SpiderLabs / owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)
https://modsecurity.org/crs
Apache License 2.0
2.44k stars 725 forks source link

DOS protection is invalid #1723

Closed sule01u closed 4 years ago

sule01u commented 4 years ago

DOS protection is invalid, The same IP can be an unlimited number of requests, any other protection can work normally.

I use fstack + nginx-1.16.0 + mod security v3 + owasp-modsecurity-crs v3 ,has anyone had the same problem

Linux kernel mode can be protected normally