Hi all,

I would prefer to have it commented and or in paranoia level >=3

Regards,
Manuel

From: owasp-modsecurity-core-rule-set-boun...@lists.owasp.org 
[mailto:owasp-modsecurity-core-rule-set-boun...@lists.owasp.org] On Behalf Of 
Chaim Sanders
Sent: mercredi 17 février 2016 15:21
To: Walter Hop
Cc: owasp-modsecurity-core-rule-set@lists.owasp.org
Subject: Re: [Owasp-modsecurity-core-rule-set] Paranoia Mode: Forgotten 
controversial candidate 900050 / 910100 (Client IP is from a HIGH Risk Country 
Location)


So what's the decision here?
Comment it out? Put it in paranoid? Leave only a smaller subset?
On Feb 15, 2016 5:21 PM, Walter Hop 
<mod...@spam.lifeforms.nl<mailto:mod...@spam.lifeforms.nl>> wrote:
I think the source is an article from 2003, which explains why Yugoslavia is in 
the list:
http://citeseerx.ist.psu.edu/viewdoc/download;jsessionid=2A684B6B2B6E99D03F578D3296E05483?doi=10.1.1.198.9996&rep=rep1&type=pdf<http://scanmail.trustwave.com/?c=4062&d=9s_C1g9Xm4csjNFXCLkV562M7S5Kl2BVHTbgHImsVQ&s=5&u=http%3a%2f%2fciteseerx%2eist%2epsu%2eedu%2fviewdoc%2fdownload%3bjsessionid%3d2A684B6B2B6E99D03F578D3296E05483%3fdoi%3d10%2e1%2e1%2e198%2e9996%26rep%3drep1%26type%3dpdf>

(Just to correct, I didn’t want to keep the rule enabled by default, but 
instead I’d rather comment it as an example.)


On 15 Feb 2016, at 21:55, iul...@sphere.ro<mailto:iul...@sphere.ro> wrote:

Dears,

I am just wondering on what basis you are considering these countries to be 
potentially risky?

Even if those are risky simply putting these on default will be a mistake.
Most people don't read the configuration file or don't fully understand every 
feature and just stick with the default configuration.

If you want advanced protection then you are forced to make changes or even 
make your own rules.

Best regards,
Iulian


On February 15, 2016 10:17:35 PM GMT+02:00, Christian Folini 
<christian.fol...@netnea.com<mailto:christian.fol...@netnea.com>> wrote:

Chaim,

I see you and Walter agreeing on the idea to keep the rule around
in standard mode. I would probably still comment out the default
country list - but that's a different question.

I've removed the rule from the list of paranoia candidates.

Btw: The country list involves China, but the documentation does not
name China (but all the other countried).

Cheers,

Christian


On Mon, Feb 15, 2016 at 04:19:44AM +0000, Chaim Sanders wrote:
In general I like to assume that if people are going to get caught by
something blocking unintentionally it will be a configuration from the
configuration file, as they are supposed to be reading those :-). I
honestly haven¹t heard many complaints about this feature and as a result
I¹d probably leave it enabled as it as sad as it is, is fairly effective.

On 2/13/16, 12:30 AM,
"owasp-modsecurity-core-rule-set-boun...@lists.owasp.org<mailto:owasp-modsecurity-core-rule-set-boun...@lists.owasp.org>
 on behalf of
Christian Folini" 
<owasp-modsecurity-core-rule-set-boun...@lists.owasp.org<mailto:owasp-modsecurity-core-rule-set-boun...@lists.owasp.org>
on behalf of christian.fol...@netnea.com<mailto:christian.fol...@netnea.com>> 
wrote:
Hi there,

It seems I overlooked this candidate, where Franziska said she is unsure
whether we should blog certain countries in a default installation or
not.

The rule does:
SecRule GEO:COUNTRY_CODE "@pm %{tx.high_risk_country_codes}"

With tx.high_risk_country_codes being set to
"UA ID YU LT EG RO BG TR RU PK MY CN"
in modsecurity_crs_10_setup.conf.example.

Depending on your location, requests from the given set of
countried may be desired and not potential attacks. So I t hink
Franziska has a point.

One resolution would be to leave the rule where it is, but comment
out the definition of the variable in
modsecurity_crs_10_setup.conf.example
and provide multiple default variants in the comments.
That could also be performed in combination with the move to
the paranoia mode.

Opinions?

Christian


--
The problem is, if you're not a hacker,
you can't tell who the good hackers are.
--- Paul Graham
________________________________

Owasp-modsecurity-core-rule-set mailing list
Owasp-modsecurity-core-rule-set@lists.owasp.org<mailto:Owasp-modsecurity-core-rule-set@lists.owasp.org>
http://scanmail.trustwave.com/?c=4062&d=5sS-1i1jGNzLWl4_4Oku6bhM-zSgEVOp-i
xlzEmHDg&s=5&u=https%3a%2f%2flists%2eowasp%2eorg%2fmailman%2flistinfo%2fow
asp-modsecurity-core-rule-set

________________________________


This trans mission may contain information that is privileged, confidential, 
and/or exempt from disclosure under applicable law. If you are not the intended 
recipient, you are hereby notified that any disclosure, copying, distribution, 
or use of the information contained herein (including any reliance thereon) is 
strictly prohibited. If you received this transmission in error, please 
immediately contact the sender and destroy the material in its entirety, 
whether in electronic or hard copy format.

--
Sent from my Android device with K-9 Mail. Please excuse my brevity.
_______________________________________________
Owasp-modsecurity-core-rule-set mailing list
Owasp-modsecurity-core-rule-set@lists.owasp.org<mailto:Owasp-modsecurity-core-rule-set@lists.owasp.org>
https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set<http://scanmail.trustwave.com/?c=4062&d=9s_C1g9Xm4csjNFXCLkV562M7S5Kl2BVHWflQNr-XA&s=5&u=https%3a%2f%2flists%2eowasp%2eorg%2fmailman%2flistinfo%2fowasp-modsecurity-core-rule-set>

--
Walter Hop | PGP key: 
https://lifeforms.nl/pgp<http://scanmail.trustwave.com/?c=4062&d=9s_C1g9Xm4csjNFXCLkV562M7S5Kl2BVHWXmSdyvUw&s=5&u=https%3a%2f%2flifeforms%2enl%2fpgp>


________________________________

This transmission may contain information that is privileged, confidential, 
and/or exempt from disclosure under applicable law. If you are not the intended 
recipient, you are hereby notified that any disclosure, copying, distribution, 
or use of the information contained herein (including any reliance thereon) is 
strictly prohibited. If you received this transmission in error, please 
immediately contact the sender and destroy the material in its entirety, 
whether in electronic or hard copy format.
________________________________
This message and any attachments are intended solely for the addressees and may 
contain confidential information. Any unauthorized use or disclosure, either 
whole or partial, is prohibited.
E-mails are susceptible to alteration. Our company shall not be liable for the 
message if altered, changed or falsified. If you are not the intended recipient 
of this message, please delete it and notify the sender.
Although all reasonable efforts have been made to keep this transmission free 
from viruses, the sender will not be liable for damages caused by a transmitted 
virus.
_______________________________________________
Owasp-modsecurity-core-rule-set mailing list
Owasp-modsecurity-core-rule-set@lists.owasp.org
https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set

Reply via email to