IIS connector: audit log F part always shows '500 Internal Server Error' for normal traffic
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 76/100
Hướng nghiên cứu
Bắt đầu trong iis/mymodule.cpp tại CMyHttpModule::OnSendResponse và kiểm tra cách hookfn_log_transaction sau đó xây dựng phần F của audit log. So sánh các trường response của IIS với cách xử lý status của request_rec, sau đó xác minh rằng các response bình thường và bị chặn hiển thị đúng các dòng status thực tế của chúng, chẳng hạn như 200 OK và 403 ModSecurity Action.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
In the IIS connector (iis/mymodule.cpp), the audit log's F part (response status line) renders as HTTP/1.1 500 Internal Server Error for every transaction, even for normal requests that actually return e.g. 200 OK or 404.
Root cause
The IIS connector never copies the real HTTP response status into the request_rec. In CMyHttpModule::OnSendResponse, r->status is left at its initial value 0 (the request_rec is apr_pcalloc'd). When hookfn_log_transaction later builds the F part it calls ap_get_status_line(r->status); for r->status == 0 the standalone ap_index_of_response() maps anything < 100 to the LEVEL_500 bucket, producing 500 Internal Server Error.
Affected output
--A--
[13/Aug/2026:16:16:40.333548] ...
--F--
HTTP/1.1 500 Internal Server Error <- should be the real status (e.g. 200 OK)
Proposed fix
In CMyHttpModule::OnSendResponse (iis/mymodule.cpp), transfer pRawHttpResponse->StatusCode into r->status (and build r->status_line from the reason phrase) before the rest of the response handling:
if(pRawHttpResponse->StatusCode > 0)
{
r->status = pRawHttpResponse->StatusCode;
if(pRawHttpResponse->pReason != NULL && pRawHttpResponse->ReasonLength > 0)
{
r->status_line = apr_psprintf(r->pool, "%d %s", r->status,
ZeroTerminate(pRawHttpResponse->pReason, pRawHttpResponse->ReasonLength, r->pool));
}
}
This makes the audit log F part and relevant-status checks use the real response code. Verified against a local IIS (default site + OWASP CRS): a normal GET / now logs HTTP/1.1 200 OK, blocked requests log HTTP/1.1 403 ModSecurity Action.
- Ngôn ngữ chính
- C++
- Star
- 9.8k
- Fork
- 1.8k
- Merge trung bình
- 2 giờ 46 phút
- Pull request đã merge (30 ngày)
- 1
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của owasp-modsecurity/ModSecurity
-
2.x Platform - IIS
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
owasp-modsecurity/ModSecurity#3623 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x Platform - IIS
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
owasp-modsecurity/ModSecurity#3621 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x Platform - IIS
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
owasp-modsecurity/ModSecurity#3619 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
3.x
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
owasp-modsecurity/ModSecurity#3580 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
2.x Platform - IIS
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 25/100
owasp-modsecurity/ModSecurity#3630 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của owasp-modsecurity/ModSecurity
Issue tương tự
-
Unconfirmed bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
luanti-org/luanti#17605 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
area: config area: firmware priority: P2 - medium size: S type: bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Mizithra/ActiveTerrain#16 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
grumpycoders/pcsx-redux#2171 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
bytedance/trae-agent#524 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày