owasp-modsecurity / owasp-modsecurity/ModSecurity

Information disclosure - statuscode response containing WAF type

Open
#1,975 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

2.x Platform - IIS
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

The response status code of a blocked request contains the text: "ModSecurity Action"
This way an attacker could find for specific security holes in this product.

It would be great if this text could be changed by parameter, or not send at all.

Code:
https://github.com/SpiderLabs/ModSecurity/blob/v2/master/iis/mymodule.cpp#L670

(this is my first bug report, sorry for any possible missing information)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in iis/mymodule.cpp around line 670, where the blocked-request response includes the "ModSecurity Action" text. Trace how that response status is produced and check whether existing tests cover it. Done means the WAF type is no longer disclosed, or is controlled by a documented parameter, with the behavior verified.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.