Re: Trying out "early blocking"
CM via mod-security-users <[email protected]> Tue, 27 May 2025 03:24:37 +0000
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <2XeQ7cFKK7i0RR6XvGRc_duxL5NtCVk2ERryUSTaBYvMB8EW5vEVcaSUAhbxk5PInXduVfMiTGVMn4lw03k0JYm_Wy1KnDT15pl6jxVYp8E=@protonmail.com> |
--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable But the purpose of early blocking is to block requests that Apache would ha= ve otherwise redirected, is it not? Your 200 OK implies that there's no redirection in place, so even though yo= ur log claimed that early blocking happened (my logs claim that too), it's = insufficient to prove that the redirect-prevention functionality is actuall= y functioning. What I'm seeing is that even though the logs claim early blocking is happen= ing, Apache is still able to perform redirects as normal on those requests. Refer to attached auditlog1.txt where a score-14 request is answered with a= 308 redirect to another site even though the log claims "Access denied wit= h code 403 (phase 1)" (you won't see all the rules it matched because I pu= t noauditlog on some of the 3-point rules, in total it violated 3 3-point r= ules (noauditlog'd) and 1 5-point rule, for a total score of 14) after doing some additional testing, this seems to be an incompatibility be= tween early blocking and Apache's "ErrorDocument 403" directive. If I disa= ble "ErrorDocument 403" then early blocking is actually able to prevent red= irects but I don't really want to do that. "ErrorDocument" when pointing t= o an internal URL is supposed to do a transparent, internal rewrite rather = than a redirect, but it sometimes has weird esoteric interactions and incom= patibilities, and it appears incompatibility with early blocking is one of = them so my next thought was to try to do early blocking with something other tha= n a 403, using some code I don't have an ErrorDocument for, such as a 429 So I go to RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf and try to modify ea= rly blocking rule 949111 like this: SecRuleUpdateActionById 949111 "t:none,deny,status:429" but this breaks my entire server and causes **all** requests to be rejected= with a 429, even score-0 requests see attached auditlog2.txt where a perfect score-0 request is rejected with= a 429 Message: Access denied with code 429 (phase 1). [file "/usr/local/corerules= et/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "221"] [id "949111"] = [msg "Inbound Anomaly Score Exceeded in phase 1 (Total Score: 0)"] [ver "OW= ASP_CRS/4.14.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] So I'm at a loss about how to proceed from here, other than turning off ear= ly blocking, and probably going back to an older CRS version, since my only= reason for testing out CRS4 was because I thought I would be able to get e= arly blocking to work. Sent with Proton Mail secure email. On Monday, May 12th, 2025 at 3:43 AM, Ervin Heged=C3=BCs <[email protected]= > wrote: > Hi CM, >=20 > I was able to check that with the "regular" build options (that I > mentioned previously - Debian and Ubuntu feliver their packages > with those options. >=20 > Also I checked crs-setup.conf and enabled early blocking > mechanism: >=20 > https://github.com/coreruleset/coreruleset/blob/main/crs-setup.conf.examp= le#L413-L421 >=20 > I set up my config to use CRS on PL4 (to be sure that engine runs > as many rules as possible). >=20 > Then I sent a minimal but invalid request with telnet command: >=20 > telnet localhost 80 > Trying ::1... > Connected to localhost. > Escape character is '^]'. > GET / HTTP/1.1 > Host: 127.0.0.1 >=20 > HTTP/1.1 200 OK > Date: Mon, 12 May 2025 08:32:07 GMT > Server: Apache/2.4.63 (Debian) > Content-Length: 0 >=20 > Errors in this request: > * `Host` is an IP address - rule 920350 > * `User-Agent` header is missing - rule 920320 >=20 > These two rules collect 5 points which is enough to trigger rule > 949111, which is responsible to deny the request in phase:1 >=20 > https://github.com/coreruleset/coreruleset/blob/main/rules/REQUEST-949-BL= OCKING-EVALUATION.conf#L212-L222 >=20 > Here is the log: >=20 > ModSecurity: Warning. Operator EQ matched 1 at TX:early_blocking. [file "= /home/airween/src/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] = [line "221"] [id "949111"] [msg "Inbound Anomaly Score Exceeded in phase 1 = (Total Score: 5)"] [ver "OWASP_CRS/4.15.0-dev"] >=20 > (I get response 200 because the engine is in DetectionOnly mode, > and this is why you see "ModSecurity: Warning", and not "Access > Denied) >=20 > I think early blocking works as we expected. >=20 >=20 > Please check your config again - hope this summary helps you. >=20 >=20 > Regards, >=20 >=20 > a. --b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks Content-Type: text/plain; name=auditlog1.txt Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename=auditlog1.txt LS1lYzY3ODMzYi1BLS0KWzI2L01heS8yMDI1OjIxOjMwOjI1LjM2OTE3MCAtLTA1MDBdIGFEVWp3 VmdRVkxvc0N6N1JVMS1EY1FBQUFFVSAoQ0xJRU5UX0lQKSA2MTYxNCAoU0VSVkVSX0lQKSA0NDMK LS1lYzY3ODMzYi1CLS0KUE9TVCAvLmVudiBIVFRQLzEuMQpIb3N0OiBob3N0bmFtZTEKVXNlci1B Z2VudDogY3VybC84LjUuMApBY2NlcHQ6ICovKgpDb25uZWN0aW9uOiBrZWVwLWFsaXZlLCBjbG9z ZQpSZXF1ZXN0LVJhbmdlOiAzLTEKCi0tZWM2NzgzM2ItRi0tCkhUVFAvMS4xIDMwOCBQZXJtYW5l bnQgUmVkaXJlY3QKTG9jYXRpb246IGh0dHBzOi8vaG9zdG5hbWUyLwpDb250ZW50LUxlbmd0aDog NDMwCkNvbm5lY3Rpb246IGNsb3NlCkNvbnRlbnQtVHlwZTogdGV4dC9odG1sOyBjaGFyc2V0PWlz by04ODU5LTEKCi0tZWM2NzgzM2ItRS0tCgotLWVjNjc4MzNiLUgtLQpNZXNzYWdlOiBNYXRjaGVk IHBocmFzZSAiLmVudiIgYXQgUkVRVUVTVF9GSUxFTkFNRS4gW2ZpbGUgIi91c3IvbG9jYWwvY29y ZXJ1bGVzZXQvcnVsZXMvUkVRVUVTVC05MzAtQVBQTElDQVRJT04tQVRUQUNLLUxGSS5jb25mIl0g W2xpbmUgIjE0NyJdIFtpZCAiOTMwMTMwIl0gW21zZyAiUmVzdHJpY3RlZCBGaWxlIEFjY2VzcyBB dHRlbXB0Il0gW2RhdGEgIk1hdGNoZWQgRGF0YTogLmVudiBmb3VuZCB3aXRoaW4gUkVRVUVTVF9G SUxFTkFNRTogLy5lbnYiXSBbc2V2ZXJpdHkgIkNSSVRJQ0FMIl0gW3ZlciAiT1dBU1BfQ1JTLzQu MTQuMCJdIFt0YWcgImFwcGxpY2F0aW9uLW11bHRpIl0gW3RhZyAibGFuZ3VhZ2UtbXVsdGkiXSBb dGFnICJwbGF0Zm9ybS1tdWx0aSJdIFt0YWcgImF0dGFjay1sZmkiXSBbdGFnICJwYXJhbm9pYS1s ZXZlbC8xIl0gW3RhZyAiT1dBU1BfQ1JTIl0gW3RhZyAiT1dBU1BfQ1JTL0FUVEFDSy1MRkkiXSBb dGFnICJjYXBlYy8xMDAwLzI1NS8xNTMvMTI2Il0gW3RhZyAiUENJLzYuNS40Il0KTWVzc2FnZTog QWNjZXNzIGRlbmllZCB3aXRoIGNvZGUgNDAzIChwaGFzZSAxKS4gW2ZpbGUgIi91c3IvbG9jYWwv Y29yZXJ1bGVzZXQvcnVsZXMvUkVRVUVTVC05NDktQkxPQ0tJTkctRVZBTFVBVElPTi5jb25mIl0g W2xpbmUgIjIyMSJdIFtpZCAiOTQ5MTExIl0gW21zZyAiSW5ib3VuZCBBbm9tYWx5IFNjb3JlIEV4 Y2VlZGVkIGluIHBoYXNlIDEgKFRvdGFsIFNjb3JlOiAxNCkiXSBbdmVyICJPV0FTUF9DUlMvNC4x NC4wIl0gW3RhZyAiYW5vbWFseS1ldmFsdWF0aW9uIl0gW3RhZyAiT1dBU1BfQ1JTIl0KQWN0aW9u OiBJbnRlcmNlcHRlZCAocGhhc2UgMSkKU3RvcHdhdGNoOiAxNzQ4MzEzMDI1MzY3NzQ3IDE0NDIg KC0gLSAtKQpTdG9wd2F0Y2gyOiAxNzQ4MzEzMDI1MzY3NzQ3IDE0NDI7IGNvbWJpbmVkPTgyNSwg cDE9NzcwLCBwMj0wLCBwMz0wLCBwND0wLCBwNT01NSwgc3I9MCwgc3c9MCwgbD0wLCBnYz0wClJl c3BvbnNlLUJvZHktVHJhbnNmb3JtZWQ6IERlY2h1bmtlZApQcm9kdWNlcjogTW9kU2VjdXJpdHkg Zm9yIEFwYWNoZS8yLjkuNyAoaHR0cDovL3d3dy5tb2RzZWN1cml0eS5vcmcvKTsgT1dBU1BfQ1JT LzQuMTQuMC4KU2VydmVyOiBBcGFjaGUvMi40LjU4IChVYnVudHUpIE9wZW5TU0wvMy4wLjEzCkVu Z2luZS1Nb2RlOiAiRU5BQkxFRCIKCi0tZWM2NzgzM2ItWi0t --b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks Content-Type: text/plain; name=auditlog2.txt Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename=auditlog2.txt LS1iNzlhZjQyOC1BLS0KWzI2L01heS8yMDI1OjIyOjA2OjIwLjc0MjAwOCAtLTA1MDBdIGFEVXNM SmhqTEZteTFYRGwxLXo0Z1FBQVN3QSAoY2xpZW50SVApIDYxNzY2IChzZXJ2ZXJJUCkgNDQzCi0t Yjc5YWY0MjgtQi0tCkdFVCAvIEhUVFAvMi4wClVzZXItQWdlbnQ6IGN1cmwvOC41LjAKQWNjZXB0 OiAqLyoKSG9zdDogaG9zdG5hbWUKCi0tYjc5YWY0MjgtRi0tCkhUVFAvMS4xIDQyOSBUb28gTWFu eSBSZXF1ZXN0cwpDb250ZW50LUxlbmd0aDogNDMyCkNvbm5lY3Rpb246IGNsb3NlCkNvbnRlbnQt VHlwZTogdGV4dC9odG1sOyBjaGFyc2V0PWlzby04ODU5LTEKRGF0ZTogVHVlLCAyNyBNYXkgMjAy NSAwMzowNjoyMCBHTVQKU2VydmVyOiBBcGFjaGUgbW9kX2ZjZ2lkLzIuMy45IG1vZF9wZXJsLzIu MC4xMyBQZXJsL3Y1LjM4LjIKCi0tYjc5YWY0MjgtRS0tCgotLWI3OWFmNDI4LUgtLQpNZXNzYWdl OiBBY2Nlc3MgZGVuaWVkIHdpdGggY29kZSA0MjkgKHBoYXNlIDEpLiBbZmlsZSAiL3Vzci9sb2Nh bC9jb3JlcnVsZXNldC9ydWxlcy9SRVFVRVNULTk0OS1CTE9DS0lORy1FVkFMVUFUSU9OLmNvbmYi XSBbbGluZSAiMjIxIl0gW2lkICI5NDkxMTEiXSBbbXNnICJJbmJvdW5kIEFub21hbHkgU2NvcmUg RXhjZWVkZWQgaW4gcGhhc2UgMSAoVG90YWwgU2NvcmU6IDApIl0gW3ZlciAiT1dBU1BfQ1JTLzQu MTQuMCJdIFt0YWcgImFub21hbHktZXZhbHVhdGlvbiJdIFt0YWcgIk9XQVNQX0NSUyJdCkFjdGlv bjogSW50ZXJjZXB0ZWQgKHBoYXNlIDEpClN0b3B3YXRjaDogMTc0ODMxNTE4MDc0MDQxNyAxNjEx ICgtIC0gLSkKU3RvcHdhdGNoMjogMTc0ODMxNTE4MDc0MDQxNyAxNjExOyBjb21iaW5lZD04MDUs IHAxPTcxOSwgcDI9MCwgcDM9MCwgcDQ9MCwgcDU9ODUsIHNyPTAsIHN3PTEsIGw9MCwgZ2M9MApS ZXNwb25zZS1Cb2R5LVRyYW5zZm9ybWVkOiBEZWNodW5rZWQKUHJvZHVjZXI6IE1vZFNlY3VyaXR5 IGZvciBBcGFjaGUvMi45LjcgKGh0dHA6Ly93d3cubW9kc2VjdXJpdHkub3JnLyk7IE9XQVNQX0NS Uy80LjE0LjAuClNlcnZlcjogQXBhY2hlLzIuNC41OCAoVWJ1bnR1KSBPcGVuU1NMLzMuMC4xMwpF bmdpbmUtTW9kZTogIkVOQUJMRUQiCgotLWI3OWFmNDI4LVotLQ== --b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ --b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks--