Create httpd fingerprinting detection plugin
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- apache
- 領域
- security
調査の方向性
まず、リンクされている議論と PR #4297、#4302 を読んで、候補となるルールとその想定される適用範囲を理解します。REQUEST_URI_RAW、paranoia level 2、protocol-enforcement の分類を使用し、httpd のフィンガープリンティングとエンコードされた予約文字を中心にプラグインを定義します。完了条件は、プラグインが登録され、初期ルールがグループ化されて文書化されていることです。
索引モデルが issue の本文から書いたものです。
説明
Background
Following the discussion in coreruleset/coreruleset#4297 and the related PR coreruleset/coreruleset#4302, @theseion proposed that rules aimed at preventing httpd fingerprinting and blocking URL-encoded reserved characters in request paths would be better suited as a dedicated CRS plugin rather than being included in CRS core.
Problem
Requests containing URL-encoded reserved characters (e.g., %2F) in the request path serve no legitimate purpose in most environments and are commonly used by scanners and attackers to:
- Fingerprint the backend web server (e.g., triggering Apache default error pages)
- Exploit parser confusion between frontends and backends
- Bypass phase-1 protections that don't perform URL decoding
While these rules provide real security value, they don't fit well into CRS core because:
- They are more relevant to specific web server configurations (particularly Apache httpd)
- They may cause false positives in edge cases (e.g., resources with
%2fin filenames) - Behavior varies across web servers (Nginx, Caddy/Coraza, Envoy, etc.)
Proposal
Create a new CRS plugin, e.g., httpd-fingerprinting-detection-plugin, that groups rules serving this purpose. This would:
- Group related rules — Collect rules that detect and block fingerprinting/reconnaissance patterns specific to httpd
- Avoid false positives in CRS core — Keep CRS core clean of rules that may cause unexpected FPs depending on the deployment
- Avoid issues with other web servers — Rules targeting httpd-specific behavior won't affect users running other engines
- Allow iterative growth — New fingerprinting detection rules can be added to the plugin over time
Candidate rules
- Blocking
%2F(URL-encoded slash) in request paths (#4297) - Blocking other URL-encoded reserved characters that have no legitimate reason to appear encoded in request paths (#4302)
- Potentially, response body inspection rules for detecting stock error pages
Considerations
- Rules should use
REQUEST_URI_RAWto ensure the URI hasn't already been decoded - Paranoia level 2 is recommended as a starting point to stay safe with respect to false positives
- Rules should be categorized under protocol enforcement
References
- PR coreruleset/coreruleset#4297 —
feat: add 920630 to prevent fingerprinting - PR coreruleset/coreruleset#4302 — Broader rule for URL-encoded reserved characters
- RFC 2396 — URI Generic Syntax (slash is in the "reserved" set)
- RFC 2616 §3.2.3 — URI Comparison
- 主要言語
- Python
- スター
- 53
- フォーク
- 13
- 平均マージ
- 7時間 30分
- マージ済み PR(30日)
- 1
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
coreruleset/plugin-registry のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
enhancement help wanted
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
coreruleset/plugin-registry#44 · コメント 10 件 ·
-
Feature Request: GitLab Plugin再び着手できるかも @EsadCetiner が 261 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
coreruleset/plugin-registry#25 · コメント 6 件 · リアクション 1 件 · 担当者 1 名 ·
-
難易度 5/5 1週間以上 初心者へのやさしさ 15/100
coreruleset/plugin-registry#19 · コメント 13 件 ·
-
Improve XML External Entity (XXE) detection再び着手できるかも @azurit が 886 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
coreruleset/plugin-registry#47 · コメント 63 件 · リアクション 3 件 · 担当者 1 名 ·
coreruleset/plugin-registry の issue をすべて見る
似ている issue
-
customer-reported
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
Azure/azure-cli#34150 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
community-request
難易度 1/5 1時間未満 初心者へのやさしさ 95/100
NVIDIA-NeMo/Curator#2464 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
WeblateOrg/translation-finder#1099 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
trezor/trezor-firmware#7997 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信