client9 / client9/libinjection

modsecurity libinjection false positive

Open
#129 6 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
1k
Forks
282
PR merge metrics
No merged PRs in 30d

Description

ModSecurity reports:
```
[data "Matched Data: novc found within ARGS:LoginPassword: il0veGrandpa!@#"]
```
I'm not sure what it's objecting to. It's pretty clear that I'm going to have to disable the rule, but I was hoping for an explanation.

Taking a look at fingerprints2sqli.py I don't see how il0vegrandpa!@# translates into anything offensive.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.