0 Mitglieder und 1 Gast betrachten dieses Thema.
<IfModule mod_security2.c> SecRuleEngine Off</IfModule>
<IfModule mod_ssl.c><VirtualHost *:443> ServerName mail.example.com ServerAlias mail.example.com ServerAdmin admin@example.com ErrorLog ${APACHE_LOG_DIR}/zimbra-error.log CustomLog ${APACHE_LOG_DIR}/zimbra-access.log combined SSLProxyEngine ON SSLEngine On ProxyPass / http://localhost:55080/ ProxyPassReverse / http://localhost:55080/ SSLCertificateFile /etc/letsencrypt/live/mail.example.com/cert.pem SSLCertificateKeyFile /etc/letsencrypt/live/mail.example.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf SSLCertificateChainFile /etc/letsencrypt/live/mail.example.com/chain.pem <IfModule mod_security2.c> SecRuleEngine Off </IfModule></VirtualHost></IfModule>
--5a2d607e-A--[27/Mar/2016:21:52:07 +0200] Vvg555BMOoQAAH0qfgwAAAAA 80.130.113.210 41566 144.76.58.132 443--5a2d607e-B--GET / HTTP/1.1Host: mail.example.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.108 Safari/537.36Accept-Encoding: gzip, deflate, sdchAccept-Language: de-DE,de;q=0.8,en-US;q=0.6,en;q=0.4,en-GB;q=0.2Cookie: ZM_TEST=true; JSESSIONID=13uwd6hrzqbub1mk7syhntzjg5--5a2d607e-F--HTTP/1.1 403 ForbiddenX-Frame-Options: SAMEORIGINContent-Length: 202Connection: closeContent-Type: text/html; charset=iso-8859-1--5a2d607e-E--<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access /on this server.</p></body></html>--5a2d607e-H--Message: Access denied with code 403 (phase 1). Operator EQ matched 1 at SESSION:IS_NEW. [file "/usr/share/modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf"] [line "24"] [id "981054"] [msg "Invalid SessionID Submitted."]Action: Intercepted (phase 1)Stopwatch: 1459108327444980 960 (- - -)Stopwatch2: 1459108327444980 960; combined=543, p1=393, p2=0, p3=0, p4=0, p5=149, sr=81, sw=1, l=0, gc=0Response-Body-Transformed: DechunkedProducer: ModSecurity for Apache/2.7.7 (http://www.modsecurity.org/); OWASP_CRS/2.2.8.Server: ApacheWebApp-Info: "default" "13uwd6hrzqbub1mk7syhntzjg5" "-"Engine-Mode: "ENABLED"--5a2d607e-Z----5a2d607e-A--[27/Mar/2016:21:52:07 +0200] Vvg555BMOoQAAH1rpccAAAAC 80.130.113.210 41568 144.76.58.132 443--5a2d607e-B--GET /favicon.ico HTTP/1.1Host: mail.example.comConnection: keep-alivePragma: no-cacheCache-Control: no-cacheUser-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.108 Safari/537.36Accept: */*Referer: https://example.com/Accept-Encoding: gzip, deflate, sdchAccept-Language: de-DE,de;q=0.8,en-US;q=0.6,en;q=0.4,en-GB;q=0.2Cookie: ZM_TEST=true; JSESSIONID=13uwd6hrzqbub1mk7syhntzjg5--5a2d607e-F--HTTP/1.1 403 ForbiddenX-Frame-Options: SAMEORIGINContent-Length: 213Connection: closeContent-Type: text/html; charset=iso-8859-1--5a2d607e-E--<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access /favicon.icoon this server.</p></body></html>--5a2d607e-H--Message: Access denied with code 403 (phase 1). Operator EQ matched 1 at SESSION:IS_NEW. [file "/usr/share/modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf"] [line "24"] [id "981054"] [msg "Invalid SessionID Submitted."]Action: Intercepted (phase 1)Stopwatch: 1459108327554031 772 (- - -)Stopwatch2: 1459108327554031 772; combined=415, p1=298, p2=0, p3=0, p4=0, p5=116, sr=64, sw=1, l=0, gc=0Response-Body-Transformed: DechunkedProducer: ModSecurity for Apache/2.7.7 (http://www.modsecurity.org/); OWASP_CRS/2.2.8.Server: ApacheWebApp-Info: "default" "13uwd6hrzqbub1mk7syhntzjg5" "-"Engine-Mode: "ENABLED"--5a2d607e-Z--