[ { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: supporting transformation", "client":{ "ip":"200.249.12.31", "port":2313 }, "server":{ "ip":"200.249.12.31", "port":80 }, "request":{ "headers":{ "User-Agent":"Mozilla\/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko\/20091102 Firefox\/3.5.5 (.NET CLR 3.5.30729)", "Accept":"text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8", "Accept-Language":"en-us,en;q=0.5", "Accept-Encoding":"gzip,deflate", "Accept-Charset":"ISO-8859-1,utf-8;q=0.7,*;q=0.7", "Keep-Alive":"300", "Connection":"keep-alive", "Cookie":"PHPSESSID=rAAAAAAA2t5uvjq435r4q7ib3vtdjq120", "Pragma":"no-cache", "Cache-Control":"no-cache" }, "uri":"\/test.pl?param1= test ¶m2=test2", "method":"GET", "http_version":1.1, "body":"" }, "response":{ "headers":{ "Content-Type":"text\/xml; charset=utf-8\n\r", "Content-Length":"length\n\r" }, "body":[ "\n\r", "\n\r", " \n\r", " \n\r", " string<\/EnlightenResult>\n\r", " <\/EnlightenResponse>\n\r", " <\/soap:Body>\n\r", "<\/soap:Envelope>\n\r" ] }, "expected":{ "audit_log":"", "debug_log":"lowercase: \"300\"", "error_log":"" }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,t:lowercase,pass\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"phase:2,id:1,msg:'This is a test, %{REQUEST_HEADERS:Accept}%'\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none\"" ] }, { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: supporting transformation + t:none", "client":{ "ip":"200.249.12.31", "port":2313 }, "server":{ "ip":"200.249.12.31", "port":80 }, "request":{ "headers":{ "User-Agent":"Mozilla\/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko\/20091102 Firefox\/3.5.5 (.NET CLR 3.5.30729)", "Accept":"text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8", "Accept-Language":"en-us,en;q=0.5", "Accept-Encoding":"gzip,deflate", "Accept-Charset":"ISO-8859-1,utf-8;q=0.7,*;q=0.7", "Keep-Alive":"300", "Connection":"keep-alive", "Cookie":"PHPSESSID=rAAAAAAA2t5uvjq435r4q7ib3vtdjq120", "Pragma":"no-cache", "Cache-Control":"no-cache" }, "uri":"\/test.pl?param1= test ¶m2=test2", "method":"GET", "http_version":1.1, "body":"" }, "response":{ "headers":{ "Content-Type":"text\/xml; charset=utf-8\n\r", "Content-Length":"length\n\r" }, "body":[ "\n\r", "\n\r", " \n\r", " \n\r", " string<\/EnlightenResult>\n\r", " <\/EnlightenResponse>\n\r", " <\/soap:Body>\n\r", "<\/soap:Envelope>\n\r" ] }, "expected":{ "audit_log":"", "debug_log":" Target value: \"PHPSESSID=rAAAAAAA2t5uvjq435r4q7ib3vtdjq120\" ", "error_log":"" }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,t:lowercase,pass\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"t:none,phase:2,id:1,msg:'This is a test, %{REQUEST_HEADERS:Accept}%'\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none\"" ] }, { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: t:none", "expected":{ "parser_error":"The transformation none is not suitable to be part of the SecDefaultActions" }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,t:none\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"t:none,phase:2,id:1,msg:'This is a test, %{REQUEST_HEADERS:Accept}%'\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none\"" ] }, { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: simple test", "client":{ "ip":"200.249.12.31", "port":2313 }, "server":{ "ip":"200.249.12.31", "port":80 }, "request":{ "headers":{ "User-Agent":"Mozilla\/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko\/20091102 Firefox\/3.5.5 (.NET CLR 3.5.30729)", "Accept":"text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8", "Accept-Language":"en-us,en;q=0.5", "Accept-Encoding":"gzip,deflate", "Accept-Charset":"ISO-8859-1,utf-8;q=0.7,*;q=0.7", "Keep-Alive":"300", "Connection":"keep-alive", "Cookie":"PHPSESSID=rAAAAAAA2t5uvjq435r4q7ib3vtdjq120", "Pragma":"no-cache", "Cache-Control":"no-cache" }, "uri":"\/test.pl?param1= test ¶m2=test2", "method":"GET", "http_version":1.1, "body":"" }, "response":{ "headers":{ "Content-Type":"text\/xml; charset=utf-8\n\r", "Content-Length":"length\n\r" }, "body":[ "\n\r", "\n\r", " \n\r", " \n\r", " string<\/EnlightenResult>\n\r", " <\/EnlightenResponse>\n\r", " <\/soap:Body>\n\r", "<\/soap:Envelope>\n\r" ] }, "expected":{ "audit_log":"", "debug_log":"Saving msg: This is a test, text\/html,application", "error_log":"" }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,log,auditlog,pass\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"id:1,t:lowercase,t:none,msg:'This is a test, %{REQUEST_HEADERS:Accept}%'\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none\"" ] }, { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: action not suitable", "expected":{ "parser_error":"The action 'id' is not suitable to be part of the SecDefaultActions" }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,id:1,log,auditlog,pass,tag:'teste'\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"id:1,tag:'teste',t:lowercase,t:none,msg:'This is a test, %{REQUEST_HEADERS:Accept}%'\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none\"" ] }, { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: twice", "expected":{ "parser_error":"SecDefaultActions can only be placed once per phase and configuration context. Phase 2 was informed already." }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,log,auditlog,pass,tag:'teste'\"", "SecDefaultAction \"phase:2,log,auditlog,pass,tag:'teste'\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"id:1,tag:'teste',t:lowercase,t:none,msg:'This is a test, %{REQUEST_HEADERS:Accept}%'\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none\"" ] }, { "enabled":1, "version_min":300000, "version_max":0, "title":"Testing action :: SecDefaultAction: status + redirect", "client":{ "ip":"200.249.12.31", "port":2313 }, "server":{ "ip":"200.249.12.31", "port":80 }, "request":{ "headers":{ "User-Agent":"Mozilla\/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko\/20091102 Firefox\/3.5.5 (.NET CLR 3.5.30729)", "Accept":"text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8", "Accept-Language":"en-us,en;q=0.5", "Accept-Encoding":"gzip,deflate", "Accept-Charset":"ISO-8859-1,utf-8;q=0.7,*;q=0.7", "Keep-Alive":"300", "Connection":"keep-alive", "Cookie":"PHPSESSID=rAAAAAAA2t5uvjq435r4q7ib3vtdjq120", "Pragma":"no-cache", "Cache-Control":"no-cache" }, "uri":"\/test.pl?param1= test ¶m2=test2", "method":"GET", "http_version":1.1, "body":"" }, "response":{ "headers":{ "Content-Type":"text\/xml; charset=utf-8\n\r", "Content-Length":"length\n\r" }, "body":[ "\n\r", "\n\r", " \n\r", " \n\r", " string<\/EnlightenResult>\n\r", " <\/EnlightenResponse>\n\r", " <\/soap:Body>\n\r", "<\/soap:Envelope>\n\r" ] }, "expected":{ "audit_log":"", "debug_log":"Request was relevant to be saved.", "http_code": 302 }, "rules":[ "SecRuleEngine On", "SecDefaultAction \"phase:2,log,auditlog,status:302,redirect:'http://www.google.com'\"", "SecRule REQUEST_HEADERS \"@contains PHPSESSID\" \"phase:2,id:1,block\"", "SecRule TX \"@contains to_test\" \"id:2,t:lowercase,t:none,block\"" ] } ]