关于 modsecurity 的疑问

2016-08-08 19:05:24 +08:00
 linus

[root@xxx waf-fle-0.6.3]# /etc/init.d/mlog2waffle start Starting mlog2waffle... Starting up mlog2waffle in "tail" mode, using config file /etc/mlog2waffle.conf Error in HTTP connection: 403 Forbidden [FAILED]

tailf /var/log/httpd/modsec_debug.log
[08/Aug/2016:18:59:47 +0800] [maf/sid#7f937f876850][rid#7f93804cf8a8][/controller/][1] Access denied with code 403 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/crs/owasp-modsecurity-crs/base_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "84"] [id "960904"] [rev "2"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"]

3765 次点击
所在节点    信息安全
0 条回复

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/297949

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX