ModSecurity SecRule,从任何检查中排除URL

问题描述 投票:0回答:1

ModSecurity尝试打开URL时误报:https://www.galgani.it/solitudine-contesti-virtuali-internet-facebook-social-network-smartphone/solitudine-e-contesti-virtuali.html

返回403错误。

这只是一个简单的静态html页面,没有javascript或动态代码。

ModSecurity在我的其他页面上工作正常。在/etc/modsecurity/modsecurity.conf中,我可以将哪个规则添加到该特定网址的白名单(或排除在白名单之外?)>

错误是:

[Fri Mar 27 14:54:50.189006 2020] [:error] [pid 10566:tid 140214542481152] [client 91.252.113.190:26752] [client 91.252.113.190] ModSecurity: Warning. Operator GE matched 4 at TX:outbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "82"] [id "980140"] [msg "Outbound Anomaly Score Exceeded (score 4): PHP source code leakage"] [tag "event-correlation"] [hostname "www.galgani.it"] [uri "/solitudine-contesti-virtuali-internet-facebook-social-network-smartphone/solitudine-e-contesti-virtuali.html"] [unique_id "Xn4FqfNLERK@02hvkdmOogAAAFI"]

ModSecurity在尝试打开URL时存在误报:https://www.galgani.it/solitudine-contesti-virtuali-internet-facebook-social-network-smartphone/solitudine-e-contesti-virtuali.html ...

mod-security
1个回答
0
投票

已解决!要插入特定网址的/etc/modsecurity/modsecurity.conf规则是:

© www.soinside.com 2019 - 2024. All rights reserved.