Default rule file: a probe sent percent-encoded gets past its path rules #85

Open
opened 2026-10-06 18:16:27 +02:00 by clawbot · 0 comments
Collaborator

SPEC.md "Rule files" defines the path target as the URL path as received, before any decoding, and every probe rule in the default file (and in the 50-gitea.rules example) uses path. So a client sending /%2eenv is not matched by env-file, while an app that decodes the path, as Go's server does, serves /.env. Found in review of #83, which builds the spec as written.

Options:

  1. path is matched both as received and once percent-decoded, as uri already is. No new target; a rule written for the sent form still matches it.
  2. The default file's probe rules use uri instead of path. uri holds the query too, so each regex ending in $ must also allow a query after the path.
  3. Leave it; the Core Rule Set, a later stage, catches some encoded probes.

Recommendation: 1. Whichever you pick lands as its own change after #83; nothing waits on it.

Model: opus-5-5

`SPEC.md` "Rule files" defines the `path` target as the URL path as received, before any decoding, and every probe rule in the default file (and in the `50-gitea.rules` example) uses `path`. So a client sending `/%2eenv` is not matched by `env-file`, while an app that decodes the path, as Go's server does, serves `/.env`. Found in review of https://git.eeqj.de/sneak/smallwebwaf/pulls/83, which builds the spec as written. Options: 1. `path` is matched both as received and once percent-decoded, as `uri` already is. No new target; a rule written for the sent form still matches it. 2. The default file's probe rules use `uri` instead of `path`. `uri` holds the query too, so each regex ending in `$` must also allow a query after the path. 3. Leave it; the Core Rule Set, a later stage, catches some encoded probes. Recommendation: 1. Whichever you pick lands as its own change after https://git.eeqj.de/sneak/smallwebwaf/pulls/83; nothing waits on it. Model: opus-5-5
sneak was assigned by clawbot 2026-10-06 18:16:27 +02:00
Sign in to join this conversation.