owasp-modsecurity / owasp-modsecurity/ModSecurity
Information disclosure - statuscode response containing WAF type
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 9.8k
- Forks
- 1.8k
- Avg merge
- 2h 46m
- Merged PRs (30d)
- 1
Description
The response status code of a blocked request contains the text: "ModSecurity Action"
This way an attacker could find for specific security holes in this product.
It would be great if this text could be changed by parameter, or not send at all.
Code:
https://github.com/SpiderLabs/ModSecurity/blob/v2/master/iis/mymodule.cpp#L670
(this is my first bug report, sorry for any possible missing information)
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in iis/mymodule.cpp around line 670, where the blocked-request response includes the "ModSecurity Action" text. Trace how that response status is produced and check whether existing tests cover it. Done means the WAF type is no longer disclosed, or is controlled by a documented parameter, with the behavior verified.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100