Inconsistent Error Log Format of ModSecurity depending on Apache's ErrorLogFormat directive
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- apache, cpp
- 领域
- backend, observability
调研方向
首先,在使用和不使用 Apache 的 ErrorLogFormat 指令的情况下,重现报告的三个 ModSecurity 2.9.7 和 2.9.8 案例。阅读 pull request 3192 中的错误修复合并所带来的行为变化,然后确定预期结果是恢复兼容性还是记录该行为;当所选行为一致并由适当的回归检查覆盖时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
There is a funny behavior in the 2.9.x release line that I discovered yesterday.
ModSec 2.9.x has a habit of writing a prefix into the error log: [client <IP Address>] ModSecurity: ...
Starting 2.9.8 and following a merge of a bugfix by Marc Stern (https://github.com/owasp-modsecurity/ModSecurity/pull/3192), this prefix in square brackets disappears when you configure ErrorLogFormat in Apache. If you do not configure said directive, the [client ...] prefix remains, but the IP is accompanied by a colon and the client port number.
Up to 2.9.7, the Apache error log format would not change the behavior of ModSecurity. It would simply allow you to define the Apache prefix (e.g. format of the timestamp, severity etc.).
But now suddenly ModSecurity reacts to this as well. I am not sure this can be considered a bug. But it's certainly undocumented behavior.
Example ModSec 2.9.7 with ErrorLogFormat (-> ErrorLogFormat "[%{cu}t] [%-m:%-l] %-a %-L %M"):
[2025-12-02 11:46:39.609045] [security2:error] 127.0.0.1:48024 aS7Djwp_d4rQSzSzUpsP1wAAAAE [client 127.0.0.1] ModSecurity: Warning. Matched phrase "etc/passwd" at ARGS:test. [file "/home/dune73/crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "118"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: etc/passwd found within ARGS:test: /etc/passwd"] [severity "CRITICAL"] [ver "OWASP_CRS/4.21.0-dev"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [hostname "localhost"] [uri "/index.html"] [unique_id "aS7Djwp_d4rQSzSzUpsP1wAAAAE"]
Example ModSec 2.9.8 with ErrorLogFormat:
[2025-12-02 11:47:02.523759] [security2:error] 127.0.0.1:43714 aS7DpilIiJN1A-ostwkEZQAAAAA ModSecurity: Warning. Matched phrase "etc/passwd" at ARGS:test. [file "/home/dune73/crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "118"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: etc/passwd found within ARGS:test: /etc/passwd"] [severity "CRITICAL"] [ver "OWASP_CRS/4.21.0-dev"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [hostname "localhost"] [uri "/index.html"] [unique_id "aS7DpilIiJN1A-ostwkEZQAAAAA"]
Example ModSec 2.9.8 without ErrorLogFormat:
[Tue Dec 02 11:47:30.996655 2025] [security2:error] [pid 2150210:tid 2150239] [client 127.0.0.1:38370] ModSecurity: Warning. Matched phrase "etc/passwd" at ARGS:test. [file "/home/dune73/crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "118"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: etc/passwd found within ARGS:test: /etc/passwd"] [severity "CRITICAL"] [ver "OWASP_CRS/4.21.0-dev"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [hostname "localhost"] [uri "/index.html"] [unique_id "aS7DwtEn2rWqwBtW5o1hlQAAAAA"]
- 主要语言
- C++
- 星标
- 9.8k
- 派生
- 1.8k
- 平均合并
- 2 小时 46 分钟
- 30 天内合并 PR
- 1
环境准备
我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
owasp-modsecurity/ModSecurity 的其他 Issue
-
2.x Platform - IIS
难度 1/5 1 小时以内 新手友好度 90/100
owasp-modsecurity/ModSecurity#3623 · 1 条评论 ·
维护者通常 1 天内回复
-
2.x Platform - IIS
难度 2/5 1-3 小时 新手友好度 82/100
owasp-modsecurity/ModSecurity#3621 · 1 条评论 ·
维护者通常 1 天内回复
-
2.x Platform - IIS
难度 2/5 1-3 小时 新手友好度 84/100
owasp-modsecurity/ModSecurity#3619 · 1 条评论 ·
维护者通常 1 天内回复
-
2.x Platform - IIS
难度 2/5 1-3 小时 新手友好度 76/100
owasp-modsecurity/ModSecurity#3612 · 1 条评论 ·
维护者通常 1 天内回复
-
3.x
难度 2/5 1-3 小时 新手友好度 70/100
owasp-modsecurity/ModSecurity#3580 · 1 条评论 ·
维护者通常 1 天内回复
查看 owasp-modsecurity/ModSecurity 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 92/100
espressif/esp-matter#1867 ·
-
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 92/100
isce-framework/isce3#387 ·
-
upstream update
难度 2/5 1-3 小时 新手友好度 68/100
conan-io/conan-center-index#31055 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复