Skip to content

Feature/modsecurity v3.0.3#9

Merged
GustavoKatel merged 16 commits into
masterfrom
feature/modsecurity-v3.0.3
Apr 25, 2019
Merged

Feature/modsecurity v3.0.3#9
GustavoKatel merged 16 commits into
masterfrom
feature/modsecurity-v3.0.3

Conversation

@GustavoKatel

Copy link
Copy Markdown
Contributor

Initial support

Hamza Zerhouni and others added 16 commits April 18, 2019 10:14
The body size is misscalculated which cause a null byte transfert to Modsecurity e.g:

POST /wp-login.php HTTP/1.1
...
...

log=admin&pwd=admin&wp-submit=Log In&redirect_to=https://www.example.com/wp-admin/&testcookie=1

====

Matched "Operator `ValidadeByteRange\' with parameter `1-255\' against variable `ARGS:testcookie\' (Value: `1\\x00\' )
Signed-off-by: Gustavo Sampaio <gbritosampaio@gmail.com>
Signed-off-by: Gustavo Sampaio <gbritosampaio@gmail.com>
Signed-off-by: Gustavo Sampaio <gbritosampaio@gmail.com>
Signed-off-by: Gustavo Sampaio <gbritosampaio@gmail.com>
Signed-off-by: Gustavo Sampaio <gbritosampaio@gmail.com>
Signed-off-by: Gustavo Sampaio <gbritosampaio@gmail.com>
@GustavoKatel GustavoKatel merged commit e132b37 into master Apr 25, 2019
@GustavoKatel GustavoKatel deleted the feature/modsecurity-v3.0.3 branch April 25, 2019 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant