Hi Stefan,
Are you sure, it is CRS blocking this? The single alert you posted below bring
you to a score of 5 and that's far from the 1,000 which you set. Also, the
rule itself only says "ModSecurity: Warning" which is a deadsure indicator
that it was not _this_ rule that blocked the request (so the behaviour is
exactly what you said you configured). With this being said, here are some
thoughts:
- What is the total score of this request. Have you configured an extended
access log that tells you the total score of every request. If not, this
would be helpful here.
If not, look for rule 949110 with the same request-id. It should bring
you the score too.
- It is not always CRS which blocks. Often it is one of the recommended rules
(range 200,000+) or one of the limits. However, I do not think 920420
would trigger in that situation. Said rules and limits would be faster
usually.
So I do not really know, but maybe you can still use these idea.
Best,
Christian
P.S. I have raised the proposed default anomaly threshold from 1,000 to
10,000 in my tutorials at
netnea.com.
> --
> You received this message because you are subscribed to the Google Groups "ModSecurity Core Rule Set project" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to
modsecurity-core-rule-...@owasp.org.
> To post to this group, send email to
modsecurity-core...@owasp.org.
> Visit this group at
https://groups.google.com/a/owasp.org/group/modsecurity-core-rule-set-project/.
> To view this discussion on the web visit
https://groups.google.com/a/owasp.org/d/msgid/modsecurity-core-rule-set-project/4a0fa265-c4bf-47b6-a0bf-5260977da858%40owasp.org.
> For more options, visit
https://groups.google.com/a/owasp.org/d/optout.