Our company site is behind WAF based on NGINX ModSecurity. And permanently in WAF logs we see blocked requests from site forms. Example:
SQL Injection Attack Detected via libinjection - Matched Data: sos found within ARGS:BoxOrgName: %u041e%u041e%u041e "%u0422%u0440%u0438%u043e+"
Why it happens? This string:
%u041e%u041e%u041e "%u0422%u0440%u0438%u043e+"
is just Cyrillic company name:
ООО "Трио+"
How and what can we configure in mod_security to prevent such wrong request blocking?