tue Aug 14 12:46:58 EDT 2007
I just set up modsecurity 2.1.2 on a FC6 running plesk 8.2 replacing my 1.9 version. I am currently getting 2 false positives when I use the blocking rules. The core rule mod-security_cvs_21_protocol_anomalies blocks Plesk API from communicating with other applications i.e SiteBuilder module.
Another rule mod-security_cvs_30_http_policy prevent our clients from using a web gallery admin tool, a flash application used to upload pictures to a dynamic flash gallery. I don't know how to go about defining the exclusions for the Breach rule, can I use my old 1.9 exclusion rule? And is it better to use the Breach core rules or gotroot rules?
More information about the Modsecurity
mailing list