LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > 4.2.2 update changed mod_security rule matching behaviour

Reply
 
Thread Tools Display Modes
  #1  
Old 03-18-2013, 05:38 AM
jack jack is offline
New Member
 
Join Date: Mar 2011
Posts: 7
Default 4.2.2 update changed mod_security rule matching behaviour

Hi,

Last week we decided to update LS to 4.2.2, it has been out for a while so we assumed it would be a safe move. However things didn't run smoothly at all! We started getting a lot of false positives with the got_root rules leading to lots of 403 pages with some IP address blocks and a lot of support tickets to handle.

After a thorough check we saw that immediately after the upgrade a lot more web requests were being matched. At the time 3 rules were playing up and over the weekend 3 other rules have been whitelisted too. Oddly, those rules were previously regularly catching legitimate SQL injection attack requests and after the update we stopped seeing those being logged.

We haven't yet looked at the mod_security rule syntax, they seem like regexes, but this is a nice example of an odd match:

--340a1df9-H--
Message: [client 120.40.156.230] mod_security: Access denied with code 403, [Rule: 'REQUEST_URI' '!(?:/install/index\.php|/index\.php\?mode=install&sub=create_table$|^/admin/test/examples/txtsqladmin/index\.php|^/store/images/|^/wp-admin/admin\.php\?page=wpsc-settings)'] [ID "340157"] [Msg "Atomicorp.com UNSUPPORTED DELAYED Rules: Generic SQL inline command protection"] [severity "CRITICAL"] [MatchedString "lrefrkgcltzqgzetgbhyijchfcrgckvvuartrkkikbgfccayy ixpcjkngtioaeupnbocomungnuisnozbdmpfxsmbaeewmmlyvh rpwqcbqcknggohsfnexlgfoyswsreelitnvmbggbbpjqalstdd ocetizxdmwdkrtghfamzllabpfcpprahsvleapokymmvtqkpqr otfpdjpzdyvvlpphmaifihcnsxqehyiayrubrpbiqiwrrpxswr qfbcnbgkqxoscyirguwhibefqwylupzkxbtcazjnjqivhonagz txojkvjsnynwkkfayxgrzlazzjmnchttebagjymyeaixsgvdre zsfmvjecaxogrnkjdvrrwpjvjbxqiwumttmuugchztshigooqs zdyvvenpsgdodnmmlipdrgesdsjqrvqrxkdptqaxbpczsqtnew dloyialbnovmubvkhrhafzdbniufsmfactdjsvmlzbfafempqm elpfypwnaohmdqunjeiapwpzqirrwdqzrvfjysrkmmiijlhylk vbobcisdcevqjvlgllamjgwivknsvtctmxrqndiecrqrchukqn rgoowfgmeuspryqgmaftlvpyjbmrbknrrcmgfhrkrsctexwmsv jmsusaxoljrdafwnxerniouofivccyilckqtgnvafjimsmenxt modfnaaliikacfjtszbkzavpnembswhvxsmioworlzedkmyrfv wzebkxtwpwfrocojcdiczkbrnsxilkdgjoapiqhmyxhiemlfxq dmumirwbjxikgtkkhiswqzprjcvisyrpmllpxtdgzwhjlckgth hypzaqsiswfxhgikrvrltxuhuxuimavsmyfbqlyunhjyuwznyd mpyudvagfkfzcgandgtkyavclvmbypghtfeyijkbylgvenygrz wdvtwhsegorggtychjbtmffslccokakbiypibueotntealoejg egejjslvqvfjhorrqjopfdyenetlunjddnilcqdgzukggpsiik cpdyrijsycqqshkhkhuowppijipjpphpjpvzcvxmqxlocwphan tatzcrsyiddnzxfqqqdupsjuzznptesscuqrbxgyxxipbpywxt wxwgjrpskvznzfbxaudwjzqg"]
--

Our servers run either CloudLinux 5 32bit or version 6 64bit.

The above example is from a CL 5 box.

We're running the got_root 2.5 rules.

Let us know if you'd like full logs so you can take a better look at them. Currently we're moving back to 4.2.1.

Best Regards,
Jack
Reply With Quote
  #2  
Old 03-18-2013, 11:55 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,389
pls try the latest 4.2.2 (force reinstall).
Reply With Quote
  #3  
Old 03-19-2013, 02:47 AM
jack jack is offline
New Member
 
Join Date: Mar 2011
Posts: 7
Are you saying that there are several 4.2.2 versions sharing the same release number?

If that's so then it doesn't sound sensible at all. Shouldn't be hard to append a 4th number to reflect minor fixes.

Anyway, we installed "our version of the 4.2.2 version" on March 14 (5 days ago). Not going to push anything newer than 4.2.1 until we see a bump in the version number or get proper feedback.

All the best,
Jack
Reply With Quote
  #4  
Old 03-21-2013, 05:59 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,389
just an FYI.

http://www.litespeedtech.com/support...ead.php?t=6424
Reply With Quote
  #5  
Old 04-26-2013, 08:29 AM
jack jack is offline
New Member
 
Join Date: Mar 2011
Posts: 7
Hi,

Where can we download the "latest" 4.2.1 version?

I used this URL before but now there's nothing there and I didn't save a copy.

http://www.litespeedtech.com/package...4-linux.tar.gz

Thanks

Jack
Reply With Quote
  #6  
Old 04-26-2013, 11:11 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,389
Pls try again.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 03:17 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.