[prev in list] [next in list] [prev in thread] [next in thread] 

List:       mod-security-users
Subject:    Re: [mod-security-users] nginx segfaulting with mod_security
From:       Robert Paprocki <rpaprocki () fearnothingproductions ! net>
Date:       2014-04-16 20:42:47
Message-ID: 534EEB47.9070908 () fearnothingproductions ! net
[Download RAW message or body]

Hi Felipe,

I am p0pr0ck5 :D

This patch seems to have worked so far, I think you emailed me thinking
I was @akamatgi, so there's a bit of a mixup there. I'll keep testing
this and let you guys know if there's anything else that comes up

On 04/16/2014 01:11 PM, Felipe Costa wrote:
> Hi Robert,
> 
> On Apr 12, 2014, at 8:49 PM, Robert Paprocki
> <rpaprocki@fearnothingproductions.net
> <mailto:rpaprocki@fearnothingproductions.net>> wrote:
> 
>> I have compiled nginx-1.5.13 with modsecurity-2.7.7 and am seeing
>> occasional segfaults when sending requests to the server. mod_security
>> was compiled as a standalone module per the instructions made available
>> at
>> https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX.
>> The segfaults appear sporadic and do not seem to match up with any given
>> request. 
> 
> Thank you for the report with all the details that we need to
> investigate the problem.
> 
> We have recently received an report of an issues that I believe is
> similar from what you are facing, the details are available here:
> https://github.com/SpiderLabs/ModSecurity/issues/681
> 
> As you can see in the issue @akamatgi is suggesting a patch. Also,
> @p0pr0ck5 is helping with some tests. I have asked @akamatgi to submit
> the patches in a pull request format this morning. This not went to our
> buildbots yet.
> 
> 
> Br.,
> *Felipe "Zimmerle" Costa*
> Security Researcher, SpiderLabs
> 
> *Trustwave* | SMART SECURITY ON DEMAND
> www.trustwave.com <http://www.trustwave.com/>
> 
> 
> 
> 
> 
> 
> ------------------------------------------------------------------------
> 
> This transmission may contain information that is privileged,
> confidential, and/or exempt from disclosure under applicable law. If you
> are not the intended recipient, you are hereby notified that any
> disclosure, copying, distribution, or use of the information contained
> herein (including any reliance thereon) is strictly prohibited. If you
> received this transmission in error, please immediately contact the
> sender and destroy the material in its entirety, whether in electronic
> or hard copy format.
> 
> 
> ------------------------------------------------------------------------------
> Learn Graph Databases - Download FREE O'Reilly Book
> "Graph Databases" is the definitive new guide to graph databases and their
> applications. Written by three acclaimed leaders in the field,
> this first edition is now available. Download your free book today!
> http://p.sf.net/sfu/NeoTech
> 
> 
> 
> _______________________________________________
> mod-security-users mailing list
> mod-security-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
> 

------------------------------------------------------------------------------
Learn Graph Databases - Download FREE O'Reilly Book
"Graph Databases" is the definitive new guide to graph databases and their
applications. Written by three acclaimed leaders in the field,
this first edition is now available. Download your free book today!
http://p.sf.net/sfu/NeoTech
_______________________________________________
mod-security-users mailing list
mod-security-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic