question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

false positives with matrix synapse homeserver

See original GitHub issue

_Issue originally created by user damnms on date 2019-03-06 20:11:59. Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1321._

The default ruleset blocks matrix synapse (reference server implementation)

Type of Issue

https://github.com/SpiderLabs/ModSecurity/issues/2036 and also uploads in general seems to be blocked, at least images

Message: Access denied with code 403 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "995"] [id "920420"] [rev "2"] [msg "Request content type is not allowed by policy"] [data "image/jpeg"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/POLICY/ENCODING_NOT_ALLOWED"] [tag "WASCTC/WASC-20"] [tag "OWASP_TOP_10/A1"] [tag "OWASP_AppSensor/EE2"] [tag "PCI/12.1"]
Apache-Error: [file "apache2_util.c"] [line 273] [level 3] [client %s] ModSecurity: %s%s [uri "%s"]%s
Action: Intercepted (phase 2)
Apache-Handler: proxy-server
Stopwatch: 1551902256288022 54267 (- - -)
Stopwatch2: 1551902256288022 54267; combined=866, p1=420, p2=392, p3=0, p4=0, p5=54, sr=57, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for Apache/2.9.1 (http://www.modsecurity.org/); OWASP_CRS/3.0.0.
Server: Apache
Engine-Mode: "ENABLED"

Description

Your Environment

  • CRS version (e.g. v3.0.2): ii modsecurity-crs 3.0.0-3 all OWASP ModSecurity Core Rule Set

  • ModSecurity version (e.g. 2.9.2): ii libapache2-mod-security2 2.9.1-2 amd64 Tighten web applications security for Apache

  • Web Server and version (e.g. apache 2.4.27): ii apache2-bin 2.4.25-3+deb9u6 amd64 Apache HTTP Server (modules and other binary files)

  • Operating System and version: debian 9

Confirmation

[x ] I have removed any personal data (email addresses, IP addresses, passwords, domain names) from any logs posted.

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:7

github_iconTop GitHub Comments

1reaction
CRS-migration-botcommented, May 13, 2020

User fgsch commented on date 2019-03-07 15:59:30:

This looks like a support question so maybe more suitable for https://security.stackexchange.com/questions/tagged/mod-security?

0reactions
CRS-migration-botcommented, May 13, 2020

User dune73 commented on date 2019-03-08 16:04:50:

I do not see anything for us to do. So I’m closing this.

damnms: Feel free to reopen, if the project should act.

Read more comments on GitHub >

github_iconTop Results From Across the Web

I had a pretty positive view of Matrix until I came across this ...
It's true that Synapse is the only homeserver that is in a "finished" state, but that has more to do with Matrix being...
Read more >
Type coverage for Sydent - Matrix.org
If mypy can spot that an equality is always False , there's a good chance of there being ... Synapse is the reference...
Read more >
Installation - Synapse
At least 1GB of free RAM if you want to join large public rooms like #matrix:matrix.org. To install the Synapse homeserver run: mkdir...
Read more >
Confusion Matrix is Not so Confusing - Morioh
F.N.(False Negative): Truth is Positive but Prediction is Negative ... Synapse: Matrix Homeserver Written in Python 3/Twisted.
Read more >
matrix-synapse - PyPI
Synapse is the reference Python/Twisted Matrix homeserver implementation. ... users on your server even if enable_registration is false.
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found