IIS connector: audit log F part always shows '500 Internal Server Error' for normal traffic
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 76/100
調査の方向性
iis/mymodule.cpp の CMyHttpModule::OnSendResponse から始め、hookfn_log_transaction が後で監査ログの F 部分をどのように構築するかを調べます。IIS のレスポンスフィールドと request_rec のステータス処理を比較し、その後、通常のレスポンスとブロックされたレスポンスに、200 OK や 403 ModSecurity Action などの実際のステータス行が表示されることを確認します。
索引モデルが issue の本文から書いたものです。
説明
Summary
In the IIS connector (iis/mymodule.cpp), the audit log's F part (response status line) renders as HTTP/1.1 500 Internal Server Error for every transaction, even for normal requests that actually return e.g. 200 OK or 404.
Root cause
The IIS connector never copies the real HTTP response status into the request_rec. In CMyHttpModule::OnSendResponse, r->status is left at its initial value 0 (the request_rec is apr_pcalloc'd). When hookfn_log_transaction later builds the F part it calls ap_get_status_line(r->status); for r->status == 0 the standalone ap_index_of_response() maps anything < 100 to the LEVEL_500 bucket, producing 500 Internal Server Error.
Affected output
--A--
[13/Aug/2026:16:16:40.333548] ...
--F--
HTTP/1.1 500 Internal Server Error <- should be the real status (e.g. 200 OK)
Proposed fix
In CMyHttpModule::OnSendResponse (iis/mymodule.cpp), transfer pRawHttpResponse->StatusCode into r->status (and build r->status_line from the reason phrase) before the rest of the response handling:
if(pRawHttpResponse->StatusCode > 0)
{
r->status = pRawHttpResponse->StatusCode;
if(pRawHttpResponse->pReason != NULL && pRawHttpResponse->ReasonLength > 0)
{
r->status_line = apr_psprintf(r->pool, "%d %s", r->status,
ZeroTerminate(pRawHttpResponse->pReason, pRawHttpResponse->ReasonLength, r->pool));
}
}
This makes the audit log F part and relevant-status checks use the real response code. Verified against a local IIS (default site + OWASP CRS): a normal GET / now logs HTTP/1.1 200 OK, blocked requests log HTTP/1.1 403 ModSecurity Action.
- 主要言語
- C++
- スター
- 9.8k
- フォーク
- 1.8k
- 平均マージ
- 2時間 46分
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
owasp-modsecurity/ModSecurity のほかの issue
-
2.x Platform - IIS
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
owasp-modsecurity/ModSecurity#3623 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
owasp-modsecurity/ModSecurity#3621 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
owasp-modsecurity/ModSecurity#3619 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
3.x
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
owasp-modsecurity/ModSecurity#3580 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 25/100
owasp-modsecurity/ModSecurity#3630 ·
メンテナーはふだん 1 日以内に返信
owasp-modsecurity/ModSecurity の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
sandialabs/seacas#945 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
ROCm/FastFlowLM#757 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
espressif/esp-matter#1867 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
mltframework/shotcut#1920 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信