Christian Folini

Results 38 issues of Christian Folini

### Motivation See the discussion in #2622. - Forward slashes (`/`) do not require an escaping backslash. All manually created regular expressions should use `/` instead of `\/` (note that...

PR available
cleanup

### Description See the following spreadsheet: * https://docs.google.com/spreadsheets/d/1OF6vt-YQRH7Vxmemp9QGrsEYWNvQ29zJZzGTl63faik/edit#gid=0 (Only visible for CRS team.) ### Your Environment Irrelevant ### Confirmation [X] I have removed any personal data (email addresses, IP addresses,...

False Negative - Evasion

### Describe the bug ``` # # -- [[ Collection timeout ]] -------------------------------------------------- # # Set the SecCollectionTimeout directive from the ModSecurity default (1 hour) # to a lower setting...

``` $ ./amass enum -v -src -ip -brute -min-for-recursive 2 -d example.com flag provided but not defined: -src $ ./amass enum -v -ip -brute -min-for-recursive 2 -d example.com flag provided...

https://en.wikipedia.org/wiki/ModSecurity

admin (OWASP transfer)

The security.md is very minimal and it also points to the Spiderlabs repo. This has to be updated and expanded.

admin (OWASP transfer)

Trustwave Spiderlabs has the following repos with a connection to ModSecurity. 4 of them have been transferred as of this writing (2024-01-28): * https://github.com/SpiderLabs/ModSecurity (has been transferred) * https://github.com/SpiderLabs/ModSecurity-nginx (has...

admin (OWASP transfer)

**Describe the bug** Instead of failing safely, ModSec triggers a status 500. ``` $ cat example.json { "id" : "123" $ curl -v http://localhost -H "Content-Type: application/json" -d @example.json ......

2.x

**Devs can fill in the meeting agenda here before the meeting:** https://github.com/coreruleset/coreruleset/wiki/Agenda-Next --- This is the Agenda for the two Monthly CRS Chats. The general chat is going to happen...

:bookmark: Meeting Agenda

This is the Agenda for the two Monthly CRS Chats. The general chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, 2024-02-05, at 20:30 CET. That's...

:bookmark: Meeting Agenda