Re: Issue with ModSecurity and my proxy

Felipe Costa <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <MN2PR07MB6094269B08C645F915E99043C86E0@MN2PR07MB6094.namprd07.prod.outlook.com>
Hi,


ModSecurity uses libCurl to download the rules. If it works with the command line `curl', it is likely to work with the library as well.


Make sure that the proxy variable is also set for your httpd user. During the startup process, Apache may change users losing the environment variables that you have set in your console.


Br.,

Felipe "Zimmerle" Costa

Security Researcher, Lead Developer ModSecurity

m: +55 81.98706.5547



[signature_480191669]

www.trustwave.com<http://www.trustwave.com/>



Recognized by industry analysts as a leader in managed security services.<https://www.trustwave.com/company/about-us/accolades/>


________________________________
From: service maintenanceinfotel <[email protected]>
Sent: Monday, February 4, 2019 3:10:47 PM
To: [email protected]
Cc: FONTVIELLE Thibault; [email protected]; [email protected]
Subject: [mod-security-users] Issue with ModSecurity and my proxy


Hello Community,



Here’s my problem :



The server where I have to install ModSecurity must pass by a proxy server to join internet



Therefore, I configure this on my debian :



export http_proxy=http://myproxy.com:8080

export https_proxy=http://myproxy.com:8080



Then, ModSecurity has to download the https://dashboard.modsecurity.org/rules/download/plain<https://scanmail.trustwave.com/?c=4062&d=gPnY3CFFaGiyHevQZVijsBqHuTG8GzOh4-c8x8Yz9Q&s=5&u=https%3a%2f%2fdashboard%2emodsecurity%2eorg%2frules%2fdownload%2fplain>



Here’s what happen on my WAF server when I reload apache2 :



[cid:[email protected]]



We have a TCP RETRANSMISSION



But when I try to wget on this link, it works :



[cid:[email protected]]



It takes into account my export http_proxy from before



And If I try this wget on my proxy server, of course it works :



[cid:[email protected]]



My proxy doesn’t block the link



When I reload apache and tshark the 443 on my proxy, I don’t see anything : no accept, no reject etc…



There’s nothing between my proxy and my WAF



My theory is that ModSecurity does not take into account the proxy rules I’ve set on my debian OS



So, If you don’t see any other source about my problem, my main question is :



How to force ModSecurity to pass by my proxy to download and synchronize the rules ?



Thank you for your help



Regards,



BC



Ce message est confidentiel. Son contenu ne represente en aucun cas un
engagement de la part de la Mutuelle Saint-Christophe assurances sous reserve de
tout accord conclu par ecrit entre vous et la Mutuelle Saint-Christophe assurances.
Toute publication, utilisation ou diffusion, meme partielle, doit etre
autorisee prealablement. Si vous n'etes pas destinataire de ce message,
merci d'en avertir immediatement l'expediteur.

This message is confidential. Its contents do not constitute a
commitment by Mutuelle Saint-Christophe assurances except where provided for in
a written agreement between you and Mutuelle Saint-Christophe assurances. Any
unauthorised disclosure, use or dissemination, either whole or partial, is
prohibited. If you are not the intended recipient of the message, please
notify the sender immediately.

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
image002.jpg (image/jpeg, 29.9 KB) - not displayed
image001.jpg (image/jpeg, 39.4 KB) - not displayed
image003.jpg (image/jpeg, 17.4 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.