ip collection does not seem to work properly with latest ModSecurity
维护者通常 1 天内回复
@airween 已经在做这个了。
开始于 2025年5月30日。
评估
这个 Issue 还没有评估数据。
描述
I am using @rbl xbl.spamhaus.org. rule for protecting my Fediverse server and I face the issue that with latest version of either ModSecurity or the docker.io/owasp/modsecurity-crs:nginx container the collection handling for the IP collection seems to not longer work properly.
In my pi-hole I see a huge number of queries to .xbl.spamhaus.org for all the ip addresses checked and with queries to the same ip based query many times where I would expect that this is not the case due to how I set up the ModSecurity rules.
- The issue is happening with the latest version of the docker.io/owasp/modsecurity-crs:nginx container.
- It is far less a occuring with docker.io/owasp/modsecurity-crs:4.10-nginx-202501050801 even when mounting ruleset 4.14 to this container.
- I don't believe it is a problem with the CRS.
Based on what I see I would see it as if
- the expirevar for the IP collection is not working properly
- maybe the persistent store is causing the problem (as I don't see any problems with the TX collection which is also a collection but not persistet). This might be an docker image problem.
According to modsecurity.conf the SecTmpDir is set to /tmp/modsecurity/tmp (as data and upload directory are also located in /tmp/modsecurity).
This directory is empty. Wouldn't this be the directory for persistent storage and shouldn't there be a file for the IP collection database?
This is the rules I use:
# xbl.spamhaus.org to block malicious/infected ips
SecAction \
"phase:1,id:1100,\
t:none,pass,nolog,\
tag:'COLLECTIONS',\
initcol:ip=%{remote_addr},\
setvar:'tx.real_ip=%{remote_addr}'"
SecRule IP:SPAMMER "@eq 1" \
"phase:1,id:1101,\
t:none,deny,log,auditlog,\
msg:'Request from Known SPAM Source (Previous RBL Match)',\
tag:'AUTOMATION/MALICIOUS',\
severity:'CRITICAL',\
setvar:'tx.msg=%{rule.msg}'"
SecRule IP:PREVIOUS_RBL_CHECK "@eq 1" "phase:1,id:1102,t:none,pass,nolog,skipAfter:END_RBL_LOOKUP"
SecAction "phase:1,id:1103,\
t:none,pass,nolog,\
setvar:ip.previous_rbl_check=1,\
expirevar:ip.previous_rbl_check=3600"
SecRule REMOTE_ADDR "@rbl xbl.spamhaus.org." \
"phase:1,id:1104,\
t:none,deny,log,auditlog,\
msg:'RBL Match for SPAM Source',\
tag:'AUTOMATION/MALICIOUS',\
severity:'CRITICAL',\
setvar:'tx.msg=%{rule.msg}',\
setvar:ip.spammer=1,\
expirevar:ip.spammer=3600"
SecMarker END_RBL_LOOKUP
This is part of my setup.conf before including the CRS rules. As said, it worked much better (but also not perfect) with the older docker image mentioned above.
- 主要语言
- C++
- 星标
- 9.8k
- 派生
- 1.8k
- 平均合并
- 2 小时 46 分钟
- 30 天内合并 PR
- 1
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
owasp-modsecurity/ModSecurity 的其他 Issue
-
2.x Platform - IIS
难度 1/5 1 小时以内 新手友好度 90/100
owasp-modsecurity/ModSecurity#3623 · 1 条评论 ·
维护者通常 1 天内回复
-
2.x Platform - IIS
难度 2/5 1-3 小时 新手友好度 82/100
owasp-modsecurity/ModSecurity#3621 · 1 条评论 ·
维护者通常 1 天内回复
-
2.x Platform - IIS
难度 2/5 1-3 小时 新手友好度 84/100
owasp-modsecurity/ModSecurity#3619 · 1 条评论 ·
维护者通常 1 天内回复
-
2.x Platform - IIS
难度 2/5 1-3 小时 新手友好度 76/100
owasp-modsecurity/ModSecurity#3612 · 1 条评论 ·
维护者通常 1 天内回复
-
3.x
难度 2/5 1-3 小时 新手友好度 70/100
owasp-modsecurity/ModSecurity#3580 · 1 条评论 ·
维护者通常 1 天内回复
查看 owasp-modsecurity/ModSecurity 的全部 Issue
相似的 Issue
-
难度 2/5 半天 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 88/100
ROCm/rocm-libraries#12703 ·
维护者通常 2 天内回复
-
bug
难度 1/5 1-3 小时 新手友好度 88/100
维护者通常 2 天内回复
-
Feature request
难度 2/5 1-3 小时 新手友好度 76/100
qbittorrent/qBittorrent#24975 ·
维护者通常 3 天内回复