Open edgreenberg opened 7 years ago
I'm having the exact same issue with the same pattern - "!@#" at the end of password ARG
We are facing the same issue. The user's password ends in !@#
.
Not to raise a corpose, but was a workaround ever discovered? Is it literally those 3 specific characters in that specific order? Is it that it can't end with a # symbol? Is it because those 3 characters in that order can't be at the end?
ModSecurity reports:
I'm not sure what it's objecting to. It's pretty clear that I'm going to have to disable the rule, but I was hoping for an explanation.
Taking a look at fingerprints2sqli.py I don't see how il0vegrandpa!@# translates into anything offensive.