Yeah, mod_security is the way to go!

Regarding your PROP* requests, it's just the mod_security config - there are some rules that limit valid requests to GET|HEAD|POST, which does not work for SVN.

Have fun!

Brett Patterson wrote:
Hi All!!!

I'm not sure who maintains the trac site, or who maintains the server that roundcube is on; however, if you can use Mod_Security from www.modescurity.org I'd suggest it. As of today, there's a project called "ScallyWack" which is a set of rules for mod_security that is for Trac Spam ;) Something worth looking into.

http://www.modsecurity.org/blog/archives/2007/06/scalywack_modse.html

There seems to be a small pitfall. I'm trying to get SVN working on my server with mod_security installed, but hitting a few bumps with it catching the PROP* and other REQUEST_METHODs. Not sure if it's my mod_security config, or I'm just not noticing something.

Anyway.... it's just a suggestion so we can get our Trac back!!

~Brett



--
Michael Baierl
mbaierl.com   http://mbaierl.com/
- - - - - - - - - - - - - - - - -
"Everything should be made as simple as possible, but not simpler" --Albert Einstein


Reply via email to