Compare commits
1
Commits
next
..
fbe87a7c5e
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fbe87a7c5e |
@@ -724,19 +724,17 @@ effective settings are logged at start, unless `SWWAF_LOG_LEVEL` is `warn` or
|
||||
(rule 900440), and a multipart body that fails Coraza's strict checks (rule
|
||||
900450), add 5 to the score, as a rule rated critical does, since no rule
|
||||
reads what comes after the fault. So does a multipart body the limit cuts
|
||||
before the colon of a part's header line, or between the carriage return and
|
||||
the line feed that end a part's header line or the empty line after its
|
||||
headers, since Coraza takes the line the limit cuts for a malformed header.
|
||||
The client has until `SWWAF_CLIENT_REQUEST_TIMEOUT` runs out to send the part
|
||||
that is read, and a request whose body passes `SWWAF_REQUEST_MAX_BYTES` within
|
||||
it is refused before anything reaches the app. Of a file in a multipart body,
|
||||
Coraza counts the bytes and writes nothing. Body inspection suits apps whose
|
||||
forms carry no code. In front of gitea it refuses issue and comment text, wiki
|
||||
pages and files saved in the web editor that hold shell commands or code
|
||||
(932125, 932235, 932250 and others), package descriptions that show code, PyPI
|
||||
uploads (922130), and attachments named like `debug.log` or `config.yml`
|
||||
(932180), until the rule ids the request log names are added to
|
||||
`SWWAF_WAF_DISABLED_RULES`.
|
||||
before the colon of a part's header line, which Coraza cannot tell from a
|
||||
header without one. The client has until `SWWAF_CLIENT_REQUEST_TIMEOUT` runs
|
||||
out to send the part that is read, and a request whose body passes
|
||||
`SWWAF_REQUEST_MAX_BYTES` within it is refused before anything reaches the
|
||||
app. Of a file in a multipart body, Coraza counts the bytes and writes
|
||||
nothing. Body inspection suits apps whose forms carry no code. In front of
|
||||
gitea it refuses issue and comment text, wiki pages and files saved in the web
|
||||
editor that hold shell commands or code (932125, 932235, 932250 and others),
|
||||
package descriptions that show code, PyPI uploads (922130), and attachments
|
||||
named like `debug.log` or `config.yml` (932180), until the rule ids the
|
||||
request log names are added to `SWWAF_WAF_DISABLED_RULES`.
|
||||
- `SWWAF_TRAP_PATHS` (default empty): paths the app never serves and only
|
||||
scanners ask for, such as `/wp-login.php,/xmlrpc.php` in front of gitea; a
|
||||
request for one bans its client for a clear sign of attack, as a `ban` rule
|
||||
|
||||
+2
-4
@@ -134,10 +134,8 @@ SecRule REQBODY_PROCESSOR "@rx ^(?:URLENCODED|MULTIPART|JSON|XML)$" \
|
||||
# Rule Set rates critical does: no rule reads what comes after the fault,
|
||||
# which the app may still read. Coraza's recommended configuration refuses
|
||||
# them in its rules 200002 and 200003. A multipart body the limit cuts
|
||||
# before the colon of a part's header line, or between the carriage return
|
||||
# and the line feed that end a part's header line or the empty line after
|
||||
# its headers, adds 5 too, since Coraza takes the line the limit cuts for a
|
||||
# malformed header. Coraza parses any form data body.
|
||||
# before the colon of a part's header line adds 5 too, since Coraza cannot
|
||||
# tell it from a header without one. Coraza parses any form data body.
|
||||
SecRule REQBODY_ERROR "!@eq 0" "id:900440,phase:2,pass,severity:'CRITICAL',\
|
||||
setvar:'tx.inbound_anomaly_score_pl1=+5'"
|
||||
SecRule MULTIPART_STRICT_ERROR "!@eq 0" "id:900450,phase:2,pass,\
|
||||
|
||||
@@ -645,25 +645,6 @@ func TestMultipartBodyCutBeforeAPartHeadersColonIsAMatch(t *testing.T) {
|
||||
body[:bodyLimit+1])
|
||||
}
|
||||
|
||||
func TestMultipartBodyCutBeforeALineFeedInAPartsHeadersIsAMatch(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
crs := readingBodies(t)
|
||||
headerLine := "--b\r\nContent-Disposition: form-data; name=\"q\"\r"
|
||||
|
||||
// The limit falls between the carriage return and the line feed that
|
||||
// end the second part's header line, and then between those that end
|
||||
// the empty line after it. Coraza, reading up to the limit, takes the
|
||||
// line ending in a lone carriage return for a malformed header.
|
||||
for _, cut := range []int{len(headerLine), len(headerLine + "\n\r")} {
|
||||
first := field("pad", strings.Repeat("a", bodyLimit-len(field("pad", ""))-cut))
|
||||
body := first + field("q", "1") + end
|
||||
|
||||
wantBody(t, crs, post(multipart), body, matched(900440, 900450),
|
||||
body[:bodyLimit+1])
|
||||
}
|
||||
}
|
||||
|
||||
// TestCorazaWritesNoFile is not parallel, since it sets TMPDIR, the
|
||||
// system's temporary directory, for the whole test process.
|
||||
func TestCorazaWritesNoFile(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user