Ervin Hegedus

Results 605 comments of Ervin Hegedus

Hi @swagliquido, thanks for reporting. Could you share your `error.log` when you send the first two requests? This rule adds `tx.critical_anomaly_score` points to the anomaly score `TX` variable (that's normally...

@swagliquido ping.

> ``` >-------- Installing package libiconv/1.17 (14 of 21) -------- > ``` That's very interesting. As I know there is no any dependency to iconv, so I have no idea...

> I also attempted to compile the x86 (32-bit) inside the docker image which also failed with libiconv errors. But again when compiling the x64 version iconv does not show...

Hi @linwaiwai, many thanks for this detailed explanation. I think we must add this to our Wiki pages.

Hi @wRkA, thanks for reporting this issue. After a quick review, I'm afraid this is a [connector](https://github.com/owasp-modsecurity/ModSecurity-nginx) issue. I run my WAF instance through `gdb` and I realized that Nginx...

> Do you have some feedback about this problem? @cello86 could you take a look at the #3917? Probably you could pick up that modification and try it (I think...

Hi @isniukArte, thanks for detailed reporting. I can confirm, any request with this `User-Agent` header triggers rule [942200](https://github.com/coreruleset/coreruleset/blob/main/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf#L823-L850). Based on this [RFC](https://www.rfc-editor.org/rfc/rfc7231#page-46), I don't think this is a false positive...

Hi @admiral504, you've tagged this issue with `2.x`, but as I know OpenLiteSpeed uses libmodsecurity3 - doesn't it? Btw. would you take a look to our [issue template](https://github.com/owasp-modsecurity/ModSecurity/blob/v3/master/.github/ISSUE_TEMPLATE/bug-report-for-version-3-x.md), and fill...

> I found in /usr/local/lsws/logs/error.log > > `2024-06-10 12:33:01.730873 [NOTICE] Loading LiteSpeed/1.7.19 Open (lsquic 3.3.2, modgzip 1.1, cache 1.66, mod_security 1.4 (with libmodsecurity v3.0.12)) BUILD (built: Tue Apr 16 15:14:26...