@@ -423,6 +423,7 @@ SecRule REQUEST_URI "@rx \%(?:(?!$|\W)|[0-9a-fA-F]{2}|u[0-9a-fA-F]{4})" \
423
423
block,\
424
424
t:none,\
425
425
msg:'URL Encoding Abuse Attack Attempt',\
426
+ logdata:'%{matched_var}',\
426
427
tag:'application-multi',\
427
428
tag:'language-multi',\
428
429
tag:'platform-multi',\
@@ -443,6 +444,7 @@ SecRule REQUEST_HEADERS:Content-Type "@rx ^(?:application\/x-www-form-urlencoded
443
444
block,\
444
445
t:none,\
445
446
msg:'URL Encoding Abuse Attack Attempt',\
447
+ logdata:'%{matched_var}',\
446
448
tag:'application-multi',\
447
449
tag:'language-multi',\
448
450
tag:'platform-multi',\
@@ -475,6 +477,7 @@ SecRule TX:CRS_VALIDATE_UTF8_ENCODING "@eq 1" \
475
477
block,\
476
478
t:none,\
477
479
msg:'UTF8 Encoding Abuse Attack Attempt',\
480
+ logdata:'%{matched_var}',\
478
481
tag:'application-multi',\
479
482
tag:'language-multi',\
480
483
tag:'platform-multi',\
@@ -513,6 +516,7 @@ SecRule REQUEST_URI|REQUEST_BODY "@rx \%u[fF]{2}[0-9a-fA-F]{2}" \
513
516
block,\
514
517
t:none,\
515
518
msg:'Unicode Full/Half Width Abuse Attack Attempt',\
519
+ logdata:'%{matched_var_name}=%{matched_var}',\
516
520
tag:'application-multi',\
517
521
tag:'language-multi',\
518
522
tag:'platform-iis',\
@@ -567,6 +571,7 @@ SecRule REQUEST_URI|REQUEST_HEADERS|ARGS|ARGS_NAMES "@validateByteRange 1-255" \
567
571
block,\
568
572
t:none,t:urlDecodeUni,\
569
573
msg:'Invalid character in request (null character)',\
574
+ logdata:'%{matched_var_name}=%{matched_var}',\
570
575
tag:'application-multi',\
571
576
tag:'language-multi',\
572
577
tag:'platform-multi',\
@@ -821,6 +826,7 @@ SecRule &TX:MAX_NUM_ARGS "@eq 1" \
821
826
block,\
822
827
t:none,\
823
828
msg:'Too many arguments in request',\
829
+ logdata:'%{matched_var_name}=%{matched_var}',\
824
830
tag:'application-multi',\
825
831
tag:'language-multi',\
826
832
tag:'platform-multi',\
@@ -846,6 +852,7 @@ SecRule &TX:ARG_NAME_LENGTH "@eq 1" \
846
852
block,\
847
853
t:none,\
848
854
msg:'Argument name too long',\
855
+ logdata:'%{matched_var_name}=%{matched_var}',\
849
856
tag:'application-multi',\
850
857
tag:'language-multi',\
851
858
tag:'platform-multi',\
@@ -870,6 +877,7 @@ SecRule &TX:ARG_LENGTH "@eq 1" \
870
877
block,\
871
878
t:none,\
872
879
msg:'Argument value too long',\
880
+ logdata:'%{matched_var_name}=%{matched_var}',\
873
881
tag:'application-multi',\
874
882
tag:'language-multi',\
875
883
tag:'platform-multi',\
@@ -894,6 +902,7 @@ SecRule &TX:TOTAL_ARG_LENGTH "@eq 1" \
894
902
block,\
895
903
t:none,\
896
904
msg:'Total arguments size exceeded',\
905
+ logdata:'%{matched_var_name}=%{matched_var}',\
897
906
tag:'application-multi',\
898
907
tag:'language-multi',\
899
908
tag:'platform-multi',\
@@ -946,6 +955,7 @@ SecRule &TX:COMBINED_FILE_SIZES "@eq 1" \
946
955
block,\
947
956
t:none,\
948
957
msg:'Total uploaded files size too large',\
958
+ logdata:'%{matched_var_name}=%{matched_var}',\
949
959
tag:'application-multi',\
950
960
tag:'language-multi',\
951
961
tag:'platform-multi',\
@@ -1189,6 +1199,7 @@ SecRule ARGS "@rx \%((?!$|\W)|[0-9a-fA-F]{2}|u[0-9a-fA-F]{4})" \
1189
1199
block,\
1190
1200
t:none,\
1191
1201
msg:'Multiple URL Encoding Detected',\
1202
+ logdata:'%{matched_var}',\
1192
1203
tag:'application-multi',\
1193
1204
tag:'language-multi',\
1194
1205
tag:'platform-multi',\
@@ -1245,6 +1256,7 @@ SecRule REQUEST_URI|REQUEST_HEADERS|ARGS|ARGS_NAMES "@validateByteRange 9,10,13,
1245
1256
block,\
1246
1257
t:none,t:urlDecodeUni,\
1247
1258
msg:'Invalid character in request (non printable characters)',\
1259
+ logdata:'%{matched_var_name}=%{matched_var}',\
1248
1260
tag:'application-multi',\
1249
1261
tag:'language-multi',\
1250
1262
tag:'platform-multi',\
@@ -1330,6 +1342,7 @@ SecRule REQUEST_URI|REQUEST_HEADERS|ARGS|ARGS_NAMES|REQUEST_BODY "@validateByteR
1330
1342
block,\
1331
1343
t:none,t:urlDecodeUni,\
1332
1344
msg:'Invalid character in request (outside of printable chars below ascii 127)',\
1345
+ logdata:'%{matched_var_name}=%{matched_var}',\
1333
1346
tag:'application-multi',\
1334
1347
tag:'language-multi',\
1335
1348
tag:'platform-multi',\
@@ -1385,8 +1398,9 @@ SecRule ARGS|ARGS_NAMES|REQUEST_BODY "@validateByteRange 38,44-46,48-58,61,65-90
1385
1398
"id:920273,\
1386
1399
phase:2,\
1387
1400
block,\
1388
- msg:'Invalid character in request (outside of very strict set)',\
1389
1401
t:none,t:urlDecodeUni,\
1402
+ msg:'Invalid character in request (outside of very strict set)',\
1403
+ logdata:'%{matched_var_name}=%{matched_var}',\
1390
1404
tag:'application-multi',\
1391
1405
tag:'language-multi',\
1392
1406
tag:'platform-multi',\
@@ -1409,6 +1423,7 @@ SecRule REQUEST_HEADERS|!REQUEST_HEADERS:User-Agent|!REQUEST_HEADERS:Referer|!RE
1409
1423
block,\
1410
1424
t:none,t:urlDecodeUni,\
1411
1425
msg:'Invalid character in request headers (outside of very strict set)',\
1426
+ logdata:'%{matched_var_name}=%{matched_var}',\
1412
1427
tag:'application-multi',\
1413
1428
tag:'language-multi',\
1414
1429
tag:'platform-multi',\
0 commit comments