-
Notifications
You must be signed in to change notification settings - Fork 1.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Apache error_log not showing "ModSecurity: Access denied" when they exist in modsec_audit.log #3355
Comments
Please tell us about your exact engine version and the platform. As this seems to be ModSec 3, the connector version is also important. And finally: A curl call to reproduce the behavior shown above would be perfect. Also: This was all part of the bug template. Yet you removed it. |
Hi @dune73 , thank you, I've updated my original post with those details. Yes it with Mod Security 3
How can I check the connector version? Cheers |
Hi @airween, thanks. I was experimenting with v3 due to an issue with v2, which I think I've only just now resolved after a rebuild, I'm just running some tests. |
thanks - is there anything that we can do here? If not, could we close this issue? |
@airween would you like me to build the latest v3 and run a test to see if the issue persists? |
Every tests are welcome and big help, so yes, thank you. But I think the result won't be clear, I mean if there will be any issue, we can't decide what is the root cause: library or the connector. But let's see. |
I've run into some issues trying to get the new version working with my stack, so can't do any further testing. |
Mod Security 3
I've an issue where the apache error_log isn't containing the ModSecurity: Access denied record as shown in the modsec_audit.log.
If I do not change any config, and just use modsecurity2, then it works fine, and the error_log contains the Access denied record
Any ideas why it missing?
Operating System
Bitnami package for WordPress 6.6.2-11
Debian GNU/Linux 12 (bookworm)
Curl Command
curl https://IP/?foo=/etc/passwd&bar=/bin/sh
modsec_audit.log
error_log
Rule Set (please complete the following information):
coreruleset-4.11.0-minimal
Thank you!
The text was updated successfully, but these errors were encountered: