Re: Trying out "early blocking"

CM via mod-security-users <[email protected]> Tue, 27 May 2025 03:24:37 +0000
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <2XeQ7cFKK7i0RR6XvGRc_duxL5NtCVk2ERryUSTaBYvMB8EW5vEVcaSUAhbxk5PInXduVfMiTGVMn4lw03k0JYm_Wy1KnDT15pl6jxVYp8E=@protonmail.com>
--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

But the purpose of early blocking is to block requests that Apache would ha=
ve otherwise redirected, is it not?

Your 200 OK implies that there's no redirection in place, so even though yo=
ur log claimed that early blocking happened (my logs claim that too), it's =
insufficient to prove that the redirect-prevention functionality is actuall=
y functioning.

What I'm seeing is that even though the logs claim early blocking is happen=
ing, Apache is still able to perform redirects as normal on those requests.

Refer to attached auditlog1.txt where a score-14 request is answered with a=
 308 redirect to another site even though the log claims "Access denied wit=
h code 403 (phase 1)"  (you won't see all the rules it matched because I pu=
t noauditlog on some of the 3-point rules, in total it violated 3 3-point r=
ules (noauditlog'd) and 1 5-point rule, for a total score of 14)

after doing some additional testing, this seems to be an incompatibility be=
tween early blocking and Apache's "ErrorDocument 403" directive.  If I disa=
ble "ErrorDocument 403" then early blocking is actually able to prevent red=
irects but I don't really want to do that.  "ErrorDocument" when pointing t=
o an internal URL is supposed to do a transparent, internal rewrite rather =
than a redirect, but it sometimes has weird esoteric interactions and incom=
patibilities, and it appears incompatibility with early blocking is one of =
them

so my next thought was to try to do early blocking with something other tha=
n a 403, using some code I don't have an ErrorDocument for, such as a 429

So I go to RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf and try to modify ea=
rly blocking rule 949111 like this:

SecRuleUpdateActionById 949111 "t:none,deny,status:429"

but this breaks my entire server and causes **all** requests to be rejected=
 with a 429, even score-0 requests

see attached auditlog2.txt where a perfect score-0 request is rejected with=
 a 429

Message: Access denied with code 429 (phase 1). [file "/usr/local/corerules=
et/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "221"] [id "949111"] =
[msg "Inbound Anomaly Score Exceeded in phase 1 (Total Score: 0)"] [ver "OW=
ASP_CRS/4.14.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"]

So I'm at a loss about how to proceed from here, other than turning off ear=
ly blocking, and probably going back to an older CRS version, since my only=
 reason for testing out CRS4 was because I thought I would be able to get e=
arly blocking to work.







Sent with Proton Mail secure email.

On Monday, May 12th, 2025 at 3:43 AM, Ervin Heged=C3=BCs <[email protected]=
> wrote:

> Hi CM,
>=20
> I was able to check that with the "regular" build options (that I
> mentioned previously - Debian and Ubuntu feliver their packages
> with those options.
>=20
> Also I checked crs-setup.conf and enabled early blocking
> mechanism:
>=20
> https://github.com/coreruleset/coreruleset/blob/main/crs-setup.conf.examp=
le#L413-L421
>=20
> I set up my config to use CRS on PL4 (to be sure that engine runs
> as many rules as possible).
>=20
> Then I sent a minimal but invalid request with telnet command:
>=20
> telnet localhost 80
> Trying ::1...
> Connected to localhost.
> Escape character is '^]'.
> GET / HTTP/1.1
> Host: 127.0.0.1
>=20
> HTTP/1.1 200 OK
> Date: Mon, 12 May 2025 08:32:07 GMT
> Server: Apache/2.4.63 (Debian)
> Content-Length: 0
>=20
> Errors in this request:
> * `Host` is an IP address - rule 920350
> * `User-Agent` header is missing - rule 920320
>=20
> These two rules collect 5 points which is enough to trigger rule
> 949111, which is responsible to deny the request in phase:1
>=20
> https://github.com/coreruleset/coreruleset/blob/main/rules/REQUEST-949-BL=
OCKING-EVALUATION.conf#L212-L222
>=20
> Here is the log:
>=20
> ModSecurity: Warning. Operator EQ matched 1 at TX:early_blocking. [file "=
/home/airween/src/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] =
[line "221"] [id "949111"] [msg "Inbound Anomaly Score Exceeded in phase 1 =
(Total Score: 5)"] [ver "OWASP_CRS/4.15.0-dev"]
>=20
> (I get response 200 because the engine is in DetectionOnly mode,
> and this is why you see "ModSecurity: Warning", and not "Access
> Denied)
>=20
> I think early blocking works as we expected.
>=20
>=20
> Please check your config again - hope this summary helps you.
>=20
>=20
> Regards,
>=20
>=20
> a.
--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks
Content-Type: text/plain; name=auditlog1.txt
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=auditlog1.txt

LS1lYzY3ODMzYi1BLS0KWzI2L01heS8yMDI1OjIxOjMwOjI1LjM2OTE3MCAtLTA1MDBdIGFEVWp3
VmdRVkxvc0N6N1JVMS1EY1FBQUFFVSAoQ0xJRU5UX0lQKSA2MTYxNCAoU0VSVkVSX0lQKSA0NDMK
LS1lYzY3ODMzYi1CLS0KUE9TVCAvLmVudiBIVFRQLzEuMQpIb3N0OiBob3N0bmFtZTEKVXNlci1B
Z2VudDogY3VybC84LjUuMApBY2NlcHQ6ICovKgpDb25uZWN0aW9uOiBrZWVwLWFsaXZlLCBjbG9z
ZQpSZXF1ZXN0LVJhbmdlOiAzLTEKCi0tZWM2NzgzM2ItRi0tCkhUVFAvMS4xIDMwOCBQZXJtYW5l
bnQgUmVkaXJlY3QKTG9jYXRpb246IGh0dHBzOi8vaG9zdG5hbWUyLwpDb250ZW50LUxlbmd0aDog
NDMwCkNvbm5lY3Rpb246IGNsb3NlCkNvbnRlbnQtVHlwZTogdGV4dC9odG1sOyBjaGFyc2V0PWlz
by04ODU5LTEKCi0tZWM2NzgzM2ItRS0tCgotLWVjNjc4MzNiLUgtLQpNZXNzYWdlOiBNYXRjaGVk
IHBocmFzZSAiLmVudiIgYXQgUkVRVUVTVF9GSUxFTkFNRS4gW2ZpbGUgIi91c3IvbG9jYWwvY29y
ZXJ1bGVzZXQvcnVsZXMvUkVRVUVTVC05MzAtQVBQTElDQVRJT04tQVRUQUNLLUxGSS5jb25mIl0g
W2xpbmUgIjE0NyJdIFtpZCAiOTMwMTMwIl0gW21zZyAiUmVzdHJpY3RlZCBGaWxlIEFjY2VzcyBB
dHRlbXB0Il0gW2RhdGEgIk1hdGNoZWQgRGF0YTogLmVudiBmb3VuZCB3aXRoaW4gUkVRVUVTVF9G
SUxFTkFNRTogLy5lbnYiXSBbc2V2ZXJpdHkgIkNSSVRJQ0FMIl0gW3ZlciAiT1dBU1BfQ1JTLzQu
MTQuMCJdIFt0YWcgImFwcGxpY2F0aW9uLW11bHRpIl0gW3RhZyAibGFuZ3VhZ2UtbXVsdGkiXSBb
dGFnICJwbGF0Zm9ybS1tdWx0aSJdIFt0YWcgImF0dGFjay1sZmkiXSBbdGFnICJwYXJhbm9pYS1s
ZXZlbC8xIl0gW3RhZyAiT1dBU1BfQ1JTIl0gW3RhZyAiT1dBU1BfQ1JTL0FUVEFDSy1MRkkiXSBb
dGFnICJjYXBlYy8xMDAwLzI1NS8xNTMvMTI2Il0gW3RhZyAiUENJLzYuNS40Il0KTWVzc2FnZTog
QWNjZXNzIGRlbmllZCB3aXRoIGNvZGUgNDAzIChwaGFzZSAxKS4gW2ZpbGUgIi91c3IvbG9jYWwv
Y29yZXJ1bGVzZXQvcnVsZXMvUkVRVUVTVC05NDktQkxPQ0tJTkctRVZBTFVBVElPTi5jb25mIl0g
W2xpbmUgIjIyMSJdIFtpZCAiOTQ5MTExIl0gW21zZyAiSW5ib3VuZCBBbm9tYWx5IFNjb3JlIEV4
Y2VlZGVkIGluIHBoYXNlIDEgKFRvdGFsIFNjb3JlOiAxNCkiXSBbdmVyICJPV0FTUF9DUlMvNC4x
NC4wIl0gW3RhZyAiYW5vbWFseS1ldmFsdWF0aW9uIl0gW3RhZyAiT1dBU1BfQ1JTIl0KQWN0aW9u
OiBJbnRlcmNlcHRlZCAocGhhc2UgMSkKU3RvcHdhdGNoOiAxNzQ4MzEzMDI1MzY3NzQ3IDE0NDIg
KC0gLSAtKQpTdG9wd2F0Y2gyOiAxNzQ4MzEzMDI1MzY3NzQ3IDE0NDI7IGNvbWJpbmVkPTgyNSwg
cDE9NzcwLCBwMj0wLCBwMz0wLCBwND0wLCBwNT01NSwgc3I9MCwgc3c9MCwgbD0wLCBnYz0wClJl
c3BvbnNlLUJvZHktVHJhbnNmb3JtZWQ6IERlY2h1bmtlZApQcm9kdWNlcjogTW9kU2VjdXJpdHkg
Zm9yIEFwYWNoZS8yLjkuNyAoaHR0cDovL3d3dy5tb2RzZWN1cml0eS5vcmcvKTsgT1dBU1BfQ1JT
LzQuMTQuMC4KU2VydmVyOiBBcGFjaGUvMi40LjU4IChVYnVudHUpIE9wZW5TU0wvMy4wLjEzCkVu
Z2luZS1Nb2RlOiAiRU5BQkxFRCIKCi0tZWM2NzgzM2ItWi0t

--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks
Content-Type: text/plain; name=auditlog2.txt
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=auditlog2.txt

LS1iNzlhZjQyOC1BLS0KWzI2L01heS8yMDI1OjIyOjA2OjIwLjc0MjAwOCAtLTA1MDBdIGFEVXNM
SmhqTEZteTFYRGwxLXo0Z1FBQVN3QSAoY2xpZW50SVApIDYxNzY2IChzZXJ2ZXJJUCkgNDQzCi0t
Yjc5YWY0MjgtQi0tCkdFVCAvIEhUVFAvMi4wClVzZXItQWdlbnQ6IGN1cmwvOC41LjAKQWNjZXB0
OiAqLyoKSG9zdDogaG9zdG5hbWUKCi0tYjc5YWY0MjgtRi0tCkhUVFAvMS4xIDQyOSBUb28gTWFu
eSBSZXF1ZXN0cwpDb250ZW50LUxlbmd0aDogNDMyCkNvbm5lY3Rpb246IGNsb3NlCkNvbnRlbnQt
VHlwZTogdGV4dC9odG1sOyBjaGFyc2V0PWlzby04ODU5LTEKRGF0ZTogVHVlLCAyNyBNYXkgMjAy
NSAwMzowNjoyMCBHTVQKU2VydmVyOiBBcGFjaGUgbW9kX2ZjZ2lkLzIuMy45IG1vZF9wZXJsLzIu
MC4xMyBQZXJsL3Y1LjM4LjIKCi0tYjc5YWY0MjgtRS0tCgotLWI3OWFmNDI4LUgtLQpNZXNzYWdl
OiBBY2Nlc3MgZGVuaWVkIHdpdGggY29kZSA0MjkgKHBoYXNlIDEpLiBbZmlsZSAiL3Vzci9sb2Nh
bC9jb3JlcnVsZXNldC9ydWxlcy9SRVFVRVNULTk0OS1CTE9DS0lORy1FVkFMVUFUSU9OLmNvbmYi
XSBbbGluZSAiMjIxIl0gW2lkICI5NDkxMTEiXSBbbXNnICJJbmJvdW5kIEFub21hbHkgU2NvcmUg
RXhjZWVkZWQgaW4gcGhhc2UgMSAoVG90YWwgU2NvcmU6IDApIl0gW3ZlciAiT1dBU1BfQ1JTLzQu
MTQuMCJdIFt0YWcgImFub21hbHktZXZhbHVhdGlvbiJdIFt0YWcgIk9XQVNQX0NSUyJdCkFjdGlv
bjogSW50ZXJjZXB0ZWQgKHBoYXNlIDEpClN0b3B3YXRjaDogMTc0ODMxNTE4MDc0MDQxNyAxNjEx
ICgtIC0gLSkKU3RvcHdhdGNoMjogMTc0ODMxNTE4MDc0MDQxNyAxNjExOyBjb21iaW5lZD04MDUs
IHAxPTcxOSwgcDI9MCwgcDM9MCwgcDQ9MCwgcDU9ODUsIHNyPTAsIHN3PTEsIGw9MCwgZ2M9MApS
ZXNwb25zZS1Cb2R5LVRyYW5zZm9ybWVkOiBEZWNodW5rZWQKUHJvZHVjZXI6IE1vZFNlY3VyaXR5
IGZvciBBcGFjaGUvMi45LjcgKGh0dHA6Ly93d3cubW9kc2VjdXJpdHkub3JnLyk7IE9XQVNQX0NS
Uy80LjE0LjAuClNlcnZlcjogQXBhY2hlLzIuNC41OCAoVWJ1bnR1KSBPcGVuU1NMLzMuMC4xMwpF
bmdpbmUtTW9kZTogIkVOQUJMRUQiCgotLWI3OWFmNDI4LVotLQ==

--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--b1=_WVGThVKcbSmVvACI8JjPQXakHyfPkA9iK2XKp5Tks--