question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Couple false-negatives

See original GitHub issue

_Issue originally created by user migolovanov on date 2017-09-17 12:15:08. Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/891._

These attacks are not blocked by current version:

?test=%27+%0A%09%09%09%09%09%09};+%0A%09%09%09%09%09%09alert%280%29;+%0A%09%09%09%09%09%09a%20=%20{+%0A%09%09%09%09%09%09%09%27a%27+:+%27
?test=%27+alert(1)&&null==%27
?test=%27+alert(%27XSS%27)+%27
?test=C%3A/inetpub/wwwroot/global.asa
?test=C%3A%5Cinetpub%5Cwwwroot%5Cglobal.asa
?test=././.htaccess

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:10

github_iconTop GitHub Comments

1reaction
CRS-migration-botcommented, May 13, 2020

User dune73 commented on date 2017-09-18 15:11:48:

Thank you for the info migolovanov.

Most of them trigger on PL2, it might be worth checking if we can shift the .htaccess payload to PL2 as well. PL3 is a bit high for something that obvious.

0reactions
CRS-migration-botcommented, May 13, 2020

User fgsch commented on date 2019-10-20 22:17:09:

This issue has timed out as it has not received any update in over 2 years. If this is still a problem please open a new issue.

Read more comments on GitHub >

github_iconTop Results From Across the Web

Knoxville couple receives positive and negative COVID-19 ...
George and Lottie Richardson took several precautions to avoid COVID-19 ahead of their long-planned Caribbean cruise.
Read more >
When A Negative Doesn't Really Mean Negative: Why Quality ...
A couple of days later when my boyfriend's symptoms got worse, ... While both false positive and false negative results come with their...
Read more >
Trust Clinical COVID-19 Signs Over a Negative RT-PCR Test
A Rutgers study finds patients who repeatedly tested negative but had COVID-19 clinical signs were likely to have COVID-19.
Read more >
Many people say they've gotten false negatives on at-home ...
No test is 100% accurate, and experts say some patients aren't administering them correctly.
Read more >
A Negative COVID Test Has Never Been So Meaningless
... and may not accumulate to the densities that Delta did in the nose, which could make false negatives more likely. A couple...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found