LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > LSWS 4.2.2 VS mod_security

Reply
 
Thread Tools Display Modes
  #1  
Old 03-20-2013, 01:02 PM
DraCoola DraCoola is offline
Senior Member
 
Join Date: Mar 2009
Posts: 149
Default LSWS 4.2.2 VS mod_security

Latest 4.2.2 build won't block with this simple rule :

####
SecRule REQUEST_URI "/any-folder/.+/filename.\php" "id:20202020,rev:1,severity:2,msg:'must be denied',deny" \
####

Performing /usr/local/lsws/admin/misc/lsup.sh -f -v 4.2.1 and then the rule above did block filename.php as it should be.



Please fix it

Last edited by DraCoola; 03-20-2013 at 01:04 PM..
Reply With Quote
  #2  
Old 03-20-2013, 10:04 PM
DraCoola DraCoola is offline
Senior Member
 
Join Date: Mar 2009
Posts: 149
any help from anybody?
Reply With Quote
  #3  
Old 03-20-2013, 10:11 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,226
Hi, it has been fixed. will be in next build.

Thanks for your reporting.
Reply With Quote
  #4  
Old 03-20-2013, 10:37 PM
DraCoola DraCoola is offline
Senior Member
 
Join Date: Mar 2009
Posts: 149
Hi NiteWave,

Thank you, I will waiting so much for that next build.
By the way :

-----------------
lsphp5:/home/username/andsoon
-----------------

will be more neat than :

-----------------
/usr/local/lsws/fcgi-bin/lsphp5:/home/username/andsoon
-----------------

that you are using now on 4.2.2, while running top -c in ssh

Last edited by DraCoola; 03-20-2013 at 10:40 PM..
Reply With Quote
  #5  
Old 03-21-2013, 04:21 PM
DraCoola DraCoola is offline
Senior Member
 
Join Date: Mar 2009
Posts: 149
any update yet?
because using 4.2.1 with Atomic rule set makes lsws restart oftenly




Last edited by DraCoola; 03-21-2013 at 04:25 PM..
Reply With Quote
  #6  
Old 03-21-2013, 05:38 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
new build has been uploaded. you can do a force reinstall see if work better this time.
Reply With Quote
  #7  
Old 03-21-2013, 05:51 PM
DraCoola DraCoola is offline
Senior Member
 
Join Date: Mar 2009
Posts: 149
thank you very much, George.
it work flawlessly now
Reply With Quote
  #8  
Old 03-21-2013, 05:57 PM
DraCoola DraCoola is offline
Senior Member
 
Join Date: Mar 2009
Posts: 149
by the way I hope next build of lsws will revert back to neat old fashion of lsws processing as bellow :





because newest build showing too long line of process :

Reply With Quote
  #9  
Old 03-21-2013, 08:47 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
You can download the upcoming PHP LSAPI 6.2 http://www.litespeedtech.com/package...espeed-6.2.tgz, apply it to php-xxx/sapi/litespeed, make, copy to lsws/fcgi-bin/, to get what you want.
Reply With Quote
  #10  
Old 03-23-2013, 02:45 PM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
After several years of running the same rules on LSWS Standard without any problem all the way up to 4.2.1, I just upgraded to 4.2.2 and now see a lot of this:

2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.114 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT
2013-03-23 13:26:04.115 ERROR [ModSecurity] unknown server variable while parsing: HEADER_USER_AGENT

The rules are simple ones that looks like this:

Quote:
SecFilterSelective HEADER_USER_AGENT ^Morfeus
or
Quote:
SecFilterSelective HEADER_USER_AGENT "Toata"
And the action is:
Quote:
log,deny,status:404,msg:'Badbot blocked'
Why do these rules break now?

Last edited by brrr; 03-23-2013 at 02:52 PM..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 03:11 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.