We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The CRS rule 913100 is based on scanners-user-agents.data and this file contains lines with only a #. A user-agent with a # leads to a false positive.
#
Logs and dumps
See SpiderLabs/owasp-modsecurity-crs#1215
Notice: Be carefully to not leak any confidential information.
To Reproduce
Steps to reproduce the behavior:
curl -v localhost -H "User-Agent: Sogou Pic Spider/3.0(+http://www.sogou.com/docs/help/webmasters.htm#07)"
Expected behavior
All lines starting with # are being ignored like with ModSec 2.x.
The text was updated successfully, but these errors were encountered:
Hi @dune73
Thanks for the report. It seems like this is a duplicate of #1645. Do you mind sharing your findings there so we can better keep track of the issues?
Thanks.
Sorry, something went wrong.
Don't mind at all. Thanks for the pointer.
victorhora
No branches or pull requests
The CRS rule 913100 is based on scanners-user-agents.data and this file contains lines with only a
#
. A user-agent with a#
leads to a false positive.Logs and dumps
See SpiderLabs/owasp-modsecurity-crs#1215
Notice: Be carefully to not leak any confidential information.
To Reproduce
Steps to reproduce the behavior:
curl -v localhost -H "User-Agent: Sogou Pic Spider/3.0(+http://www.sogou.com/docs/help/webmasters.htm#07)"
Expected behavior
All lines starting with
#
are being ignored like with ModSec 2.x.The text was updated successfully, but these errors were encountered: