Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default Mod Security Rule help

    Hello,

    we have a particular mod_security rule:
    Code:
    # php injections
    SecFilterSelective ARGS_VALUES "[[:space:]]*(to|bcc|cc)[[:space:]]*:.*@"
    that is blocking various domains when they use their Perl bulk mailer, which has worked for quiet some time with no problems, but lately they are getting blocked via the CSF firewall when it triggers the mod_security settings. Here is a snip from the audit log:
    Code:
    ==59a76e3d==============================
    Request: www.userdomain.com IP_ADDRESS - - [10/Jan/2007:21:12:19 -0600] "POST /scgi-bin/mailermem.cgi HTTP/1.1" 406 360 "http://www.winning-trader.com/scgi-bin/mailermem.cgi?access=377a88b223dc45e6&action=process" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)" - "-"
    ----------------------------------------
    POST /scgi-bin/mailermem.cgi HTTP/1.1
    Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-powerpoint, application/vnd.ms-excel, application/msword, */*
    Accept-Encoding: gzip, deflate
    Accept-Language: en-us
    Cache-Control: no-cache
    Connection: Keep-Alive
    Content-Length: 410999
    Content-Type: application/x-www-form-urlencoded
    Cookie: trader_admin=377a88b223dc45e6
    Host: www.userdomain.com
    Referer: http://www.userdomain.com/scgi-bin/mailermem.cgi?access=377a88b223dc45e6&action=process
    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
    mod_security-action: 406
    mod_security-message: Access denied with code 406. Pattern match "[[:space:]]*(to|bcc|cc)[[:space:]]*:.*@" at ARGS_VALUES("message")
    
    410999
    access=377a88b223dc45e6&action=sendmailer&format=html&subject=Thursday%27s+Trading+Update
    &message= .........
    I have been trying to figure out how to change the rule so they don't trigger the mod security rule, but not having much luck .... or should I remove this rule

    TIA,
    Mickalo

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  2. #2
    Member wolfy's Avatar
    Join Date
    Jul 2005
    Location
    Canada
    Posts
    45

    Default

    the posted rule appears to check to see if the to cc or bcc headers are malformed or missing. check one of the bulk mailer headers and confirm that all fields are formed correctly.

  3. #3
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default

    Quote Originally Posted by wolfy View Post
    the posted rule appears to check to see if the to cc or bcc headers are malformed or missing. check one of the bulk mailer headers and confirm that all fields are formed correctly.
    that's what I though too, but couldn't find anything wrong. is there some specific format it's looking for here. The mailer never uses a Bcc header but does use a Cc header on occasion.

    The rule was trigger by the user who authoirized to use mailer(their IP matched) so it wasn't some outside source attempting to use it.

    TIA,
    Mickalo

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

Similar Threads & Tags
Similar threads

  1. Mod Security?!
    By reporter in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 11-18-2009, 04:16 PM
  2. Mod security
    By black&white in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-19-2008, 11:16 AM
  3. Mod Security Rule
    By SandM in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-16-2008, 11:44 AM
  4. Mod Security Rule Question
    By Nhojohl in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-21-2007, 08:38 PM
  5. Simple security question about mod-security rule sets.
    By jols in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-09-2007, 04:37 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube