Re: Backporting 1823047 for 2.4.30 / 2.4.3x?

2018-02-28 Thread Christian Folini
for your good work! Christian On Fri, Feb 16, 2018 at 12:56:40PM +0100, Yann Ylavic wrote: > On Fri, Feb 16, 2018 at 12:54 PM, Yann Ylavic <ylavic@gmail.com> wrote: > > On Fri, Feb 16, 2018 at 11:47 AM, Christian Folini > > <christian.fol...@netnea.com> wrote: >

Re: Backporting 1823047 for 2.4.30 / 2.4.3x?

2018-02-18 Thread Christian Folini
Hey Yann, On Fri, Feb 16, 2018 at 12:56:40PM +0100, Yann Ylavic wrote: > On Fri, Feb 16, 2018 at 12:54 PM, Yann Ylavic <ylavic@gmail.com> wrote: > > On Fri, Feb 16, 2018 at 11:47 AM, Christian Folini > > <christian.fol...@netnea.com> wrote: > >> > >&

Backporting 1823047 for 2.4.30 / 2.4.3x?

2018-02-16 Thread Christian Folini
will issue a new release as well. So if you could backport this for 2.4.30 or a following release, it would be very welcome. Best regards, Christian Folini -- https://www.feistyduck.com/training/modsecurity-training-course https://www.feistyduck.com/books/modsecurity-handbook/ mailto:christian.fol

Re: 2.4.27

2017-07-06 Thread Christian Folini
roxyFCGIBackendType, fixing a regression with PHP-FPM. PR 61202. > [Jacob Champion, Jim Jagielski] > > *) core: Avoid duplicate HEAD in Allow header. > This is a regression in 2.4.24 (unreleased), 2.4.25 and 2.4.26. > PR 61207. [Christophe Jaillet] > > >

Re: 2.4.27

2017-07-03 Thread Christian Folini
d help with the holiday schedule. Regards, Christian Folini -- Christian Folini - <christian.fol...@netnea.com>

Re: Tool to analyze and minimize loaded modules.

2017-05-18 Thread Christian Folini
r reducing the memory > footprint. > > Thanks, > > Mike Rumph -- Christian Folini - <christian.fol...@netnea.com>

Re: HTTP/1.1 strict ruleset

2016-08-03 Thread Christian Folini
n in this regard (but it would certainly take quite a while to get this out the door). Cheers, Christian Folini -- https://www.feistyduck.com/training/modsecurity-training-course mailto:christian.fol...@netnea.com twitter: @ChrFolini

Re: Allow SSLProxy* config in context?

2016-04-13 Thread Christian Folini
Rainer, There is a commercial apache-based reverse proxy in Switzerland (with substantial market share) which is able to use / create a client certificate _per_ session. So the client connects to the RP, performs authentication. When creating the session serverside, the RP creates a client cert

Re: reverse proxy wishlist

2015-12-05 Thread Christian Folini
for ProxyErrorOverride AFAICT. Ahoj, Christian Folini -- Christian Folini - <christian.fol...@netnea.com>

Re: "httpd -X" segfaults with 2.4.17

2015-10-16 Thread Christian Folini
Works fine here with event. At least so far. Ahoj, Christian Folini -- The test of every religious, political, or educational system is the man which it forms. -- Henri-Frédéric Amiel

Re: Expression Parser: search and replace with s/PATTERN/REPLACEMENT/FLAGS

2015-10-01 Thread Christian Folini
lable within the expression parser would simplify things a lot (and get rid of timing and hook precedence issues). Ahoj, Christian Folini -- Christian Folini - <christian.fol...@netnea.com>

Re: mod_lua: Accessing multiple Set-Cookie response headers

2015-05-18 Thread Christian Folini
, 2015 at 06:58:15PM +0200, Daniel Gruno wrote: This should really go to users@, but anyway... You might want to take a look at: http://modlua.org/api/builtin#getcookie http://modlua.org/api/builtin#setcookie With regards, Daniel. On 2015-05-18 16:53, Christian Folini wrote: Hello

2.2.25 build problem (was: Re: svn commit: r1497466 - in /httpd/httpd/branches/2.2.x: CHANGES STATUS modules/ssl/ssl_engine_io.c)

2013-07-09 Thread Christian Folini
to be fixed before the release? Rainer's proposed patch worked here. Regs, Christian Folini -- Christian Folini - christian.fol...@netnea.com

Re: URL scanning by bots

2013-05-02 Thread Christian Folini
On Fri, May 03, 2013 at 09:39:44AM +1000, Noel Butler wrote: real-time blacklist lookup (- ModSecurity's @rbl operator). Try using that on busy servers (webhosts/ISP's)... might be fine for a SOHO, but in a larger commercial world, forget it, the impact is far far worse than the other

Re: URL scanning by bots

2013-05-01 Thread Christian Folini
this configured, but I would be really interested to see the effect on average load, connection use and number of scanning attempts on a server. Interesting discussion by the way. Maybe a bit hot, though. Best, Christian Folini -- We have to remember that what we observe is not nature herself, but nature

Re: URL scanning by bots

2013-04-30 Thread Christian Folini
professionally. -- Christian Folini - christian.fol...@netnea.com

Re: Add bandwidth information to access_log

2013-01-18 Thread Christian Folini
timestamps but it is still possible to get a value which more or less represents up- and downstream bandwidth. Still, you should not trust it too much. Regs, Christian Folini -- Christian Folini - christian.fol...@netnea.com

Re: Add bandwidth information to access_log

2013-01-18 Thread Christian Folini
mailinglist for help. This list is for httpd development. Cheers, Christian Folini Then you should turn to the ModSecurity On Fri, Jan 18, 2013 at 09:33:04AM +, Chau Pham wrote: Thank you, I saw this line below in access log while it was playing m3u3 file, one of chunk below. 172.16.33.168

Re: Rethinking be liberal in what you accept

2012-11-08 Thread Christian Folini
in a request, a bogus request line may pass beneath the threshold of the Core-Rules. A simple, single directive to stop any protocol violations once and for all is preferable in my eyes. regs, Christian Folini -Original Message- From: Stefan Fritsch Sent: Wednesday, November 7, 2012 12:26

Re: Proposal: adoption of mod_firehose subproject

2011-12-13 Thread Christian Folini
this problem too. Regards, Christian Folini -- First you make it, then it works, then you invite people to make it better. -- Eben Moglen, Free Software Foundation

A timestamp for mod_log_forensic (?)

2011-03-30 Thread Christian Folini
|yQtJf8CoAB4AAFNXBIEA|GET /manual/de/ ... or +yQtJf8CoAB4AAFNXBIEA|956166333.123456|GET /manual/de/ ... or +yQtJf8CoAB4AAFNXBIEA|GET /manual/de/ ... |956166333.123456| Best regards, Christian Folini -- Christian Folini - christian.fol...@netnea.com

Re: A timestamp for mod_log_forensic (?)

2011-03-30 Thread Christian Folini
timestamp patch for mod_log_forensic for future convenience. regs, Christian -- Christian Folini - christian.fol...@netnea.com

Re: [PATCH] Logging the handler in the access log

2010-02-01 Thread Christian Folini
On Tue, Feb 02, 2010 at 12:06:33AM +0200, Graham Leggett wrote: On 01 Feb 2010, at 10:59 PM, Christian Folini wrote: Sure. Here you go: Committed to trunk, and proposed for backport to v2.2. Thanks for this. My pleasure. Thank you. Best, Christian -- We must be diligent, we must keep

[PATCH] Logging the handler in the access log

2010-01-31 Thread Christian Folini
Hello all, In a heterogenous setup with multiple servers and reverse proxies, life can be a burden. At times, the access log could help by sharing some insight on the handler involved with the response. Unfortunately, mod_log_config does not give an easy way to log this information. Therefore

Re: [Fwd: Slowloris]

2009-06-22 Thread Christian Folini
or a single post payload byte is not resetting them to zero again. Just my 2 cents Christian Folini -- If you shut your door to all errors truth will be shut out. --- Rabindranath Tagore

Problems with SSL environment variable SSL_CLIENT_CERT as http header

2005-12-12 Thread Christian Folini
is: Is this a missing feature or a bug? Does it ring a bell? Or is there someone who can point out a better way, how to pass on the certificate to the backend application? best regards, Christian -- Christian Folini - [EMAIL PROTECTED]