hi,
im using latest modsecurity rule set and i tried out crs_11_bruteforce from
experimental rule. But its not working for me. I created a shortlink of it
in the activated rules directory, restarted the apache and when i brute
force my web application login page the modsecurity audit log dont give me
any brute force warnings. what could be the problem? Im using burp suite
pro version's intruder for brute forcing.
can anyone point to helpful resource that i can follow?

thanks.

regards
sabin
_______________________________________________
Owasp-modsecurity-core-rule-set mailing list
Owasp-modsecurity-core-rule-set@lists.owasp.org
https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set

Reply via email to