hey @p0pr0ck5 welcome back to the world of the living :)
Robert
@p0pr0ck5
:D
Robert
@p0pr0ck5
@csanders-git heya, whats the numeric relationship for human-readable phase representations? i assume request phase is analagous phase 2. is response phase 4, given that it seems to expect the body? any human readable words for phases 1 and 3?
we'd like to support this in lua-resty-waf (matter of fact, on my plate now is integrating CRS directly into the project for out-of-the-box support)
Chaim Sanders
@csanders-git
@p0pr0ck5 nope, just those two .... AWESOME, we're always happy to help make sure CRS works on any WAF that is looking to have its support :)
Robert
@p0pr0ck5
bueno. will keep yall updated
FP reduction is a big draw for us to the CRS. only roadblock at this point is target exclusions
(and then response body handling, but thats another kettle of fish ;) )
is there a test suite for new CRS rules? e.g. a set of requests/responses that are known to trigger rules so we can check for correctness in other projects?
found a 6 year old changelog entry about it reference evasion, but im having trouble understanding how its useful
Chaim Sanders
@csanders-git
I asked Ryan the same question, it isn't clear how this actually avoids any issue in the rule it's used in.
Michael Birnholz
@mbtoldya
Howdy folks. I am a newb, who just tried installing v2.92 on a win 2012 server. it failed, and i tried to remove it and can't be removed. Is there a way to just force a later version on top of old ?