Download
Blog
Wiki
Forum
Store
Contact
Home
Products
Web Server
Load Balancer
LiteSpeed SAPI
Solutions
Web Hosting
Online Gaming
PHP Application
Rails Hosting
Case Studies
Resources
Documentation
White Papers
Benchmarks
Testimonials
FAQ
HOW-TOs
Support
Services
Wiki
Forum
Company
About
News
Blog
Management
Partners
Careers
Support
Services
Wiki
Forum
User Name
Password
Remember Me?
Register
FAQ
Members List
Calendar
Search
Today's Posts
Mark Forums Read
LiteSpeed Support Forums
>
LiteSpeed Web Server
>
Bug Reports
>
SecFilterSelective HTTP_X_MOZ "prefetch" <-- broken!
Thread Tools
Display Modes
#
1
09-28-2007, 10:42 AM
phallstrom
Member
Join Date: Jan 2007
Posts: 28
SecFilterSelective HTTP_X_MOZ "prefetch" <-- broken!
Hi -
I am trying to block google's web accelerator. I have the following request filter setup:
Action: log,deny,status:403,msg:'GWA Prefetch'
Rule: SecFilterSelective HTTP_X_MOZ "prefetch"
I then test it using curl:
curl --header "X-Moz: prefetch" -v -I
http://example.com
It returns a valid 200 response. If I change the rule to:
SecFilterSelective HTTP_USER_AGENT "curl"
Then it mostly works. It doesn't return a 403, but does return a 404.
This is occurring on standard edition, linux x86, version 3.2.2.
I've also tried the "REQUEST_HEADERS:X-Moz" which resulted in an error in the log files saying it was an unknown variable and couldn't be parsed.
Can you tell me if this is a known bug, if there's a work around and how we can get it to return a 403 instead of 404?
phallstrom
View Public Profile
Send a private message to phallstrom
Find all posts by phallstrom
#
2
09-28-2007, 12:10 PM
mistwang
LiteSpeed Staff
Join Date: May 2003
Location: New Jersey
Posts: 7,603
X-Moz is a custom header, not being recoginzed by the security engine now. You can let the engine to scan the whole request header for the signature.
Last edited by mistwang; 09-28-2007 at
12:22 PM
..
mistwang
View Public Profile
Send a private message to mistwang
Visit mistwang's homepage!
Find all posts by mistwang
#
3
09-28-2007, 12:26 PM
phallstrom
Member
Join Date: Jan 2007
Posts: 28
Ok. Thanks. It would be great if the security engine recognized every header, but maybe there are reasons it can't do that.
phallstrom
View Public Profile
Send a private message to phallstrom
Find all posts by phallstrom
#
4
09-28-2007, 01:03 PM
phallstrom
Member
Join Date: Jan 2007
Posts: 28
can you tell me why it's returning a 404 instead of a 403? If I get it working by scanning all the headers will it work correctly? it didn't when i tested against the user agent.
phallstrom
View Public Profile
Send a private message to phallstrom
Find all posts by phallstrom
«
Previous Thread
|
Next Thread
»
Thread Tools
Show Printable Version
Email this Page
Display Modes
Linear Mode
Switch to Hybrid Mode
Switch to Threaded Mode
Posting Rules
You
may not
post new threads
You
may not
post replies
You
may not
post attachments
You
may not
edit your posts
BB code
is
On
Smilies
are
On
[IMG]
code is
On
HTML code is
Off
Forum Rules
Forum Jump
User Control Panel
Private Messages
Subscriptions
Who's Online
Search Forums
Forums Home
General
News
Use Cases
LiteSpeed Web Server
General
Install/Configuration
LiteSpeed Cache
Feedback/Feature Requests
Bug Reports
LSWS 4.1 Release
LiteSpeed Load Balancer
General
LiteSpeed Anti-DDoS
Proxy Service
Popular web applications
Word Press
vBulletin Forum
Joomla
Magento
External Applications
Apache Migration/Compatibility
Ruby/Rails
PHP
CGI/Perl/Python
Java JSP/Servlet
All times are GMT -7. The time now is
06:33 AM
.
-
Archive
-
Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved.
Privacy Policy
.