anyone got a rule against this?
/_vti_bin/owssvr.dll?UL=1&ACT=4&BUILD=6254&STRMVER=4&CAPREQ=0 HTTP/1.1
Access allowed. Pattern match "_vti_bin" at REQUEST_URI
anyone got a rule against this?
/_vti_bin/owssvr.dll?UL=1&ACT=4&BUILD=6254&STRMVER=4&CAPREQ=0 HTTP/1.1
Access allowed. Pattern match "_vti_bin" at REQUEST_URI
I don't understand the question ....
You could just write a rule if you want to block something specific like that.
I was hoping someone already had a rule that they could share.
Im actually interested in something else now too....
why would another sitename/host appear in our modsecurity list....
these are the ones i've seen:
www.netevin.com
www.saasveld.info
www.deverevenues.co.uk