Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

libModSecurity3: REQUEST_HEADERS names are treated as case sensitive with configure-time rule-exclusions

Đang mở
#3,609 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
64/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
cpp, nginx

Hướng nghiên cứu

Bắt đầu bằng cách truy vết các loại trừ quy tắc tại thời điểm cấu hình từ SecRuleUpdateTargetById đến các target REQUEST_HEADERS tương ứng. Tái hiện sự cố bằng hai yêu cầu curl và so sánh các loại trừ cho Referer và referer. Hoàn tất khi việc phân biệt chữ hoa chữ thường trong tên header được bỏ qua, để một loại trừ hoạt động nhất quán với cả hai yêu cầu, kèm theo coverage cho hồi quy.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

:1st_place_medal: good first issue 3.x

Describe the bug

This bug is similar to: https://github.com/owasp-modsecurity/ModSecurity/issues/3441, which also doesn't appear in ModSecurity2.

Logs and dumps

N/A

To Reproduce

Re-using the previous example in this issue, say I have this rule:

SecRule REQUEST_HEADERS:Referer "@contains <evil-string>" \
    "id:2,\
    phase:1,\
    deny,\
    t:none,\
    log"

and I want to write a rule-exclusion for this rule via a configure-time rule-exclusion:

SecRuleUpdateTargetById 2 !REQUEST_HEADERS:referer

This rule-exclusion works if the client sends a lowercase referer header:

$ curl -H "referer: <evil-string>" localhost:8080

But if the client sends an uppercase referer header, then the request is wrongly blocked:

$ curl -H "Referer: <evil-string>" localhost:8080
<html>
<head><title>403 Forbidden</title></head>
<body>
<center><h1>403 Forbidden</h1></center>
<hr><center>nginx/1.28.3 (Ubuntu)</center>
</body>
</html>

If I exclude both uppercase and lowercase referer header, then the rule-exclusion works as expected.

SecRuleUpdateTargetById 2 !REQUEST_HEADERS:Referer
SecRuleUpdateTargetById 2 !REQUEST_HEADERS:referer

Expected behavior

Request header case should be ignored.

Server (please complete the following information):

  • OS: Ubuntu 26.04
  • ModSecurity Version: 3.0.17
  • NGINX Connector Version: v1.0.4
  • NGINX Version: 1.28.3

Rule Set (please complete the following information):

N/A

Additional context

Similar to: https://github.com/owasp-modsecurity/ModSecurity/issues/3441

Ngôn ngữ chính
C++
Star
9.8k
Fork
1.8k
Merge trung bình
2 giờ 46 phút
Pull request đã merge (30 ngày)
1

Chuẩn bị môi trường

Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của owasp-modsecurity/ModSecurity

Tất cả issue của owasp-modsecurity/ModSecurity

Issue tương tự

Thêm issue về C++

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.