store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 25, 2013 5:59 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: Global disabling of a rule problem
Unread postPosted: Fri Sep 16, 2011 1:18 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 24, 2008 12:05 pm
Posts: 145
I just tried to globally disable rule 300023 (Multiple embedded urls in argument), but once i set that global disable option to 'yes' and save.. and then reload that rule info page, it still shows 'no' for globally disabled.

The /etc/asl/rules file shows:

G, waf, 300023,,yes,yes,7,yes,yes,


Top
 Profile  
 
 Post subject: Re: Global disabling of a rule problem
Unread postPosted: Fri Sep 16, 2011 1:28 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3249
Location: Chantilly, VA
Is the rule disabled though? This could just be a minor GUI bug. Does the rule trigger?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Global disabling of a rule problem
Unread postPosted: Fri Sep 16, 2011 1:46 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 24, 2008 12:05 pm
Posts: 145
It seems to not trigger anymore so it may indeed just be a GUI bug.


Top
 Profile  
 
 Post subject: Re: Global disabling of a rule problem
Unread postPosted: Fri Sep 16, 2011 2:49 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
We see this whenever a rule is disabled. I thought it was a known bug :-(

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Global disabling of a rule problem
Unread postPosted: Fri Sep 16, 2011 5:23 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 24, 2008 12:05 pm
Posts: 145
Actually, it is not a GUI problem. I just received a message that the person was 403'ed again on the same rule, eventhough it is in the /etc/asl/rules file. Maybe the line in the file is not formatted correctly for ASL to read and so still sees it as active?

This is very important actually because now we can no longer update the relevant wiki pages on our site. This rule was blocked before using the old ASL 2.x but obviously those no longer work in the new ASL.


Top
 Profile  
 
 Post subject: Re: Global disabling of a rule problem
Unread postPosted: Fri Sep 16, 2011 5:41 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jun 24, 2008 12:05 pm
Posts: 145
hmm when i disable the rule using the command line, it seems to work. But now i have 2 lines in /etc/asl/rules. The old one that was done via the GUI (2nd one) and the new one using the cli (1st one):

G,waf,300023,,yes,no,0,no,no,
G, waf, 300023,,yes,yes,7,yes,yes,

The person editing my wiki says it goes through now. Not sure if that is because the 1st line says 'no' on things that may possibly be the 'active response' item, or if it is actually disabled now. The GUI however still shows the rule being active.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group