10000 Add urlDecodeUni() operation to ARG/ARGS_NAMES · Issue #578 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Add urlDecodeUni() operation to ARG/ARGS_NAMES #578

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
CRS-migration-bot opened this issue May 13, 2020 · 0 comments
Closed

Add urlDecodeUni() operation to ARG/ARGS_NAMES #578

CRS-migration-bot opened this issue May 13, 2020 · 0 comments

Comments

@CRS-migration-bot
Copy link

Issue for tracking original pull request created by user csjperon on date 2016-09-15 14:31:33.
Link to original PR: SpiderLabs/owasp-modsecurity-crs#578.

HEAD is: 73805dc
BASE is: 2396428

  • Add the urlDecodeUni transform operation to rules which inspect the
    ARGS/ARGS_NAMES collections, which do not currently call urlDecodeUni
  • This operation should be here. Some rules were written under the assumption
    that Apache/Nginx will automatically decode these collections prior to
    entering Modsecurity.
  • This change shouldn't impact the rule quality, but will introduce additional decoding overhead

I am creating this PR to start the discussion

Thoughts?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant
0