[Owasp-modsecurity-core-rule-set] Setting default action for blocking rules only?

Mario Santana msantana at terremark.com
Wed May 19 10:17:45 EDT 2010


Hi, all.

I'm looking for a way to set a SESSION variable in all blocking rules.  If I put "setvar:SESSION.tagged=1" in SecDefaultAction, then that variable will be set when some non-blocking rules match.  I've read Ivan's book, browsed the code, and experimented with Lua - without finding a way.  Any pointers?

I'm about to despair and just manually add the setvar action to all blocking rules in the CRS...



More information about the Owasp-modsecurity-core-rule-set mailing list