Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Create httpd fingerprinting detection plugin

オープン
#43 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
apache
領域
security

調査の方向性

まず、リンクされている議論と PR #4297、#4302 を読んで、候補となるルールとその想定される適用範囲を理解します。REQUEST_URI_RAW、paranoia level 2、protocol-enforcement の分類を使用し、httpd のフィンガープリンティングとエンコードされた予約文字を中心にプラグインを定義します。完了条件は、プラグインが登録され、初期ルールがグループ化されて文書化されていることです。

索引モデルが issue の本文から書いたものです。

説明

enhancement help wanted

Background

Following the discussion in coreruleset/coreruleset#4297 and the related PR coreruleset/coreruleset#4302, @theseion proposed that rules aimed at preventing httpd fingerprinting and blocking URL-encoded reserved characters in request paths would be better suited as a dedicated CRS plugin rather than being included in CRS core.

Problem

Requests containing URL-encoded reserved characters (e.g., %2F) in the request path serve no legitimate purpose in most environments and are commonly used by scanners and attackers to:

  • Fingerprint the backend web server (e.g., triggering Apache default error pages)
  • Exploit parser confusion between frontends and backends
  • Bypass phase-1 protections that don't perform URL decoding

While these rules provide real security value, they don't fit well into CRS core because:

  • They are more relevant to specific web server configurations (particularly Apache httpd)
  • They may cause false positives in edge cases (e.g., resources with %2f in filenames)
  • Behavior varies across web servers (Nginx, Caddy/Coraza, Envoy, etc.)

Proposal

Create a new CRS plugin, e.g., httpd-fingerprinting-detection-plugin, that groups rules serving this purpose. This would:

  1. Group related rules — Collect rules that detect and block fingerprinting/reconnaissance patterns specific to httpd
  2. Avoid false positives in CRS core — Keep CRS core clean of rules that may cause unexpected FPs depending on the deployment
  3. Avoid issues with other web servers — Rules targeting httpd-specific behavior won't affect users running other engines
  4. Allow iterative growth — New fingerprinting detection rules can be added to the plugin over time
Candidate rules
  • Blocking %2F (URL-encoded slash) in request paths (#4297)
  • Blocking other URL-encoded reserved characters that have no legitimate reason to appear encoded in request paths (#4302)
  • Potentially, response body inspection rules for detecting stock error pages
Considerations
  • Rules should use REQUEST_URI_RAW to ensure the URI hasn't already been decoded
  • Paranoia level 2 is recommended as a starting point to stay safe with respect to false positives
  • Rules should be categorized under protocol enforcement

References

主要言語
Python
スター
53
フォーク
13
平均マージ
7時間 30分
マージ済み PR(30日)
1

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

coreruleset/plugin-registry のほかの issue

coreruleset/plugin-registry の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。