Commit Graph

176 Commits

Author SHA1 Message Date
brectanus
f173301b39 Worked around mod_jk issue where a 401 response was not including the WWW-Authentication header (MODSEC-16). 2008-09-15 19:51:06 +00:00
brectanus
d257fd7910 Change from ctl:requestBodyBuffering to ctl:forceRequestBodyVariable. 2008-09-10 17:11:20 +00:00
brectanus
28bda503a3 Make sure we fail to validate DTD/schema after a parsing error. Fixes MODSEC-5. 2008-09-03 22:16:42 +00:00
brectanus
f2f160e10c Allow ability to force request body buffering to memory. Fixes MODSEC-2. 2008-09-03 20:42:28 +00:00
brectanus
a25269a5e5 Updated the CHANGES. 2008-09-03 18:06:14 +00:00
brectanus
c47c3583e0 Added mlogc source. 2008-09-02 23:10:36 +00:00
brectanus
b6657a4b93 Update CHANGES.
Sync up docs.
2008-08-15 20:25:27 +00:00
brectanus
492ffd9897 Sync up branches/2.5.x and trunk. 2008-07-31 22:36:24 +00:00
brectanus
bab6fdba35 Prepare 2.5.x branch for next release. 2008-07-31 20:30:03 +00:00
brectanus
5c06f31001 Added mlogc to CHANGES. 2008-07-31 17:05:31 +00:00
brectanus
bc40fdb054 Fix a typo. 2008-07-31 16:57:44 +00:00
ivanr
2f6d1f873e Remove description of transformation caching issues from CHANGES. 2008-07-31 09:04:05 +00:00
brectanus
9fd865b763 Add the licensing exception (a text version). 2008-07-29 04:43:59 +00:00
brectanus
6ebc5ad6e7 Transformation caching fixes. See #364. 2008-07-29 00:18:16 +00:00
brectanus
e1342ff011 Backport trunk changes for changeset:1072 and changeset:1073 to 2.5, but leave out the error filter code until more testing is completed. See #498. 2008-06-05 16:55:53 +00:00
brectanus
896ae59e1f Re-enable error output filter with a fix after more testing/tracing of code. See #498.
Update versions to ready for release of 2.5.5.
2008-06-03 20:28:05 +00:00
brectanus
22f1c61f1d Fixed issue where logging was not occuring unless "auditlog" was enabled. See #497, #4, #451 and #445. 2008-06-02 23:34:31 +00:00
brectanus
a9fca34107 Enable "auditlog" action by default. See #445 and #451. 2008-06-02 23:31:27 +00:00
brectanus
0389a88b6a Backport fix to improve request body processing error messages. See #504. 2008-05-30 20:16:34 +00:00
brectanus
3632dae024 Backported changeset:1056 to 2.5.x which handles a lacking new line after the final multipart boundary. See #502. 2008-05-30 20:07:47 +00:00
brectanus
3240e91140 Fixed XML multithreading crash. See #501. 2008-05-30 20:01:44 +00:00
brectanus
603c0626f9 Fixed blocking in phase 3 by reverting changeset:591 (for now). See #65 and #498. 2008-05-30 19:31:22 +00:00
brectanus
e9efefe33e Added mod_rpaf-2.0 and mod_custom_header to the beforeme list. 2008-05-09 15:50:17 +00:00
brectanus
0c3f6bd2c2 Change version/date for release of 2.5.4. 2008-05-07 16:25:07 +00:00
brectanus
0c28f30876 Fix a transformation caching bug. See #490. 2008-05-05 21:57:28 +00:00
brectanus
60af949a7a Update CRS to 1.6.1. See #484. 2008-04-24 16:48:08 +00:00
brectanus
c6edc2d317 Fixed crash if a persistent variable name was more than 126 characters. See #478. 2008-04-24 16:40:14 +00:00
brectanus
a615470028 Fixed issue where the exec action may not be able to execute shell scripts. See #475. 2008-04-24 16:30:58 +00:00
brectanus
28e2ed2068 Expand macros in expirevar and deprecatevar. See #477.
Cleaned up debug logs in actions.
Warn on mismatched curly braces in macro expansion.
2008-04-24 16:23:35 +00:00
brectanus
4bdda866be Add missing CHANGES entry for build fixes. 2008-04-02 16:19:57 +00:00
brectanus
8e75cdb884 Update versions for release. 2008-04-02 16:10:47 +00:00
brectanus
e13d3dab8b Make sure all filehandles are closed at the end of a trasaction. See #464 and #465.
Fixes a few typos in some error messages when we are over the limits.
2008-03-28 20:00:37 +00:00
brectanus
6b970c9185 Added back support for HTTP_* targets by aliasing it to REQUEST_HEADERS:*.
Fixed the severity warning message to only be displayed at a warn log level.
2008-03-19 21:31:41 +00:00
brectanus
b2cf7d1329 Change version to 2.5.1 for tagging. 2008-03-14 23:03:13 +00:00
brectanus
d38f5da865 Change branch version back to -rc1 for re-taging. 2008-03-07 20:50:00 +00:00
brectanus
57e8fc57d9 Change version to 2.5.1-breach2 for appliance. 2008-03-07 20:41:27 +00:00
brectanus
024e854725 Fixed a bug in transformation caching, which would prevent a match in certian cases.
Updated docs on "pass" action to explicitly state that we execute all targets.
2008-03-07 20:23:16 +00:00
brectanus
69a547ccf9 Create a 2.5.1-breach1 for the M1100. 2008-03-05 18:16:23 +00:00
brectanus
20274563fb Make a severity in a default action just a warning instead of a fatal error. 2008-03-04 22:55:39 +00:00
brectanus
628321bb86 Cleaned up "make test" and document as still experimental. 2008-03-03 16:50:40 +00:00
brectanus
1e991d6fcd Add searching for lua in /usr/lib{64|32}.
Do not default to using -Werror (warnings are errors).
2008-02-27 23:18:03 +00:00
brectanus
1fbf0c97f2 Update CHANGES, versions and dates for 2.5.0. 2008-02-15 22:51:01 +00:00
brectanus
8cf74f5c91 Update version dates.
Fix a small typo in Lua example: nil, not null.
2008-02-14 22:16:21 +00:00
brectanus
f00e15cc0a More updates for Windows builds suggested by Tom Donovan at apachelounge. 2008-02-13 18:10:04 +00:00
brectanus
cc2110b187 Updates to build on Windows with MS VC++ 8. 2008-02-13 07:10:54 +00:00
brectanus
20bc34a53f Update core rules to 1.6.0-rc3. 2008-02-11 22:57:54 +00:00
brectanus
731ac3321b Update version date for 2.5.0-rc3. 2008-02-11 22:49:08 +00:00
brectanus
94f617ae1c Update CHANGES and release dates. 2008-02-09 01:22:01 +00:00
brectanus
45e85e4c89 Update CHANGES and version dates. 2008-02-08 01:24:46 +00:00
brectanus
fd8f4e319f Update CHANGES and versions for 2.5.0-rc3. 2008-02-05 00:55:16 +00:00