I have two websites.
http://example1.com/project1/login.php
http://example2.com/project2/login.php
Both need to log in to use. And they send username and password to
/project1/action1/login_submit1.php
/project2/action2/login_submit2.php
I wrote a rule to block it.
<Location /project1/action1/login_submit1.php>
SecAction "initcol:IP=%{REMOTE_ADDR},pass,nolog,id:5554"
SecRule IP:bf_block "@eq 1" \
"id:5555,deny,\
msg:'IP address blocked because of suspected brute-force attack'"
SecRule REQUEST_METHOD "^POST$" "auditlog,pass,id:5556,chain"
SecRule RESPONSE_STATUS "^[200]" "setvar:IP.bf_counter=+1"
SecRule IP:bf_counter "@ge 3" \
"id:5557,auditlog, phase:5,pass,t:none, \
setvar:IP.bf_block=1,\
setvar:!IP.bf_counter,\
expirevar:IP.bf_block=30"
</Location>
But it still blocks attack on single web because it uses Location tag. Now, i want to custom a rule to protect both web from brute force attacks. It means that rule can used by any web apps. So any ideas for it.