LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > Request Filters

Reply
 
Thread Tools Display Modes
  #1  
Old 01-21-2012, 07:58 PM
JasonWSInc JasonWSInc is offline
Member
 
Join Date: Jan 2012
Posts: 10
Default Request Filters

Hi there. I could use some help getting LiteSpeed Request Filters figured out please. I'm attaching some screenshots to show my current configuration. Problem: With the configuration you see in the screenshots, LiteSpeed is not "passing" on either of the two Request Filter Rule Sets that I've got, can you please explain why? Both the Rules are being denied, but I only want them to be logged, and then pass through silent, allowing access (this is just a test so I can understand how things work).

My Default Action is: log,deny,status:403
Each Rule Set has the Action: msg:"[message]",pass

I guess I'm not understanding something? After reading the documentation on mod_security, I thought that a Disruptive Action of "pass" in the Rule Set, would override that of the Default Action, which is "deny". Is that not correct?
Attached Images
File Type: jpg SNAG-0038.jpg (20.2 KB, 5 views)
File Type: jpg SNAG-0039.jpg (20.3 KB, 3 views)
Reply With Quote
  #2  
Old 01-22-2012, 09:27 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,220
Quote:
I thought that a Disruptive Action of "pass" in the Rule Set, would override that of the Default Action, which is "deny". Is that not correct?
I did local test, the result is : yes, should override.

the attached picture is not clear.
Reply With Quote
  #3  
Old 01-22-2012, 11:34 PM
JasonWSInc JasonWSInc is offline
Member
 
Join Date: Jan 2012
Posts: 10
Default re: Request Filters

Thanks. Here are better screenshots.
http://img16.imageshack.us/img16/8712/snag0039.png
http://img827.imageshack.us/img827/5732/snag0038.png

Quote:
I did local test, the result is : yes, should override.
Sorry, does that mean that my assumption is correct then? My rules SHOULD be passing, instead of triggering a 403 status and denying the request?

What is happening is that these rules which are configured to "pass" are still being denied with a 403 status. I'm not sure if I have something configured incorrectly, or I'm missing something, or if it's a bug. Any help is appreciated. Thank you so much!
Reply With Quote
  #4  
Old 01-22-2012, 11:50 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,220
still can't view the image.

Quote:
My rules SHOULD be passing
right
Reply With Quote
  #5  
Old 01-22-2012, 11:55 PM
JasonWSInc JasonWSInc is offline
Member
 
Join Date: Jan 2012
Posts: 10
Default re: Request Filters

Thank you. I'll test again just to be sure.

I posted links to the images. Here they are:

http://img16.imageshack.us/img16/8712/snag0039.png
http://img827.imageshack.us/img827/5732/snag0038.png

I tried uploading them to the forum, but your system re-sized them on me.
Reply With Quote
  #6  
Old 01-23-2012, 12:47 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,337
Quote:
Originally Posted by JasonWSInc View Post
Thank you. I'll test again just to be sure.

...
You should enable audit logging to troubleshoot.

Last edited by webizen; 01-23-2012 at 12:55 PM..
Reply With Quote
  #7  
Old 01-23-2012, 12:48 PM
JasonWSInc JasonWSInc is offline
Member
 
Join Date: Jan 2012
Posts: 10
Default re: Request Filters

Audit logging is enabled, as seen in the screenshots I attached. That's how I know it's not working as expected. These rules are being triggered even though they're suppose to pass.
Reply With Quote
  #8  
Old 01-23-2012, 01:00 PM
JasonWSInc JasonWSInc is offline
Member
 
Join Date: Jan 2012
Posts: 10
Default re: Request Filters

I'm running Litespeed Web Server Enterprise v4.1.10 with FireHost on Ubuntu 64-bit.
Reply With Quote
  #9  
Old 01-23-2012, 02:16 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,337
Quote:
Originally Posted by JasonWSInc View Post
Audit logging is enabled, as seen in the screenshots I attached. That's how I know it's not working as expected. These rules are being triggered even though they're suppose to pass.
Sorry for the confusion. Yes, you may put 'log,' in the override rule to update audit log.

tested on ubuntu 11.10 64bit env in our lab. override rules are in effect: when 'pass' is used, no blockage.

btw, are you using lsws native vhost or you have apache vhost in httpd.conf?
Reply With Quote
  #10  
Old 01-24-2012, 01:26 PM
JasonWSInc JasonWSInc is offline
Member
 
Join Date: Jan 2012
Posts: 10
Default re: Request Filters

I'm running with native vhost configuration, no Apache configuration file. Everything I've done so far is through the web console for LiteSpeed.

I'll test this again tonite and see if I can find out more. Until then, if you have any other ideas, please let me know.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 02:29 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.