Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
more apache/php
#52
Quote:<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentcommentid="15628" data-ipsquote-username="Dungeon-Dave" data-cite="Dungeon-Dave" data-ipsquote-timestamp="1322579643" data-ipsquote-contentapp="forums" data-ipsquote-contenttype="forums" data-ipsquote-contentid="4150" data-ipsquote-contentclass="forums_Topic"><div>
When I've been debugging mod_sec, I find that a tail of that logfile when a site breaks on me shows what's tripping it (rule name, ID, etc).

 

Note that - in terms of vulnerabilities - disclosure of information is not insecure in itself. How that information is used to enumerate and select an exploit is.

 

Concealing the fact you're using a version of PHP does not make that version secure, it just means a cracker will take longer to choose an appropriate attack vector.
 

Seems like my mod_security is working :)

 

# tail /home/www/feedmebits.nl/logs/error.log

[Thu Dec 01 15:42:56 2011] [error] [client 145.117.85.40] File does not exist: /home/www/feedmebits.nl/htdocs/login

[sat Dec 03 16:58:54 2011] [error] [client 94.24.41.240] ModSecurity: [file "/etc/httpd/modsecurity.d/asl/modsec/00_asl_rbl.conf"] [line "48"] [id "350000"] [rev "2"] [msg "Global RBL Match: IP is on the xbl.spamhaus.org Blacklist (Report False Positives to www.spamhaus.org)"] [severity "ERROR"] Access denied with code 403 (phase 1). RBL lookup of 240.41.24.94.xbl.spamhaus.org succeeded at REMOTE_ADDR (Illegal 3rd party exploits). [hostname "62.212.66.15"] [uri "/admin/cdr/counter.txt"] [unique_id "TtpHPj7UQg8AAC-4NEcAAAAF"]

 

Still working on my fail2ban. But looking at this seems like mod_security is giving me some protection :)

 

Look also at your modsec_audit_log and modsec_debug_log - they should have more detailed info.



</div></blockquote>
Reply


Messages In This Thread
more apache/php - by inittux - 2011-09-06, 06:25 AM
more apache/php - by Dungeon-Dave - 2011-09-07, 07:14 AM
more apache/php - by inittux - 2011-09-09, 06:17 AM
more apache/php - by inittux - 2011-09-10, 03:43 PM
more apache/php - by Dungeon-Dave - 2011-09-11, 01:40 PM
more apache/php - by inittux - 2011-09-11, 01:54 PM
more apache/php - by Dungeon-Dave - 2011-09-11, 03:49 PM
more apache/php - by inittux - 2011-09-11, 03:58 PM
more apache/php - by Dungeon-Dave - 2011-09-11, 05:12 PM
more apache/php - by inittux - 2011-09-12, 06:09 AM
more apache/php - by Dungeon-Dave - 2011-09-12, 12:30 PM
more apache/php - by inittux - 2011-09-13, 06:12 AM
more apache/php - by inittux - 2011-09-13, 08:47 AM
more apache/php - by Dungeon-Dave - 2011-09-13, 10:58 AM
more apache/php - by inittux - 2011-09-13, 11:43 AM
more apache/php - by inittux - 2011-09-14, 07:02 AM
more apache/php - by Dungeon-Dave - 2011-09-14, 10:49 AM
more apache/php - by inittux - 2011-09-14, 05:40 PM
more apache/php - by inittux - 2011-09-14, 07:27 PM
more apache/php - by Dungeon-Dave - 2011-09-14, 07:28 PM
more apache/php - by inittux - 2011-09-14, 07:33 PM
more apache/php - by inittux - 2011-09-15, 05:08 AM
more apache/php - by inittux - 2011-09-18, 06:40 PM
more apache/php - by Dungeon-Dave - 2011-09-19, 05:44 PM
more apache/php - by inittux - 2011-09-19, 05:50 PM
more apache/php - by inittux - 2011-09-20, 04:57 PM
more apache/php - by Dungeon-Dave - 2011-09-21, 07:42 PM
more apache/php - by inittux - 2011-09-22, 02:39 PM
more apache/php - by inittux - 2011-09-22, 05:12 PM
more apache/php - by inittux - 2011-10-06, 10:43 AM
more apache/php - by Dungeon-Dave - 2011-10-07, 02:21 PM
more apache/php - by inittux - 2011-10-08, 07:11 AM
more apache/php - by Dungeon-Dave - 2011-10-08, 01:00 PM
more apache/php - by inittux - 2011-10-08, 01:06 PM
more apache/php - by inittux - 2011-10-11, 07:42 AM
more apache/php - by Dungeon-Dave - 2011-10-11, 01:33 PM
more apache/php - by inittux - 2011-10-12, 10:34 AM
more apache/php - by Dungeon-Dave - 2011-10-13, 11:41 AM
more apache/php - by inittux - 2011-10-13, 11:46 AM
more apache/php - by Dungeon-Dave - 2011-10-13, 04:47 PM
more apache/php - by inittux - 2011-11-01, 03:11 PM
more apache/php - by inittux - 2011-11-28, 09:56 PM
more apache/php - by hybrid - 2011-11-29, 10:48 AM
more apache/php - by inittux - 2011-11-29, 11:17 AM
more apache/php - by hybrid - 2011-11-29, 11:21 AM
more apache/php - by inittux - 2011-11-29, 11:34 AM
more apache/php - by hybrid - 2011-11-29, 11:40 AM
more apache/php - by Dungeon-Dave - 2011-11-29, 02:43 PM
more apache/php - by inittux - 2011-11-29, 02:51 PM
more apache/php - by Dungeon-Dave - 2011-11-29, 03:14 PM
more apache/php - by inittux - 2011-12-14, 11:07 AM
more apache/php - by Dungeon-Dave - 2011-12-14, 10:06 PM
more apache/php - by inittux - 2011-12-14, 10:17 PM
more apache/php - by Dungeon-Dave - 2011-12-15, 01:58 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)