3 Jun 20:47
Trouble with phpMyAdmin and mod_sec (getting caught in phase:1)
hanj <mailing <at> astarna.com>
2007-06-03 18:47:21 GMT
2007-06-03 18:47:21 GMT
Hello I'm having trouble the excluding phpMyAdmin from mod_sec. I've added the SecRuleInheritance Off and SecRuleEngine Off in the Directory area of my VirtualHost. This seems to apply to phase:2, but not phase:1. I'm getting a 400 status when I try to edit a record. I also tried the SecRule REQUEST_FILENAME and allowing phase:1, but I continue to get the 400 status. Here is my modsec_audit.log and below that is a view of my apache config for that directory. Any suggestions are greatly appreciated. --816a6d09-(Continue reading)A-- [03/Jun/2007:12:37:24 --0600] vVBTC0LbO5UAAD46MaoAAAAA xxx.xxx.xxx.xxx 1359 xxx.xxx.xxx.xxx 443 --816a6d09-B-- GET /phpmyadmin/tbl_change.php?db=mydb&table=data&token=323cf89f3969db1b855a159b9b250bc3&pos=0&session_max_rows=30&disp_direction=horiz ontal&repeat_cells=100&dontlimitchars=0&primary_key=+%60data%60.%60DataID%60+%3D+702&sql_query=SELECT+%2A+FROM+%60data%60+WHERE+LastName+LIKE+%27%25doe%25%27&goto=sql.php HTTP/1.1 Host: my.host.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.12) Gecko/20070508 Firefox/1.5.0.12 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: https://my.host.com/phpmyadmin/import.php Cookie: pmaCookieVer=4; pma_collation_connection=utf8_unicode_ci; pma_charset=iso-8859-1; pma_lang=en-utf-8;


RSS Feed