mirror of
https://github.com/owasp-modsecurity/ModSecurity.git
synced 2025-08-13 21:36:00 +03:00
68 lines
3.5 KiB
Plaintext
68 lines
3.5 KiB
Plaintext
# ---------------------------------------------------------------
|
|
# Core ModSecurity Rule Set ver.1.6.1
|
|
# Copyright (C) 2006-2007 Breach Security Inc. All rights reserved.
|
|
#
|
|
# The ModSecuirty Core Rule Set is distributed under GPL version 2
|
|
# Please see the enclosed LICENCE file for full details.
|
|
# ---------------------------------------------------------------
|
|
|
|
|
|
#
|
|
# TODO in some cases a valid client (usually automated) generates requests that
|
|
# violates the HTTP protocol. Create exceptions for those clients, but try
|
|
# to limit the exception to a source IP or other additional properties of
|
|
# the request such as URL and not allow the violation generally.
|
|
#
|
|
|
|
# Do not accept requests without common headers.
|
|
# Implies either an attacker or a legitimate automation client.
|
|
#
|
|
# Exception for Apache SSL pinger
|
|
|
|
SecRule REQUEST_LINE "^GET /$" "chain,phase:2,t:none,pass,nolog,ctl:ruleRemoveById=960019,ctl:ruleRemoveById=960008,ctl:ruleRemoveById=960015,ctl:ruleRemoveById=960009,id:'999210',severity:'5'"
|
|
SecRule REMOTE_ADDR "^127\.0\.0\.1$" t:none
|
|
|
|
# Exception for Apache internal dummy connection
|
|
SecRule REQUEST_LINE "^GET / HTTP/1.0$" "chain,phase:2,t:none,pass,nolog,ctl:ruleRemoveById=960019,ctl:ruleRemoveById=960008,ctl:ruleRemoveById=960015,ctl:ruleRemoveById=960009,id:'999211',severity:'5'"
|
|
SecRule REMOTE_ADDR "^127\.0\.0\.1$" "chain,t:none"
|
|
SecRule REQUEST_HEADERS:User-Agent "^Apache.*\(internal dummy connection\)$" "t:none"
|
|
|
|
|
|
# Detect HTTP/0.9 Requests
|
|
SecRule REQUEST_PROTOCOL ^http/0.9$ "t:none,t:lowercase,phase:2,log,auditlog,msg:'HTTP/0.9 Request Detected',id:'960019',severity:'4'"
|
|
|
|
SecRule &REQUEST_HEADERS:Host "@eq 0" \
|
|
"skip:1,phase:2,t:none,log,auditlog,msg:'Request Missing a Host Header',id:'960008',tag:'PROTOCOL_VIOLATION/MISSING_HEADER',severity:'4'"
|
|
SecRule REQUEST_HEADERS:Host "^$" \
|
|
"phase:2,t:none,log,auditlog,msg:'Request Missing a Host Header',id:'960008',tag:'PROTOCOL_VIOLATION/MISSING_HEADER',severity:'4'"
|
|
|
|
|
|
SecRule &REQUEST_HEADERS:Accept "@eq 0" \
|
|
"chain,phase:2,skip:1,t:none,log,auditlog,msg:'Request Missing an Accept Header', severity:'2',id:'960015',tag:'PROTOCOL_VIOLATION/MISSING_HEADER'"
|
|
SecRule REQUEST_METHOD "!^OPTIONS$" "t:none"
|
|
SecRule REQUEST_HEADERS:Accept "^$" \
|
|
"chain,phase:2,t:none,log,auditlog,msg:'Request Missing an Accept Header', severity:'2',id:'960015',tag:'PROTOCOL_VIOLATION/MISSING_HEADER'"
|
|
SecRule REQUEST_METHOD "!^OPTIONS$" "t:none"
|
|
|
|
SecRule &REQUEST_HEADERS:User-Agent "@eq 0" \
|
|
"skip:1,phase:2,t:none,log,auditlog,msg:'Request Missing a User Agent Header',id:'960009',tag:'PROTOCOL_VIOLATION/MISSING_HEADER',severity:'4'"
|
|
SecRule REQUEST_HEADERS:User-Agent "^$" \
|
|
"t:none,log,auditlog,msg:'Request Missing a User Agent Header',id:'960009',tag:'PROTOCOL_VIOLATION/MISSING_HEADER',severity:'4'"
|
|
|
|
|
|
SecRule &REQUEST_HEADERS:Content-Type "@eq 0" \
|
|
"chain,phase:2,t:none,log,auditlog,msg:'Request Containing Content, but Missing Content-Type header',id:'960904',severity:'4'"
|
|
SecRule REQUEST_HEADERS:Content-Length "!^0$" "t:none"
|
|
|
|
|
|
# Check that the host header is not an IP address
|
|
#
|
|
SecRule REQUEST_HEADERS:Host "^[\d\.]+$" "phase:2,t:none,deny,log,auditlog,status:400,msg:'Host header is a numeric IP address', severity:'2',id:'960017',tag:'PROTOCOL_VIOLATION/IP_HOST'"
|
|
|
|
|
|
# Log a security event when the request is rejected by apache
|
|
#
|
|
SecRule RESPONSE_STATUS ^400$ "t:none,phase:5,chain,log,auditlog,pass,msg:'Invalid request',id:'960913',severity:'2'"
|
|
SecRule WEBSERVER_ERROR_LOG !ModSecurity "t:none"
|
|
|