false positives with matrix synapse homeserver
See original GitHub issue_Issue originally created by user damnms on date 2019-03-06 20:11:59. Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1321._
The default ruleset blocks matrix synapse (reference server implementation)
Type of Issue
https://github.com/SpiderLabs/ModSecurity/issues/2036 and also uploads in general seems to be blocked, at least images
Message: Access denied with code 403 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "995"] [id "920420"] [rev "2"] [msg "Request content type is not allowed by policy"] [data "image/jpeg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/POLICY/ENCODING_NOT_ALLOWED"] [tag "WASCTC/WASC-20"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/EE2"] [tag "PCI/12.1"]
Apache-Error: [file "apache2_util.c"] [line 273] [level 3] [client %s] ModSecurity: %s%s [uri "%s"]%s
Action: Intercepted (phase 2)
Apache-Handler: proxy-server
Stopwatch: 1551902256288022 54267 (- - -)
Stopwatch2: 1551902256288022 54267; combined=866, p1=420, p2=392, p3=0, p4=0, p5=54, sr=57, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.1 (http://www.modsecurity.org/); OWASP_CRS/3.0.0.
Server: Apache
Engine-Mode: "ENABLED"
Description
Your Environment
-
CRS version (e.g. v3.0.2): ii modsecurity-crs 3.0.0-3 all OWASP ModSecurity Core Rule Set
-
ModSecurity version (e.g. 2.9.2): ii libapache2-mod-security2 2.9.1-2 amd64 Tighten web applications security for Apache
-
Web Server and version (e.g. apache 2.4.27): ii apache2-bin 2.4.25-3+deb9u6 amd64 Apache HTTP Server (modules and other binary files)
-
Operating System and version: debian 9
Confirmation
[x ] I have removed any personal data (email addresses, IP addresses, passwords, domain names) from any logs posted.
Issue Analytics
- State:
- Created 3 years ago
- Comments:7
Top GitHub Comments
User fgsch commented on date 2019-03-07 15:59:30:
This looks like a support question so maybe more suitable for https://security.stackexchange.com/questions/tagged/mod-security?
User dune73 commented on date 2019-03-08 16:04:50:
I do not see anything for us to do. So I’m closing this.
damnms: Feel free to reopen, if the project should act.