Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Apr 2004
    Posts
    215

    Question ModSecurity blocking Firefox Indonesian version

    recently i noticed that the default rule from cpanel's modsecurity rules is blocking firefox and probably other browser which is using Indonesian language. here is the rule that give false alarm:

    Code:
    SecRule ARGS|ARGS_NAMES|REQUEST_HEADERS "(?:\b(?:(?:n(?:et(?:\b\W+?\blocalgroup|\.exe)|(?:map|c)\.exe)|t(?:racer(?:oute|t)|elnet\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\.exe|echo\b\W*?\by+)\b|c(?:md(?:(?:32)?\.exe\b|\b\W*?\/c)|d(?:\b\W*?[\\\/]|\W*?\.\.)|hmod.{0,40}?\+.{0,3}x))|[\;\|\`]\W*?\b(?:(?:c(?:h(?:grp|mod|own|sh)|md|pp|c)|p(?:asswd|ython|erl|ing|s)|n(?:asm|map|c)|f(?:inger|tp)|(?:kil|mai)l|(?:xte)?rm|ls(?:of)?|telnet|uname|echo|id)\b|g(?:\+\+|cc\b))|\/(?:c(?:h(?:grp|mod|own|sh)|pp|c)|p(?:asswd|ython|erl|ing|s)|n(?:asm|map|c)|f(?:inger|tp)|(?:kil|mai)l|g(?:\+\+|cc)|(?:xte)?rm|ls(?:of)?|telnet|uname|echo|id )(?:[\'\"\|\;\`\-\s]|$))" \
            "capture,ctl:auditLogParts=+E,deny,log,auditlog,msg:'System Command Injection. Matched signature <%{TX.0}>',id:'950006',severity:'2'"
    the rule blocks because the regex "telnet|uname|echo|id" match with firefox browser's user agent header:

    Code:
    Mozilla/5.0 (Windows; U; Windows NT 5.1; id; rv:1.9b5) Gecko/2008032620 Firefox/3.0b5
    Mozilla/5.0 (Windows; U; Windows NT 5.1; id; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
    Mozilla/5.0 (Windows; U; Windows NT 5.1; id; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1
    i wanted to create modsecurity rule to allow browser with Indonesian language but got confused with modsecurity rule, can someone help me modifying the rule to accept the browser which have Indonesian language?

    thank you
    Last edited by markhard; 01-12-2009 at 04:08 AM.
    HalfDedi.com : Half Dedicated Half Price
    We Provide Affordable VPS hosting solution in US and Singapore

  2. #2
    Registered User
    Join Date
    Mar 2007
    Location
    bali indonesia
    Posts
    2

    Question

    renaming telnet|uname|echo|id to telnet|uname|echo
    is that working?

    -------------------------
    Best Regards

    http://webwoke.com
    Last edited by harrysudana; 09-11-2009 at 08:57 AM.

  3. #3
    Registered User
    Join Date
    Feb 2008
    Posts
    4

    Default

    Quote Originally Posted by markhard View Post

    i wanted to create modsecurity rule to allow browser with Indonesian language but got confused with modsecurity rule, can someone help me modifying the rule to accept the browser which have Indonesian language?

    thank you
    Simply delete "id" ... it is decreasing the security ..
    But I haven't find any other way since the "id" is in the Indonesian Firefox user agent header.

    btw it has been discussed before .. http://www.diskusiwebhosting.com/sho...ght=rule+galak

  4. #4
    Member alphaservers's Avatar
    Join Date
    Sep 2009
    Posts
    13

    Lightbulb modsecurity problem in isp indonesian

    Since issued by the indonesian government to protected legal content for multimedia content this problems is begin to make difficulty in offshore data center who was allowed adults content

    My idea is just try to use opendns.com and make your dns server is open and unforbidden listing in isp indonesian hope you can resolve your problems soon as possible if you still have problems with your mode_security use anynomous proxy and try to use indonesian proxy and checked your website is running better in isp indonesian provider

  5. #5
    Registered User
    Join Date
    Mar 2007
    Location
    bali indonesia
    Posts
    2

    Default

    @tajid
    yes, the rule will decrease the security.

    @alphaservers
    probably opendns is good. i think it need extra campaign to inform all internet user in Indonesia for using opendns.

    or mybe should we try to contact the mozilla developer to change identity for indonesian to use "IDN" or something else instead of using "ID"?

    Or mybe try to inform the developer to stay away from using "id"?

    regards

    Harry S
    _________
    webwoke.com | SEO | Plugins | Wordpress

Similar Threads & Tags
Similar threads

  1. What version of modsecurity do you use?
    By mikegotroot in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-16-2009, 07:18 PM
  2. How can I update my modsecurity version
    By Bulent Tekcan in forum cPanel Developers
    Replies: 3
    Last Post: 06-29-2006, 06:19 AM
  3. modsecurity
    By Giannis in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-22-2005, 03:23 AM
  4. ModSecurity
    By Solokron in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-09-2004, 07:49 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube