<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=ModSecurity_CRS_RuleID-981227</id>
		<title>ModSecurity CRS RuleID-981227 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=ModSecurity_CRS_RuleID-981227"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ModSecurity_CRS_RuleID-981227&amp;action=history"/>
		<updated>2026-04-27T20:20:56Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ModSecurity_CRS_RuleID-981227&amp;diff=110138&amp;oldid=prev</id>
		<title>Rcbarnett at 17:34, 9 May 2011</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ModSecurity_CRS_RuleID-981227&amp;diff=110138&amp;oldid=prev"/>
				<updated>2011-05-09T17:34:36Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 17:34, 9 May 2011&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l109&quot; &gt;Line 109:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 109:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''None known'''&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''None known'''&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Accuracy Level&lt;/del&gt;&amp;lt;/td&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Maturity&lt;/ins&gt;&amp;lt;/td&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;5&lt;/del&gt;''' &amp;lt;br&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;5 &lt;/del&gt;point scale where:&amp;lt;br&amp;gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;1 &lt;/del&gt;= Beta/Experimental &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and&lt;/del&gt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;or high number &lt;/del&gt;of &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;false positives reported&lt;/del&gt;&amp;lt;br&amp;gt;5 = &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Strong Rule and/or no &lt;/del&gt;false positives reported&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;'''&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;0&lt;/ins&gt;'''&amp;lt;br&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;10 &lt;/ins&gt;point scale &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;(0-9) &lt;/ins&gt;where:&amp;lt;br&amp;gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;0 &lt;/ins&gt;= Beta/Experimental &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;br&amp;gt;9 = Heavily Tested&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;&lt;/ins&gt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Accuracy&amp;lt;/td&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;'''9'''&amp;lt;br&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;10 point scale (0-9) where:&amp;lt;br&amp;gt;0 = High % &lt;/ins&gt;of &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;FP&lt;/ins&gt;&amp;lt;br&amp;gt;5 = &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;No &lt;/ins&gt;false positives reported&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Documentation Contributor(s)&amp;lt;/td&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Documentation Contributor(s)&amp;lt;/td&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Rcbarnett</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=ModSecurity_CRS_RuleID-981227&amp;diff=110073&amp;oldid=prev</id>
		<title>Rcbarnett: Created page with &quot;== Rule ID: 981227 ==  &lt;table style=&quot;border-style:double;border-width:3px;&quot; &gt; &lt;tr&gt;&lt;td style=&quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=ModSecurity_CRS_RuleID-981227&amp;diff=110073&amp;oldid=prev"/>
				<updated>2011-05-06T15:27:30Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Rule ID: 981227 ==  &amp;lt;table style=&amp;quot;border-style:double;border-width:3px;&amp;quot; &amp;gt; &amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Rule ID: 981227 ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;table style=&amp;quot;border-style:double;border-width:3px;&amp;quot; &amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule ID&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
981227&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Message&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Apache Error: Invalid URI in Request&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Summary&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Identify Invalid URIs Blocked by Apache&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Impact&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
4 - Warning&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
&amp;lt;code&amp;gt;&lt;br /&gt;
 SecRule WEBSERVER_ERROR_LOG &amp;quot;@contains Invalid URI in request&amp;quot; &amp;quot;phase:5,t:none,log,pass,msg:'Apache Error: Invalid URI in Request',id:'981227',rev:'2.2.0',&lt;br /&gt;
 logdata:'%{matched_var}',severity:'4',tag:'https://www.owasp.org/index.php/ModSecurity_CRS_RuleID-%{tx.id}',tag:'http://www.w3.org/Protocols/rfc2616/rfc2616-&lt;br /&gt;
 sec3.html#sec3.2.1',tag:'RULE_ACCURACY_LEVEL/5',setvar:'tx.msg=%{rule.msg}',setvar:'tx.id=%{rule.id}',setvar:tx.anomaly_score=+%{tx.notice_anomaly_score},&lt;br /&gt;
 setvar:tx.protocol_violation_score=+%{tx.notice_anomaly_score},setvar:'tx.%{rule.id}-PROTOCOL_VIOLATION/INVALID_REQ-%{matched_var_name}=%{matched_var}'&amp;quot;&amp;lt;/code&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Detailed Rule Information&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
 There are some request violations that Apache will handle internally, prior to the&lt;br /&gt;
 ModSecurity phase:1 POST-READ-REQUEST hook.  For these requests, we can still get&lt;br /&gt;
 visibility by running a check in phase:5 logging to look for the Apache error msg.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Example Payload&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Here is an example payloads taken from the access_log:&lt;br /&gt;
&lt;br /&gt;
 127.0.0.1 - - [06/May/2011:11:22:24 -0400] &amp;quot;\tGET / HTTP/1.1&amp;quot; 400 226&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Example Audit Log Entry&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Include an example ModSecurity Audit Log Entry for when this rule matchs.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
--57ae6b4f-A--&lt;br /&gt;
[06/May/2011:11:22:24 --0400] TcQSMMCoAWQAAKNEEHMAAAAA 127.0.0.1 62905 127.0.0.1 80&lt;br /&gt;
--57ae6b4f-B--&lt;br /&gt;
        GET / HTTP/1.1&lt;br /&gt;
Host: local&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7&lt;br /&gt;
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&lt;br /&gt;
&lt;br /&gt;
--57ae6b4f-F--&lt;br /&gt;
HTTP/1.1 400 Bad Request&lt;br /&gt;
Content-Length: 226&lt;br /&gt;
Connection: close&lt;br /&gt;
Content-Type: text/html; charset=iso-8859-1&lt;br /&gt;
&lt;br /&gt;
--57ae6b4f-E--&lt;br /&gt;
&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//IETF//DTD HTML 2.0//EN&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&lt;br /&gt;
&amp;lt;title&amp;gt;400 Bad Request&amp;lt;/title&amp;gt;&lt;br /&gt;
&amp;lt;/head&amp;gt;&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;h1&amp;gt;Bad Request&amp;lt;/h1&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;Your browser sent a request that this server could not understand.&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;br /&gt;
&lt;br /&gt;
--57ae6b4f-H--&lt;br /&gt;
Message: Warning. String match &amp;quot;Invalid URI in request&amp;quot; at WEBSERVER_ERROR_LOG. [file &amp;quot;/usr/local/apache/conf/crs/base_rules/modsecurity_crs_20_protocol_violations.conf&amp;quot;] &lt;br /&gt;
[line &amp;quot;51&amp;quot;] [id &amp;quot;981227&amp;quot;] [rev &amp;quot;2.2.0&amp;quot;] [msg &amp;quot;Apache Error: Invalid URI in Request&amp;quot;] [data &amp;quot;[file \x22core.c\x22] [line 3504] [level 3] Invalid URI in request \x5c\x5ctGET / HTTP/1.1&amp;quot;] &lt;br /&gt;
[severity &amp;quot;WARNING&amp;quot;] [tag &amp;quot;https://www.owasp.org/index.php/ModSecurity_CRS_RuleID-981227&amp;quot;] [tag &amp;quot;http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.2.1&amp;quot;] &lt;br /&gt;
[tag &amp;quot;RULE_CONFIDENCE_LEVEL/5&amp;quot;]&lt;br /&gt;
Apache-Error: [file &amp;quot;core.c&amp;quot;] [line 3504] [level 3] Invalid URI in request \\tGET / HTTP/1.1&lt;br /&gt;
Stopwatch: 1304695344229544 6998 (- - -)&lt;br /&gt;
Stopwatch2: 1304695344229544 6998; combined=5474, p1=0, p2=0, p3=140, p4=4392, p5=942, sr=0, sw=0, l=0, gc=0&lt;br /&gt;
Response-Body-Transformed: Dechunked&lt;br /&gt;
Producer: ModSecurity for Apache/2.6.0-rc2 (http://www.modsecurity.org/); core ruleset/2.2.0.&lt;br /&gt;
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.12 OpenSSL/0.9.8l DAV/2&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Attack Scenarios&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Some malformed URIs are created on purpose as part of HTTP fingerprinting scans - &lt;br /&gt;
 http://projects.webappsec.org/Fingerprinting&lt;br /&gt;
Other times, these are caused by poorly written web clients.&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Ease of Attack&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Easy&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Ease of Detection&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Easy with either regular expressions or by monitoring Apache error logging in phase:5&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;False Positives&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
'''None known'''&amp;lt;br&amp;gt;&lt;br /&gt;
If there are any known false positives - specify them here&lt;br /&gt;
Also sign-up for the Reporting False Positives mail-list here:&lt;br /&gt;
https://lists.sourceforge.net/lists/listinfo/mod-security-report-false-positives&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Send FP Report emails here:&amp;lt;br&amp;gt;&lt;br /&gt;
mod-security-report-false-positives[[Image:Justat.gif|10x]]lists.sourceforge.net&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;False Negatives&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
'''None known'''&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Accuracy Level&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
'''5''' &amp;lt;br&amp;gt;5 point scale where:&amp;lt;br&amp;gt;1 = Beta/Experimental and/or high number of false positives reported&amp;lt;br&amp;gt;5 = Strong Rule and/or no false positives reported&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Rule Documentation Contributor(s)&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
Ryan Barnett - ryan.barnett[[Image:Justat.gif|10px]]owasp.org&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;quot;border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase &amp;quot; &amp;gt;Additional References&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#F2F2F2;table-layout:fixed;width:700px;&amp;quot; &amp;gt;&lt;br /&gt;
http://www.w3.org/Protocols/rfc2616/rfc2616-sec3.html#sec3.2.1&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
[[Category:OWASP ModSecurity Core Rule Set Project]]&lt;/div&gt;</summary>
		<author><name>Rcbarnett</name></author>	</entry>

	</feed>