question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Many false positives with 942360

See original GitHub issue

Description

The rule 942360 triggers many false positives. Here are some of my samples:

  • delete
  • 5desc
  • select
  • 34-delete
  • update
  • /select
  • (select
  • Update: After...
  • "desc"
  • #Create System
  • /load.php
  • /update-assets
  • bla blabla live update chart
  • .select-gws-banana

I’m opening a PR expending the patches from @franbuehler (https://github.com/coreruleset/coreruleset/issues/1675) to the other patterns.

Confirmation

[X] I have removed any personal data (email addresses, IP addresses, passwords, domain names) from any logs posted.

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:7 (5 by maintainers)

github_iconTop GitHub Comments

1reaction
Taiki-Sancommented, Feb 17, 2021
0reactions
github-actions[bot]commented, Feb 17, 2021

This issue has been open 120 days with no activity. Remove the stale label or comment, or this will be closed in 14 days

Read more comments on GitHub >

github_iconTop Results From Across the Web

Rule 942360 false-positive on Keyword alter #997 - GitHub
So this is a very similar case to #988. It is unfortunate that "Alter" is a German word (here), but the whole group...
Read more >
Disassembling SQLi Rules
We had to update an SQLi rule because of a false positive, but we did not understand the regex or even know which...
Read more >
Modsecurity: Excessive false positives - Stack Overflow
Many of these could easily appear in legitimate user input. Is there a graceful way to selectively allow common input that is not...
Read more >
Most Frequent False Positives Triggered by OWASP ... - netnea
Rule ID Description / Message False Positives Frequency 950001 SQL Injection Attack frequent false positives 950002 System Command Access few false positives 950005 Remote File Access...
Read more >
Web Application Firewall DRS rule groups and rules
Too many false positives. 942440, SQLI, SQL Comment Sequence Detected, Replaced by MSTIC rule 99031002. 99005006, MS-ThreatIntel-WebShells ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found