I’m just wondering what are the best rules that we can use in ModSecurity, not so agressive and not so soft. Also allow Google Bots and other things that may needed…
I see that the default one which CP is coming is :
SecRule ARGS “../” “t:normalisePathWin,id:99999,severity:4,msg:‘Drive Access’ ,log,auditlog,deny”,
But we can’t even save that since there is a small bug which is not allowing to save that… But still i don’t know if this is the best way for rules.
