Commit Graph

  • 62a76e1ed6 Update CHANGES Ryan Barnett 2014-04-03 08:36:42 -04:00
  • ad5824c00c Fix type on the CHANGES file. Felipe Zimmerle 2014-04-01 03:11:01 -07:00
  • 0826380acd Version 2.8.0 Felipe Zimmerle 2014-03-31 13:36:12 -07:00
  • 261d16c8aa Version 2.8.0 v2.8.0-rc1 Felipe Zimmerle 2014-03-31 13:36:12 -07:00
  • 385a2828e8 Code cosmetics: Reduces the amounts of warning. Felipe Zimmerle 2014-03-26 18:21:42 -07:00
  • 1e63e49db4 Uses %zu to print size_t instead of %d. Felipe Zimmerle 2014-03-26 15:10:44 -07:00
  • 503e8f6c8e Updates the libinjection Felipe Zimmerle 2014-02-18 05:06:58 -08:00
  • 66939d059b Adds initial support to @detectXSS Felipe Zimmerle 2014-02-17 06:31:38 -08:00
  • 47f5cf92db Removes forced chartset Felipe Zimmerle 2014-01-22 18:32:07 -08:00
  • efef989ddd Renames Sec{Read|Write}StateLimits Felipe Zimmerle 2013-11-01 07:02:59 -07:00
  • 48d85c7d6e Places connection filter engine in a separated configuration Felipe Zimmerle 2013-11-01 06:22:04 -07:00
  • a15f8813e9 Honor the SecRuleEngine while filtering connections Felipe Zimmerle 2013-10-31 14:28:00 -07:00
  • 0037a0732a Using RadixTree instead of list to storage IPs Felipe Zimmerle 2013-10-31 09:53:24 -07:00
  • 80185e2a90 Bugfix: Missing ipv6 support check Felipe Zimmerle 2013-10-31 06:11:35 -07:00
  • b9fdc4fe3b Adds support to suspicious and whitelist to Read and Write limits Felipe Zimmerle 2013-10-30 19:54:09 -07:00
  • 8ff3de5b6f iis: Disables installer repair Felipe "Zimmerle" Costa 2014-02-25 14:11:45 -03:00
  • d6dd1f0e94 iis: Adding VC110 files to the Windows installer Felipe "Zimmerle" Costa 2014-02-25 11:46:51 -03:00
  • 28d4f9fce1 iis: Checks Win version before declare inet_pton Felipe Zimmerle 2013-12-19 13:02:21 -08:00
  • bd0980f63d Reverts commit: a4202146b8 Felipe Zimmerle 2013-12-19 12:13:25 -08:00
  • 93b12df721 iis: Removes unnecessary files. Felipe "Zimmerle" Costa 2014-02-24 15:06:20 -03:00
  • fe727c7021 iis: Updated OWASP crs to version 2.2.9 Felipe "Zimmerle" Costa 2014-02-24 10:23:52 -03:00
  • 10db384316 iis: Adds cleanup methods to the installer Felipe "Zimmerle" Costa 2014-02-23 22:28:32 -03:00
  • f8f06f7930 IIS: Updates build_msi.bat to fit the new WiX install options Felipe "Zimmerle" Costa 2014-02-20 00:29:12 -03:00
  • 4d7d1ba822 iis: Adds listing dependencies script Felipe "Zimmerle" Costa 2014-02-19 22:09:57 -03:00
  • 619758c0c2 iis: Adds condition to avoid the use of 32b msi on a 64b os Felipe "Zimmerle" Costa 2014-02-19 10:38:30 -03:00
  • 93a86f6f33 iis: Adds Visual C++ 12.0 Runtime to be part of the msi package Felipe "Zimmerle" Costa 2014-02-19 02:24:31 -03:00
  • ec61749a68 Changes JSON parser to not accept parcial contents Felipe Zimmerle 2014-03-25 05:22:00 -07:00
  • 966e7e1ff1 Adds verification before access the strcmp Felipe Zimmerle 2014-03-20 11:02:36 -07:00
  • c5c2690809 Adds origin to the paramenters that cames from JSON Felipe Zimmerle 2014-03-20 10:58:43 -07:00
  • 52bef20ce5 Adds unit test to the JSON parser Felipe Zimmerle 2014-02-03 08:48:54 -08:00
  • a95f37196e Adds JSON support on ISS port Felipe Zimmerle 2013-12-03 13:41:09 -08:00
  • 0787b45481 Adds support to JSON parser in the nginx module Felipe Zimmerle 2013-12-03 13:41:09 -08:00
  • 09ced44ffa Supports the yajl version 2 Felipe Zimmerle 2013-12-03 13:41:08 -08:00
  • 8d4c3e4f5c Makes the build system to look for yajl using a macro file Felipe Zimmerle 2013-12-03 13:41:08 -08:00
  • e90874a694 Added sample JSON content-type rule Ulisses Albuquerque 2013-12-03 13:41:08 -08:00
  • c23097ce18 Added support for JSON body processor Ulisses Albuquerque 2013-12-03 13:41:08 -08:00
  • 410aca9d78 Optimization on the status engine call Felipe Zimmerle 2014-02-26 05:57:07 -08:00
  • 20014c808c Adds modsecStatusEngineCall to standalone API Felipe "Zimmerle" Costa 2014-02-15 00:29:51 -02:00
  • d75e443b9b Adds regression test to SecStatusEngine Felipe Zimmerle 2014-02-11 19:01:05 -08:00
  • a6d93441c1 Places StatusEngine to be Off by default Felipe Zimmerle 2014-01-21 12:23:19 -08:00
  • e131e2222d Adds support to status engine on IIS version Felipe Zimmerle 2014-01-19 05:51:22 -08:00
  • f86a71f7a7 Adds SecStatusEngine On/Off switch Felipe Zimmerle 2013-12-02 13:22:39 -08:00
  • 0c6a661c69 First version of the status engine implementation Felipe Zimmerle 2013-12-02 04:09:49 -08:00
  • d93ce9ceee Adds REQUEST_FULL and REQUEST_FULL_LENGTH variables Felipe Zimmerle 2014-02-27 10:39:07 -08:00
  • 62f3d02894 Adds utf8toUnicode.t to our unit tests Felipe Zimmerle 2014-03-05 14:16:14 -08:00
  • 5b0c933cf3 Fixes UTF8 to Unicode conversion bug in 4-byte encodings Greg Chow 2014-03-05 17:40:24 -05:00
  • 7e459827e0 Log why writing to audit log failed Ewald Dieterich 2014-02-26 08:32:11 +01:00
  • 607dfd229a Fix segmentation fault if writing to audit log fails Ewald Dieterich 2014-02-26 08:29:01 +01:00
  • 5342f36162 iis: Uses code 400 instead of 44 in modsecurity.conf Felipe Zimmerle 2014-03-03 15:43:56 -08:00
  • a0ed3dbbe2 Merge pull request #666 from derhansen/master Felipe Zimmerle 2014-03-03 21:42:40 -02:00
  • dda91f1689 Standalone: independently destroy the connection and request pools David Andrews 2014-03-03 14:17:00 -08:00
  • 27dd513ab6 Flip allocations that happen during initialization (typically) over to use non-global apr memory pools. David Andrews 2013-12-16 14:53:19 -08:00
  • 31d7fc6d38 Code cosmetics: Place copy_rules in nice shape. Felipe Zimmerle 2014-02-28 18:55:04 -08:00
  • 62a6f228f8 Fixes for Parfait errors - mostly unhandled NULL pointer dereference and data type mismatch Jiri Kukacka 2013-12-09 18:58:21 +01:00
  • 5f996d45f0 Adds regression test to SecRequestBodyLimitAction Felipe Zimmerle 2014-02-28 13:33:49 -08:00
  • 498b9b2e7a Don't reject a large request with ProcessPartial set Justin Gerace 2013-11-08 16:11:40 -08:00
  • ab9aede2e5 Update status code for rule 200002 Torben Hansen 2014-02-25 15:44:40 +01:00
  • 063dd640e5 Adds internal error messages while parsing the configutarion Felipe Zimmerle 2014-02-19 15:43:02 -08:00
  • da2ec008bd Fixes a typo on the README.txt Felipe Zimmerle 2014-02-10 03:04:17 -08:00
  • 1694a0cf34 Merge branch 'nginx_regression' Felipe Zimmerle 2014-01-17 22:07:50 -08:00
  • f043ba33a3 Adds .a to the list of expected liblua extension Felipe Zimmerle 2014-01-18 01:29:02 -03:00
  • 5d2e3d4321 test: 10-misc-directives.t is not considering log anymore Felipe Zimmerle 2014-01-17 13:02:48 -08:00
  • 8804b55cdd test: Makes regression test mac friendly Felipe Zimmerle 2014-01-17 11:24:53 -08:00
  • 8314791c9e test: nginx: Adds timeout while listening for a socket. Felipe Zimmerle 2014-01-16 20:22:38 -08:00
  • 215042af21 test: nginx: Points the !# to envoriment. Felipe Zimmerle 2014-01-16 10:31:59 -08:00
  • d26e639512 test: nginx: Speeds up regression test in nginx. Felipe Zimmerle 2014-01-16 10:30:23 -08:00
  • fe14d9df4d nginx: Considering modsec state before apply any rules Felipe Zimmerle 2014-01-13 14:07:18 -08:00
  • 9bf1f6a2b3 test: removes uncessary ifDefine at 10-tfn-cache.t Felipe Zimmerle 2014-01-13 08:11:42 -08:00
  • 94097103c8 test: nginx: Adds missing environment variables. Felipe Zimmerle 2014-01-13 05:35:54 -08:00
  • 6c106b1fd7 test: disabling: SecAuditLogType Concurrent Felipe Zimmerle 2014-01-13 05:33:42 -08:00
  • 8e390899e0 test: nginx: Increses the timeout while reading the audit log. Felipe Zimmerle 2014-01-10 07:54:19 -08:00
  • 3cf1701794 test: Adds loading tests also to nginx. Felipe Zimmerle 2014-01-09 12:13:47 -08:00
  • 795d6a64d2 nginx: Warn about not workable 'proxy' Felipe Zimmerle 2014-01-09 11:12:28 -08:00
  • 7478faa5ce test: Adds support to handle different content in log depending on the version Felipe Zimmerle 2014-01-09 08:45:53 -08:00
  • 7ac515ee29 nginx: Adds proper support to SecServerSignature Felipe Zimmerle 2014-01-08 13:54:51 -08:00
  • 2a43589395 nginx: Removes problematic performance improvement Felipe Zimmerle 2014-01-07 18:45:06 -08:00
  • 21e25c50af test: nginx: Adds missing files Felipe Zimmerle 2014-01-06 19:52:10 -08:00
  • 176396ddc1 tests: nginx: Allow POSTs in static files Felipe Zimmerle 2014-01-06 19:22:27 -08:00
  • e20c800044 nginx: fix missing headers while SecResponseBodyAccess was On Felipe Zimmerle 2014-01-06 13:10:13 -08:00
  • 445783d067 tests: Sleeps over 20 seconds if nginx failed to exit immediately Felipe Zimmerle 2014-01-03 13:09:44 -08:00
  • fb4e1f1b6b tests: Adds random data to a post making it workable in nginx Felipe Zimmerle 2014-01-03 09:36:25 -08:00
  • 450d621ca9 tests: adds test-regression-nginx to the makefile Felipe Zimmerle 2014-01-03 09:26:30 -08:00
  • 96ad8267ee tests: Marks the run-regression-tests-nginx.pl script as executable. Felipe Zimmerle 2014-01-03 09:25:27 -08:00
  • 93c5b8c6ac Merge branch 'regression' Felipe Zimmerle 2014-01-03 05:20:05 -08:00
  • 0ad390d12d Tests: fixes tests/regression/rule/10-xml.t Felipe Zimmerle 2014-01-01 20:56:06 -08:00
  • ba0818ca32 tests: cleans up the apache configuration file Felipe Zimmerle 2014-01-01 16:09:21 -08:00
  • 6325ed8d41 Tests: fixes regression/misc/10-tfn-cache.t Felipe Zimmerle 2014-01-01 11:49:08 -08:00
  • ddb4fceb63 Tests: fixes regression/rule/20-exceptions.t Felipe Zimmerle 2014-01-01 11:21:37 -08:00
  • 0c99063aae Tests: fixes regression/rule/00-basics.t Felipe Zimmerle 2014-01-01 11:02:20 -08:00
  • 7c9ebfeb20 Tests: fixes regression/action/10-logging.t Felipe Zimmerle 2014-01-01 10:52:44 -08:00
  • 11287a6b95 test: fixes regression/misc/00-multipart-parser.t Felipe Zimmerle 2014-01-01 10:29:03 -08:00
  • b0025c88fa tests: fixes regression/config/10-request-directives.t Felipe Zimmerle 2014-01-01 10:09:53 -08:00
  • e5560a6a43 tests: fixes regression/config/10-misc-directives.t Felipe Zimmerle 2014-01-01 09:57:45 -08:00
  • 0ddd2b4639 Add mod_extract_forwarded.c to run before mod_security2.c Chase Venters 2013-11-07 10:48:08 -06:00
  • b788ce2608 Clean the garbage character after the duplicated charset property ahuango 2013-12-12 14:22:30 +08:00
  • 74ec784005 libinjection sync Nick Galbreath 2013-12-18 04:19:02 +00:00
  • 227de9fb8a Reverts commit b1cbccdc6b Felipe Zimmerle 2013-12-18 15:05:01 -08:00
  • 2f5af6af73 Merge tag 'refs/tags/v2.7.7' Felipe Zimmerle 2013-12-18 14:56:22 -08:00
  • 87115e770a Adds a default config script to nginx v2.7.7 Felipe Zimmerle 2013-12-18 03:35:26 -08:00
  • 537b85edf8 Changes SecUnicodeMapFile in recommend configuration Felipe Zimmerle 2013-12-17 17:28:58 -08:00