×÷ÕߣººÚÉ«ÒøÔÂ
Ê×ÏÈÒª¸ÐлһÏ ³É¶¼-feeling£¬Ã»ÓÐËûµÄÈÈÐİïÖú£¬Õâ¸öÎÊÌâÎÒÏëÎÒÊÇ»ù±¾½â¾ö²»ÁËÁË¡£ÔÙ´ÎÖÔÐĵĸÐл¡£
ÕâÁ½Ì칫˾µÄ·þÎñÆ÷×°ÁËfedora8 £¬µ«ÊÇ֮ǰµÄϵͳÔÚlinuxÏÂÈ´²»ÄÜÕý³£µÄÖ´ÐУ¬Ê×ÏÈ£¬·þÎñÆ÷Ö»ÄÜÓÃÓòÃû·ÃÎÊ£¬²»ÄÜÓÃIP·ÃÎÊ£¬È»ºó£¬ËùÓÐ±íµ¥POSTµÄÌá½»£¨submit£©¶¼²»ÄÜÖ´ÐУ¬ÔÚÓ¢ÎÄ»·¾³ÏÂÓÐЩ¿ÉÒÔ£¬µ«ÊÇÔÚÖÐÎÄ»·¾³Ï¶¼²»¿ÉÒÔ£¬²»¹ÜÊǼòÖл¹ÊÇ·±ÖУ¬¶ÔÓÚÕâ¸öÎÊÌ⣬ÓôÃÆÁËÒ»´óÉÏÎ磬¿ÉÊÇ»¹ÊÇûÓнâ¾ö¡£
ÖÕÓÚÔÚ ³É¶¼-feeling µÄ°ïÖúÏ£¬¸ã¶¨ÁËÕâ¸öÎÊÌâ¡£
ÏÐÑÔÉÙÐ𣬽øÈëÕûÌ壬ÏÂÃæÊǽâ¾ö·½·¨£º
IP²»ÄÜ·ÃÎʽâ¾ö£º
modsecurity_crs_21_protocol_anomalies.conf µÚ55ÐÐÊ×¼ÓÉÏÒ»¸ö#
55ÐÐÄÚÈÝ£ºSecRule REQUEST_HEADERS:Host "^[\d\.]+$" "deny,log,auditlog,status:400,msg:'Host header is a numeric IP address', severity:'2',,id:'960017',"
POST´íÎó£º
ÒòΪûÓдíÎóÐÅÏ¢£¬ÎÒ²»ÖªµÀÊDz»ÊÇÕâ¸ö£º
modsecurity_crs_20_protocol_violations.conf µÚ52Ðк͵Ú53ÐÐÐÐÊ×¼ÓÉÏ#
52ÐÐÄÚÈÝ£ºSecRule REQUEST_METHOD "^POST$" "chain,deny,log,auditlog,status:400,msg:'POST request must have a Content-Length header',,id:'960012',severity:'4'"
53ÐÐÄÚÈÝ£ºSecRule &REQUEST_HEADERS:Content-Length "@eq 0"
Èç¹û»¹ÊDz»ÐУ¬¸É´àÖ±½Ó±à¼
modsecurity_crs_10_config.confµÄµÚ53ÐУ¬½« On ¸ÄΪ Off
53ÐÐÄÚÈÝ£ºSecRuleEngine On
È»ºóÖØÆôapache£ºservice httpd restart
¿´À´linux»¹ÓкÜÔ¶µÄ·Ҫ×ߣ¬LAMP£¬long£¬long
leaf1988 ÓÚ 2008-06-18 22:18:36·¢±í:
»¹ÓÐÈËÓÃfedora8×öserver£¬Ôõô²»ÓÃCENTOSÄØ¡£×îÆðÂëËÙ¶ÈÒªºÃЩ£¬Íâ¼Ó¸üÎȶ¨Ð©¡£