View Single Post
Old April 25th, 2007, 1:50 AM   #9 (permalink)
puckchaser
He shoots.. He scores!
Super #1
 
puckchaser's Avatar
 
Joined in Feb 2007
Lives in A room with no windows.
Hosted on SH110
1,446 posts
Gave thanks: 46
Thanked 140 times
Quote:
Originally Posted by H View Post
True... but there's some flawed logic here. When you're doing filtering based on keywords, it's absolutely necessary to at least notify someone of the problem. I'd imagine it's likely logged into a log file, but the script should also have access to it. In other words, allow the script to determine there's a possible problem, but let it determine how to handle it. I don't know how many times I've seen people have problems with curl, which can be used in normal English conversation.
I agree.

However, after a little googling, it appears that mod_security doesnt use logic. It appears to be a pretty black-and-white filter. From what I have found, it does get logged to :

/var/log/httpd/audit_log

However, us mere mortals on shared servers have no such access to that log. But I am sure a ticket to the helpdesk could get them to view/confirm.

Here's a link with more info.

PC
__________________
SH110
puckchaser is offline   Reply With Quote