Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

IIS connector: audit log F part always shows '500 Internal Server Error' for normal traffic

Aperta Adatta ai principianti
#3,612 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
76/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Tranquilla
Stack tecnologico
cpp
Ambito
backend, security

Direzione di ricerca

Inizia in iis/mymodule.cpp, in CMyHttpModule::OnSendResponse, e esamina come hookfn_log_transaction costruisce successivamente la parte F del log di audit. Confronta i campi della risposta IIS con la gestione dello stato di request_rec, quindi verifica che le risposte normali e bloccate mostrino le loro effettive righe di stato, come 200 OK e 403 ModSecurity Action.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

2.x Platform - IIS

Summary

In the IIS connector (iis/mymodule.cpp), the audit log's F part (response status line) renders as HTTP/1.1 500 Internal Server Error for every transaction, even for normal requests that actually return e.g. 200 OK or 404.

Root cause

The IIS connector never copies the real HTTP response status into the request_rec. In CMyHttpModule::OnSendResponse, r->status is left at its initial value 0 (the request_rec is apr_pcalloc'd). When hookfn_log_transaction later builds the F part it calls ap_get_status_line(r->status); for r->status == 0 the standalone ap_index_of_response() maps anything < 100 to the LEVEL_500 bucket, producing 500 Internal Server Error.

Affected output

--A--
[13/Aug/2026:16:16:40.333548] ...
--F--
HTTP/1.1 500 Internal Server Error   <- should be the real status (e.g. 200 OK)

Proposed fix

In CMyHttpModule::OnSendResponse (iis/mymodule.cpp), transfer pRawHttpResponse->StatusCode into r->status (and build r->status_line from the reason phrase) before the rest of the response handling:

if(pRawHttpResponse->StatusCode > 0)
{
    r->status = pRawHttpResponse->StatusCode;

    if(pRawHttpResponse->pReason != NULL && pRawHttpResponse->ReasonLength > 0)
    {
        r->status_line = apr_psprintf(r->pool, "%d %s", r->status,
            ZeroTerminate(pRawHttpResponse->pReason, pRawHttpResponse->ReasonLength, r->pool));
    }
}

This makes the audit log F part and relevant-status checks use the real response code. Verified against a local IIS (default site + OWASP CRS): a normal GET / now logs HTTP/1.1 200 OK, blocked requests log HTTP/1.1 403 ModSecurity Action.

Lingua principale
C++
Stelle
9.8k
Fork
1.8k
Merge medio
2h 46m
PR unite (30g)
1

Preparare l'ambiente

Non abbiamo ancora controllato i file di configurazione di questo progetto. Parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di owasp-modsecurity/ModSecurity

Tutte le issue di owasp-modsecurity/ModSecurity

Issue simili

Altre issue su C++

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.