From 58815ac1eee015fe6ceb169f9675554d2ddd7490 Mon Sep 17 00:00:00 2001 From: Daniel Hansson Date: Sat, 4 Aug 2018 17:15:30 +0200 Subject: [PATCH] add it with php-fpm instead for a complete soulution --- static/whitelist-modsecurity.sh | 57 --------------------------------- 1 file changed, 57 deletions(-) delete mode 100644 static/whitelist-modsecurity.sh diff --git a/static/whitelist-modsecurity.sh b/static/whitelist-modsecurity.sh deleted file mode 100644 index ffaa0fbf..00000000 --- a/static/whitelist-modsecurity.sh +++ /dev/null @@ -1,57 +0,0 @@ -#!/bin/bash -# shellcheck disable=2034,2059 -true -# shellcheck source=lib.sh -. <(curl -sL https://raw.githubusercontent.com/nextcloud/vm/master/lib.sh) - -# Check for errors + debug code and abort if something isn't right -# 1 = ON -# 0 = OFF -DEBUG=0 -debug_mode - -# Check if root -root_check - -cat << MODSECWHITE > "/etc/modsecurity/whitelist.conf" - -# VIDEOS - SecRuleRemoveById 958291 # Range Header Checks - SecRuleRemoveById 981203 # Correlated Attack Attempt - - # PDF - SecRuleRemoveById 950109 # Check URL encodings - - # ADMIN (webdav) - SecRuleRemoveById 960024 # Repeatative Non-Word Chars (heuristic) - SecRuleRemoveById 981173 # SQL Injection Character Anomaly Usage - SecRuleRemoveById 981204 # Correlated Attack Attempt - SecRuleRemoveById 981243 # PHPIDS - Converted SQLI Filters - SecRuleRemoveById 981245 # PHPIDS - Converted SQLI Filters - SecRuleRemoveById 981246 # PHPIDS - Converted SQLI Filters - SecRuleRemoveById 981318 # String Termination/Statement Ending Injection Testing - SecRuleRemoveById 973332 # XSS Filters from IE - SecRuleRemoveById 973338 # XSS Filters - Category 3 - SecRuleRemoveById 981143 # CSRF Protections ( TODO edit LocationMatch filter ) - - # COMING BACK FROM OLD SESSION - SecRuleRemoveById 970903 # Microsoft Office document properties leakage - - # NOTES APP - SecRuleRemoveById 981401 # Content-Type Response Header is Missing and X-Content-Type-Options is either missing or not set to 'nosniff' - SecRuleRemoveById 200002 # Failed to parse request body - - # UPLOADS ( 5 MB max excluding file size ) - SecRequestBodyNoFilesLimit 5242880 - - # GENERAL - SecRuleRemoveById 960017 # Host header is a numeric IP address - - # SAMEORIGN - SecRuleRemoveById 911100 # fpm socket - - # REGISTERED WARNINGS, BUT DID NOT HAVE TO DISABLE THEM - #SecRuleRemoveById 981220 900046 981407 - #SecRuleRemoveById 981222 981405 981185 981184 - -MODSECWHITE