@@ -90,22 +90,22 @@ SecRule TX:HIGH_RISK_COUNTRY_CODES "!@rx ^$" \
90
90
# from the SpiderLabs web honeypot systems (last 48 hours).
91
91
#
92
92
#SecRule TX:REAL_IP "@ipMatchFromFile ip_blacklist.data" \
93
- "id:910110,\
94
- phase:2,\
95
- block,\
96
- t:none,\
97
- msg:'Client IP in Trustwave SpiderLabs IP Reputation Blacklist.',\
98
- tag:'application-multi',\
99
- tag:'language-multi',\
100
- tag:'platform-multi',\
101
- tag:'attack-reputation-ip',\
102
- severity:'CRITICAL',\
103
- setvar:'tx.msg=%{rule.msg}',\
104
- setvar:'tx.anomaly_score=+%{tx.critical_anomaly_score}',\
105
- setvar:'tx.%{rule.id}-AUTOMATION/MALICIOUS-%{matched_var_name}=%{matched_var}',\
106
- setvar:'ip.reput_block_flag=1',\
107
- setvar:'ip.reput_block_reason=%{rule.msg}',\
108
- expirevar:'ip.reput_block_flag=%{tx.reput_block_duration}'"
93
+ # "id:910110,\
94
+ # phase:2,\
95
+ # block,\
96
+ # t:none,\
97
+ # msg:'Client IP in Trustwave SpiderLabs IP Reputation Blacklist.',\
98
+ # tag:'application-multi',\
99
+ # tag:'language-multi',\
100
+ # tag:'platform-multi',\
101
+ # tag:'attack-reputation-ip',\
102
+ # severity:'CRITICAL',\
103
+ # setvar:'tx.msg=%{rule.msg}',\
104
+ # setvar:'tx.anomaly_score=+%{tx.critical_anomaly_score}',\
105
+ # setvar:'tx.%{rule.id}-AUTOMATION/MALICIOUS-%{matched_var_name}=%{matched_var}',\
106
+ # setvar:'ip.reput_block_flag=1',\
107
+ # setvar:'ip.reput_block_reason=%{rule.msg}',\
108
+ # expirevar:'ip.reput_block_flag=%{tx.reput_block_duration}'"
109
109
110
110
111
111
#
0 commit comments