Hi everybody, I think the rule 910100 should be moved to the paranoia mode and the list of countries should be revised. Or the rule stays in normal mode and the list of countries is emtpy.
Regards, Franziska 2016-02-17 16:01 GMT+01:00 Leos Rivas Manuel <manuel.leosri...@gemalto.com>: > Hi all, > > > > I would prefer to have it commented and or in paranoia level >=3 > > > > Regards, > > Manuel > > > > From: owasp-modsecurity-core-rule-set-boun...@lists.owasp.org > [mailto:owasp-modsecurity-core-rule-set-boun...@lists.owasp.org] On Behalf > Of Chaim Sanders > Sent: mercredi 17 février 2016 15:21 > To: Walter Hop > Cc: owasp-modsecurity-core-rule-set@lists.owasp.org > Subject: Re: [Owasp-modsecurity-core-rule-set] Paranoia Mode: Forgotten > controversial candidate 900050 / 910100 (Client IP is from a HIGH Risk > Country Location) > > > > So what's the decision here? > > > Comment it out? Put it in paranoid? Leave only a smaller subset? > > On Feb 15, 2016 5:21 PM, Walter Hop <mod...@spam.lifeforms.nl> wrote: > > I think the source is an article from 2003, which explains why Yugoslavia is > in the list: > > http://citeseerx.ist.psu.edu/viewdoc/download;jsessionid=2A684B6B2B6E99D03F578D3296E05483?doi=10.1.1.198.9996&rep=rep1&type=pdf > > > > (Just to correct, I didn’t want to keep the rule enabled by default, but > instead I’d rather comment it as an example.) > > > > > > On 15 Feb 2016, at 21:55, iul...@sphere.ro wrote: > > > > Dears, > > I am just wondering on what basis you are considering these countries to be > potentially risky? > > Even if those are risky simply putting these on default will be a mistake. > Most people don't read the configuration file or don't fully understand > every feature and just stick with the default configuration. > > If you want advanced protection then you are forced to make changes or even > make your own rules. > > Best regards, > Iulian > > > On February 15, 2016 10:17:35 PM GMT+02:00, Christian Folini > <christian.fol...@netnea.com> wrote: > > Chaim, > > I see you and Walter agreeing on the idea to keep the rule around > in standard mode. I would probably still comment out the default > country list - but that's a different question. > > I've removed the rule from the list of paranoia candidates. > > Btw: The country list involves China, but the documentation does not > name China (but all the other countried). > > Cheers, > > Christian > > > On Mon, Feb 15, 2016 at 04:19:44AM +0000, Chaim Sanders wrote: > > In general I like to assume that if people are going to get caught by > something blocking unintentionally it will be a configuration from the > configuration file, as they are supposed to be reading those :-). I > honestly haven¹t heard many complaints about this feature and as a result > I¹d probably leave it enabled as it as sad as it is, is fairly effective. > > On 2/13/16, 12:30 AM, > "owasp-modsecurity-core-rule-set-boun...@lists.owasp.org on behalf of > Christian Folini" <owasp-modsecurity-core-rule-set-boun...@lists.owasp.org > on behalf of christian.fol...@netnea.com> wrote: > > Hi there, > > It seems I overlooked this candidate, where Franziska said she is unsure > whether we should blog certain countries in a default installation or > not. > > The rule does: > SecRule GEO:COUNTRY_CODE "@pm %{tx.high_risk_country_codes}" > > With tx.high_risk_country_codes being set to > "UA ID YU LT EG RO BG TR RU PK MY CN" > in modsecurity_crs_10_setup.conf.example. > > Depending on your location, requests from the given set of > countried may be desired and not potential attacks. So I t hink > Franziska has a point. > > One resolution would be to leave the rule where it is, but comment > out the definition of the variable in > modsecurity_crs_10_setup.conf.example > and provide multiple default variants in the comments. > That could also be performed in combination with the move to > the paranoia mode. > > Opinions? > > Christian > > > -- > The problem is, if you're not a hacker, > you can't tell who the good hackers are. > --- Paul Graham > > ________________________________ > > > Owasp-modsecurity-core-rule-set mailing list > Owasp-modsecurity-core-rule-set@lists.owasp.org > http://scanmail.trustwave.com/?c=4062&d=5sS-1i1jGNzLWl4_4Oku6bhM-zSgEVOp-i > xlzEmHDg&s=5&u=https%3a%2f%2flists%2eowasp%2eorg%2fmailman%2flistinfo%2fow > asp-modsecurity-core-rule-set > > > > ________________________________ > > > > This trans mission may contain information that is privileged, confidential, > and/or exempt from disclosure under applicable law. If you are not the > intended recipient, you are hereby notified that any disclosure, copying, > distribution, or use of the information contained herein (including any > reliance thereon) is strictly prohibited. If you received this transmission > in error, please immediately contact the sender and destroy the material in > its entirety, whether in electronic or hard copy format. > > > -- > Sent from my Android device with K-9 Mail. Please excuse my brevity. > > _______________________________________________ > Owasp-modsecurity-core-rule-set mailing list > Owasp-modsecurity-core-rule-set@lists.owasp.org > https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set > > > > -- > Walter Hop | PGP key: https://lifeforms.nl/pgp > > > > > > ________________________________ > > > This transmission may contain information that is privileged, confidential, > and/or exempt from disclosure under applicable law. If you are not the > intended recipient, you are hereby notified that any disclosure, copying, > distribution, or use of the information contained herein (including any > reliance thereon) is strictly prohibited. If you received this transmission > in error, please immediately contact the sender and destroy the material in > its entirety, whether in electronic or hard copy format. > > ________________________________ > This message and any attachments are intended solely for the addressees and > may contain confidential information. Any unauthorized use or disclosure, > either whole or partial, is prohibited. > E-mails are susceptible to alteration. Our company shall not be liable for > the message if altered, changed or falsified. If you are not the intended > recipient of this message, please delete it and notify the sender. > Although all reasonable efforts have been made to keep this transmission > free from viruses, the sender will not be liable for damages caused by a > transmitted virus. > > _______________________________________________ > Owasp-modsecurity-core-rule-set mailing list > Owasp-modsecurity-core-rule-set@lists.owasp.org > https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set > _______________________________________________ Owasp-modsecurity-core-rule-set mailing list Owasp-modsecurity-core-rule-set@lists.owasp.org https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set