Hello. I hope everyone is healthy and safe.
mod_security keeps flagging the following activity as malicous. When I reported it to Amazon they forward to party doing the scanning and their response is that they are just looking for robots.txt. However the log, below, appears a bit more than just looking for robots.txt.
Here it is and can someone weigh in on what it's about:
[Thu Feb 02 08:01:23.986104 2023] [:error] [pid 7088:tid 47276049303296] [clientxxxxxx:34986] [clientxxxxxx] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(?
?:\\\\*|[^\\"(),\\\\/:;<=>?![\\\\x5c\\\\]{}]+)\\\\/(?:\\\\*|[^\\"(),\\\\/:;<=>?![\\\\x5c\\\\]{}]+))(?:\\\\s*+;\\\\s*+(?
?:charset\\\\s*+=\\\\s*+(?:\\"?(?:iso-8859-15?|windows-1252|utf-8)\\\\b\\"?))|(?
?:c(?:h(?:a(?:r(?:s(?:e[^t\\"(),\\\\/:;<=>?![\\\\x5c\\\\]{}]|[^e\\"(),/:;<=>?![\\\\x5c ..." against "REQUEST_HEADERS:Accept" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1162"] [id "920600"] [msg "Illegal Accept header: charset parameter"] [data "text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [hostname "xxxxx.com"]
[uri "/robots.txt"] [unique_id
mod_security keeps flagging the following activity as malicous. When I reported it to Amazon they forward to party doing the scanning and their response is that they are just looking for robots.txt. However the log, below, appears a bit more than just looking for robots.txt.
Here it is and can someone weigh in on what it's about:
[Thu Feb 02 08:01:23.986104 2023] [:error] [pid 7088:tid 47276049303296] [clientxxxxxx:34986] [clientxxxxxx] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(?
[uri "/robots.txt"] [unique_id