top of page
Search
rialakipeersatexde

Talking Drupal 172 – Ways to Rule Your Content Management System



A fresh installation of core rules will typically have some false alarms. In some special cases, namely at higher paranoia levels, there can be thousands of them. In the last tutorial, we saw a number of approaches for suppressing individual false alarms. It's always hard at the beginning. What we're missing is a strategy for coping with different kinds of false alarms. Reducing the number of false alarms is the prerequisite for lowering the Core Rule Set (CRS) anomaly threshold and this, in turn, is required in order to use ModSecurity to actually ward off attackers. And only after the false alarms really are disabled, or at least curtailed to a large extent, do we get a picture of the real attackers.




Talking Drupal 172 – Ways to Rule




So this is always the same URI. Let's exclude the parameter ids[] from being examined when it occurs in requests to this location. This boils down to a run-time exclusion rule. In the previous tutorial, we have seen that writing these kind of rules is cumbersome. It would be nice to have a script do the work for us. So, I created such a script: introducing modsec-rulereport.rb. It takes an alert message (or the error log in a more general sense) on STDIN and proposes one of many rules exclusions of different types (see modsec-rulereport.rb -h` for an overview). 2ff7e9595c


1 view0 comments

Recent Posts

See All

Happymod apk download gta 5

Happymod APK Baixar GTA 5: Como Jogar GTA 5 com Mods no Android Grand Theft Auto V (GTA 5) é um dos jogos de mundo aberto mais populares...

Como conseguir robux grátis

Como obter Robux grátis no Roblox 2023 Roblox é uma das plataformas de jogos online mais populares do mundo, com milhões de jogadores...

Comentários


bottom of page