LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > LSWS 4.1 Release > mod_security RESPONSE_BODY

Reply
 
Thread Tools Display Modes
  #1  
Old 02-26-2009, 06:55 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Exclamation mod_security RESPONSE_BODY

Hello,

I have a problem about mod_security RESPONSE_BODY rules;

Some mod_sec 2.x rules not working, for examlpe i have a rule set for blocking r57,c99 etc php shells;

Quote:
SecRule RESPONSE_BODY "(?:<title>[^<]*?(?:\b(??:c(?:ehennemden|gi-telnet)|gamma web shell)\b|imhabirligi phpftp)|(?:r(?:emote explorer|57shell)|aventis klasvayv|zehir)\b|\.:?:news remote php shell injection::\.| rhtools\b)|ph(?(??: commander|-terminal)\b|remoteview)|vayv)|myshell)|\b(???: microsoft windows\b.{,10}?\bversion\b.{,20}?\(c\) copyright 1985-.{,10}?\bmicrosoft corp|ntdaddy v1\.9 - obzerve \| fux0r inc)\.|(?:www\.sanalteror\.org - indexer and read|haxplor)er|php(?:konsole| shell)|c99shell)\b|aventgrup\.<br>|drwxr))" \
"phase:4,t:none,ctl:auditLogParts=+E,deny,log,audi tlog,status:404,msg:'Backdoor access',id:'950922',tag:'MALICIOUS_SOFTWARE/TROJAN',severity:'2'"
This rule is working when i switched the apache, but on LS it is not working.

This rule have to return 404 error when someone run r57 shell script.

Can you help to improve security by using SecRule RESPONSE_BODY ?
Reply With Quote
  #2  
Old 02-28-2009, 07:07 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
Currently scanning response body is not supported by LiteSpeed yet.
A rule like that will severely slow down the server when scan a large response body.
So, we will think about it carefully.
Reply With Quote
  #3  
Old 03-01-2009, 06:11 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Hello,

Maybe it will slow down server. But security is more important for us.

You can enable RESPONSE_BODY those who want to use security?

We are looking for to use LiteSpeed instead of Apache in our 20 linux servers. But our security department doesn't approve because of mod_security respone rules.
Reply With Quote
  #4  
Old 03-04-2009, 02:50 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Hello mistwang,

It will be any progress on this issue?
Reply With Quote
  #5  
Old 03-23-2009, 05:56 PM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
George is right, it will slow down server as hell
but i think special trick for example scanning specified response mime types (plain text) or requested file types (php) would solve performances issue and increases security as well

is it possible?
Reply With Quote
  #6  
Old 03-24-2009, 02:24 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Yes it will slow down but this is our choice. Am i wrong?
Reply With Quote
  #7  
Old 03-24-2009, 08:01 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,603
It is a low priority feature.
Reply With Quote
  #8  
Old 03-26-2009, 06:45 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Quote:
Originally Posted by mistwang View Post
It is a low priority feature.
Security is low priority feature?

Each server can be hacked which is not support this feature. How can it be ignored?

Lets test it?
Reply With Quote
  #9  
Old 03-26-2009, 07:51 AM
Tony Tony is offline
Senior Member
 
Join Date: Dec 2008
Posts: 133
Quote:
Originally Posted by yolte View Post
Security is low priority feature?

Each server can be hacked which is not support this feature. How can it be ignored?

Lets test it?
I'd say more like a site can be hacked because they do not keep up to date versions of their software or make secure software. For hacking an entire server it be even more tricky assuming the site was on it's own account.



There are other mod_security rules which are already supported which can inflate memory (ones that use location match). I'd rather see the rules that are supported not slow down LSWS to Apache levels.
__________________
Hawk Host
Frog Host
Reply With Quote
  #10  
Old 03-29-2009, 04:54 AM
yolte yolte is offline
Member
 
Join Date: Feb 2009
Posts: 10
Quote:
Originally Posted by Tony View Post
I'd say more like a site can be hacked because they do not keep up to date versions of their software or make secure software. For hacking an entire server it be even more tricky assuming the site was on it's own account.
I think we have to protect customers web sites who doesn't have enough information about script security?

Quote:
There are other mod_security rules which are already supported which can inflate memory (ones that use location match). I'd rather see the rules that are supported not slow down LSWS to Apache levels.
Can you give me examples which rules are protecting from php shells? (for ex: r57, c99)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 03:25 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.