 |
| Atomicorp Staff - Site Admin |
 |
 |
Joined: Thu Feb 07, 2008 7:49 pm Posts: 3242 Location: Chantilly, VA
|
|
Thanks for the question. The rule id for this event is 393134:
Rule: 60118 fired (level 7) -> "Access attempt blocked by Mod Security." [403] [/20121023/20121023-1159/20121023-115940-iw8G6lURVx4AAHnnVnUAAAAC] [file "/etc/httpd/modsecurity.d/99_asl_jitp.conf"] [line "2873"] [id "393134"] [rev "1"] [msg "Atomicorp.com WAF Rules - Virtual Just In Time Patch: Test.fcgi or test.cgi access"] [severity "CRITICAL"] Access denied with code 403 (phase 2). Pattern match "/test\\.f?cgi" at REQUEST_URI.
The best way to do change rules is to log into the ASL gui, click on the event, and then click Manage Rule which will open that rules settings directly.
_________________ Michael Shinn Atomicorp - Security For Everyone
Co-Author of Troubleshooting Linux Firewalls.
|
|