LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > LSWS 4.1 Release > mod_security RESPONSE_BODY

Reply
 
Thread Tools Display Modes
  #1  
Old 02-26-2009, 06:55 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Exclamation mod_security RESPONSE_BODY

Hello,

I have a problem about mod_security RESPONSE_BODY rules;

Some mod_sec 2.x rules not working, for examlpe i have a rule set for blocking r57,c99 etc php shells;

Quote:
SecRule RESPONSE_BODY "(?:<title>[^<]*?(?:\b(??:c(?:ehennemden|gi-telnet)|gamma web shell)\b|imhabirligi phpftp)|(?:r(?:emote explorer|57shell)|aventis klasvayv|zehir)\b|\.:?:news remote php shell injection::\.| rhtools\b)|ph(?(??: commander|-terminal)\b|remoteview)|vayv)|myshell)|\b(???: microsoft windows\b.{,10}?\bversion\b.{,20}?\(c\) copyright 1985-.{,10}?\bmicrosoft corp|ntdaddy v1\.9 - obzerve \| fux0r inc)\.|(?:www\.sanalteror\.org - indexer and read|haxplor)er|php(?:konsole| shell)|c99shell)\b|aventgrup\.<br>|drwxr))" \
"phase:4,t:none,ctl:auditLogParts=+E,deny,log,audi tlog,status:404,msg:'Backdoor access',id:'950922',tag:'MALICIOUS_SOFTWARE/TROJAN',severity:'2'"
This rule is working when i switched the apache, but on LS it is not working.

This rule have to return 404 error when someone run r57 shell script.

Can you help to improve security by using SecRule RESPONSE_BODY ?
Reply With Quote
  #2  
Old 02-28-2009, 07:07 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
Currently scanning response body is not supported by LiteSpeed yet.
A rule like that will severely slow down the server when scan a large response body.
So, we will think about it carefully.
Reply With Quote
  #3  
Old 03-01-2009, 06:11 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Hello,

Maybe it will slow down server. But security is more important for us.

You can enable RESPONSE_BODY those who want to use security?

We are looking for to use LiteSpeed instead of Apache in our 20 linux servers. But our security department doesn't approve because of mod_security respone rules.
Reply With Quote
  #4  
Old 03-04-2009, 02:50 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Hello mistwang,

It will be any progress on this issue?
Reply With Quote
  #5  
Old 03-23-2009, 05:56 PM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
George is right, it will slow down server as hell
but i think special trick for example scanning specified response mime types (plain text) or requested file types (php) would solve performances issue and increases security as well

is it possible?
Reply With Quote
  #6  
Old 03-24-2009, 02:24 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Yes it will slow down but this is our choice. Am i wrong?
Reply With Quote
  #7  
Old 04-29-2009, 06:17 AM
muiruri muiruri is offline
Member
 
Join Date: Jun 2008
Posts: 32
For some reason customers with joomla sites when they try to log on to their joomla administrator section/control panel...

http://customer-domain.com/administrator/

get following error;

---

406 Not Acceptable
This request is not acceptable

---

Found this is related to mod_security therefore when I add following lines in .htaccess for this specific domain.

<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
</IfModule>

All works fine.

My questions are;

(a) Is there a place in LSWS 4.0.2 menu options to turn mod_sec off for specific host or domain? Or any better ideas to deal with this one pl'se ?

(b) On this server last thing we did was to upgrading openSSL to latest verion 0.9.8k, and starting getting this problem.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 05:01 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.