store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 11:42 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 10 posts ] 
Author Message
 Post subject: [DONE] Dont block self referenced sites in URL
Unread postPosted: Wed Dec 31, 2008 7:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
Currently if a domain name has its own domain name in a URL arg it will get blocked. Make the engine smart enough to know that if the host in the URI is the same thing as the host in the packet to not block
IE: a site has a redirect to link or a page from (search engine, etc) in the post or URI

Maybe make a whitelist of all of the domains local to the server and if the URL is not in the whitelist then pass it through the normal rules. This would allow the posting of URLs through out sites when the URL posted is the same as the vhost hosting the application in question.


Last edited by hostingguy on Thu Apr 02, 2009 3:29 pm, edited 1 time in total.

Top
 Profile  
 
 Post subject:
Unread postPosted: Tue Jan 20, 2009 7:26 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
added as a feature request to the queue.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Jan 21, 2009 4:09 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jan 15, 2008 3:57 am
Posts: 478
Location: Netherlands
Wow, Hostingguy, you are on the move! :) ART is getting busy with the feature request.


Top
 Profile  
 
 Post subject: Re: Dont block self referenced sites in URL
Unread postPosted: Thu Mar 05, 2009 12:12 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
Any movement on this? This is probably one of the most occuring cause of false positives, trying to redirect to a url or post a URL that is also on the same site.


Top
 Profile  
 
 Post subject: Re: Dont block self referenced sites in URL
Unread postPosted: Thu Mar 05, 2009 1:35 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Its actually a very very complicated feature, if we don't do it right it opens a huge hole so its gonna take time to get it right. When its ready you'll know. :D

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Dont block self referenced sites in URL
Unread postPosted: Thu Mar 05, 2009 1:40 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
I completely understand, and I appologize if I came accross as impatient or rushing you.

I was just wondering if was actively being worked on or still written in (chalk|marker) on a board somewhere :)


Top
 Profile  
 
 Post subject: Re: Dont block self referenced sites in URL
Unread postPosted: Thu Mar 05, 2009 1:41 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Written and heavily tested. We're concerned that it may be possible to spoof it and we don't want that. :wink:

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Dont block self referenced sites in URL
Unread postPosted: Tue Mar 31, 2009 3:01 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
I have recieved word that this is out in the wild now.
Thanks guys!


Top
 Profile  
 
 Post subject: Re: Dont block self referenced sites in URL
Unread postPosted: Tue Mar 31, 2009 4:02 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Yep, its in the latest ASL/subscriber rules.

My head hurts from this one... and yes, if done wrong it was spoofable, even the modsecurity docs were wrong on this one - but we are doing it right, its not spoofable for ASL, but if you try to roll this yoursel its easy to get it wrong.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: [DONE] Dont block self referenced sites in URL
Unread postPosted: Thu Apr 02, 2009 3:29 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Oct 29, 2007 6:51 pm
Posts: 606
Thank you for this, This should solve a lot of problems.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 10 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group