Skip to content

False Positive Numeric number followed by double hyphen 9--aB7mnS7GdA3IQ #161

@shekharcloudengg123

Description

@shekharcloudengg123

Mod security blocks a valid request having
9--aB7mnS7GdA3IQ

ModSecurity: Access denied with code 403 (phase 2). detected SQLi using libinjection. [file "/etc/nginx/owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "45"] [id "942100"] [rev ""] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: 1c found within ARGS:json.Payload.DataList.array_0.messageId: 9--aP6mnZ21eK1mPQRA6IR"] [severity "2"] [ver "OWASP_CRS/3.3.2"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"]

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions