LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > Mod Sec Rule Not Working

Reply
 
Thread Tools Display Modes
  #1  
Old 08-29-2010, 02:56 AM
NC-Designs NC-Designs is offline
Senior Member
 
Join Date: Aug 2010
Posts: 58
Default Mod Sec Rule Not Working

Hi, I run CXS on our server and I have noticed that the mod_security rule below is not working -

SecRequestBodyAccess On
SecRule FILES_TMPNAMES "@inspectFile /etc/cxs/cxscgi.sh" \
"log,auditlog,deny,severity:2,id:'1010101'"

I also found the following error in the Server Log Viewer, any ideas? Thanks.

Reply With Quote
  #2  
Old 08-29-2010, 01:51 PM
Statskij Statskij is offline
Member
 
Join Date: Dec 2008
Posts: 27
Hello.
I use cxs on my servers too, but it doesn't work via mod_security rules, I use it via suhosin. For now it works just like that.
I think that developers of Litespeed should explore closely the question of interoperation of mod_security because mod_security rules protects well from hacker attack.
Reply With Quote
  #3  
Old 08-29-2010, 02:22 PM
NC-Designs NC-Designs is offline
Senior Member
 
Join Date: Aug 2010
Posts: 58
Quote:
Originally Posted by Statskij View Post
Hello.
I use cxs on my servers too, but it doesn't work via mod_security rules, I use it via suhosin. For now it works just like that.
I think that developers of Litespeed should explore closely the question of interoperation of mod_security because mod_security rules protects well from hacker attack.
Yeah, the problem I am facing is a script uploaded via PHP only shows minimal information comparatively to Apache. For example, it fails to display the uploading script location?
Reply With Quote
  #4  
Old 08-29-2010, 07:48 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,223
Quote:
the problem I am facing is a script uploaded via PHP only shows minimal information comparatively to Apache. For example, it fails to display the uploading script location?
uploading progress bar feature is addressed in litespeed 4.1RC2 and above.
see wiki:
http://www.litespeedtech.com/support...adprogress_bar
Reply With Quote
  #5  
Old 08-30-2010, 02:05 AM
NC-Designs NC-Designs is offline
Senior Member
 
Join Date: Aug 2010
Posts: 58
Quote:
Originally Posted by NiteWave View Post
uploading progress bar feature is addressed in litespeed 4.1RC2 and above.
see wiki:
http://www.litespeedtech.com/support...adprogress_bar
I mean like data that is sent to the CXS script through suhosin. For example -
(With LiteSpeed)
Quote:
Scanning web upload script file...
Web upload script user: filetest (532)
Web upload script owner: ()
Web upload script:
Remote IP:
Deleted: No
Quarantined: No
(With Apache)
Quote:
Scanning web upload script file...
Web upload script user: nobody (99)
Web upload script owner: filetest (532)
Web upload script: /home/filetest/public_html/upload.php
Remote IP: XX.XX.XX.XX
Deleted: No
Quarantined: No
With LiteSpeed I do not even know which script is uploading the malicious data, what IP is sending the malicious data and who even owns the script. The only way I can tell what user the script is under is because suExec within LiteSpeed seems not to work as it should and declares the visitor as the owner of the file. LiteSpeed is not parsing the data that Apache otherwise would.

Also, thank you for assistance Statskij, do you have the same problem as I do above?

Last edited by NC-Designs; 08-30-2010 at 02:10 AM..
Reply With Quote
  #6  
Old 08-30-2010, 09:51 AM
Statskij Statskij is offline
Member
 
Join Date: Dec 2008
Posts: 27
Yes, cxs doesn't work too.
I asked a question at this forum and developers answered me that files check doesn't work via mod_security.

I also use GotRoot rules for mod_security and not all of them work correctly.

So I think that Litespeed doesn't have full interoperation with mod_security.
Reply With Quote
  #7  
Old 02-05-2011, 06:36 AM
masood_y masood_y is offline
Senior Member
 
Join Date: Sep 2008
Posts: 121
How can do that with "suhosin" in "/usr/local/lib/php.ini"?
I cant find "suhosin.upload.verification_script" in "/usr/local/lib/php.ini"
Im using cpanel/whm.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 04:54 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.