Coreruleset: False Positive on REQUEST-930-APPLICATION-ATTACK-LFI

Created on 13 May 2020  路  8Comments  路  Source: coreruleset/coreruleset

_Issue originally created by user neesinch on date 2017-05-18 01:53:04.
Link to original issue: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/783._

Hi,
I am having some trouble in image upload to the server. I am clueless as to what's triggering REQUEST-930-APPLICATION-ATTACK-LFI while uploading images. And surprisingly mod security allows some images whereas block others citing the above rule.

I am unable to understand as to why LFI has to trigger while uploading or POST as well.
Any guidance / help is highly appreciable.

This is my audit log, truncated some information for readability.

---T3oS3FAr---A--
[17/May/2017:19:33:54 -0400] 14950640341.000000 192.168.6.253 38322 192.168.6.253 443
---T3oS3FAr---B--
POST /Common/ManualUploadChunks HTTP/1.1
Accept-Language: en-US,en;q=0.8
Referer:
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryt15zAFJdSMDgWhIO
Cache-Control: no-cache
Accept: application/json
parentType: null
height: 60
Host:
requestorSoid: null
Cookie: __RequestVerificationToken=ZWI9ErWWFqnRs24F3xtfU9P4iVaU0ZOhVVmpAG89ipLeWBziLd2St6AA2T_xEzkB6bzQu0AO0P3pWxpQAP8_GAjAajgdUse74Pksfn5A8Cg1; .AspNet.ApplicationCookie=HKooabR_pxY15e68sUUqvK9LXq8gahgQa9aEabhzf2Y98cW9X6POGcCmQtifwEGnt-BAzH5zok8NvmY2HqioZ936AZIdZNvmHvK-K3QGfDomTIFhzUs4B3be1_QW6wTgwayjXV5hKEGyCrvNh9XbACxx15LVE3EPBLnk_m5797xErdZ2hrb8UNn9xqukbxZQ7FdJGp23Qd2_xXZItigdNwUDlDytwjeaLGA5XyOZD1JbASUbDzBCWf3vWo6KZyAB4DyT9QXpimqdqvg-kq_yP6iJ60up98MMxHIv9YJUKQMUYZagL50318pZRkEDQUyHc4IFUkWqNsK0qBpQdVy89PJ3mlQD9ON4RTW-rXpiHP6TA31ftR0-04o3mvNG6W0TDJhOnpR24zeJFoGvI1l3Gw
Connection: keep-alive
width: 60
type: image
Accept-Encoding: gzip, deflate, br
Content-Length: 136989
Origin:
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36
id: undefined
X-Requested-With: XMLHttpRequest

---T3oS3FAr---D--

---T3oS3FAr---F--
Server: nginx/1.11.12
Date: Wed, 17 May 2017 23:33:54 GMT
Content-Length: 572
Content-Type: text/html
Connection: keep-alive

---T3oS3FAr---H--
ModSecurity: Warning. Matched "Operator Pm' with parameter..\ ../' against variable REQUEST_BODY' (Value:------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqpartindex"x (801395 characters omitted)' ) [file "/opt/owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "49"] [id "930110"] [rev "1"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: ../ found within REQUEST_BODY: ------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqpartindex"x0dx0ax0dx0a0x0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqpartbyteoffset"x0dx0ax0dx0a0x0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqchunksize"x0dx0ax0dx0a136021x0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqtotalparts"x0dx0ax0dx0a1x0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqtotalfilesize"x0dx0ax0dx0a136021x0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqfilename"x0dx0ax0dx0aindianfilmhistory_bg-1024x576.jpgx0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qquuid"x0dx0ax0dx0a84713fb1-241f-43e2-877d-22a3a33eceabx0dx0a------WebKitFormBoundaryt15zAFJdSMDgWhIOx0dx0aContent-Disposition: form-data; name="qqfile"; filename="blob"x0dx0aContent-Type: application/octet-streamx0dx0ax0dx0axffffffffxffffffd8xffffffffxffffffe0x00x10JFIFx00x01x01x01x00x00x00x00x00x00xffffffffxffffffdbx00Cx00x06x04x04x05x04x04x06x05x05x05x06x06x06x07x09x0ex09x09x08x08x09x12x0dx0dx0ax0ex15x12x16x16x15x12x14x14x17x1a!x1cx17x18x1fx19x14x14x1d'x1dx1f"#%%%x16x1c),------WebKitFormBoundaryt15zAFJdSMDgWhIO--x0dx0a"] [severity "2"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "OWASP_CRS/WEB_ATTACK/DIR_TRAVERSAL"] [ref "o100366,3v1323,136989t:utf8toUnicode,t:urlDecodeUni,t:removeNulls,t:cmdLine"]
ModSecurity: Warning. Matched "Operator Ge' with parameter%{tx.inbound_anomaly_score_threshold}' against variable TX:ANOMALY_SCORE' (Value:5' ) [file "/opt/owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "36"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "2"] [ver ""] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [ref ""]
ModSecurity: Warning. Matched "Operator Ge' with parameter%{tx.inbound_anomaly_score_threshold}' against variable TX:INBOUND_ANOMALY_SCORE' (Value:5' ) [file "/opt/owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf"] [line "61"] [id "980130"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): Path Traversal Attack (/../)'"] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [tag "event-correlation"] [ref ""]

---T3oS3FAr---I--

---T3oS3FAr---J--

---T3oS3FAr---Z--

---nb7Vj0mJ---A--
[17/May/2017:20:49:14 -0400] 14950685541.000000 169.54.244.93 44109 169.54.244.93 80
---nb7Vj0mJ---B--
GET / HTTP/1.0
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0
Accept: /

---nb7Vj0mJ---D--

---nb7Vj0mJ---F--
Server: nginx/1.11.12
Date: Thu, 18 May 2017 00:49:14 GMT
Content-Length: 170
Content-Type: text/html
Connection: close

---nb7Vj0mJ---H--
ModSecurity: Warning. Matched "Operator Eq' with parameter0' against variable REQUEST_HEADERS:Host' (Value:0' ) [file "/opt/owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "526"] [id "920280"] [rev "2"] [msg "Request Missing a Host Header"] [data ""] [severity "4"] [ver "OWASP_CRS/3.0.0"] [maturity "9"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [ref ""]

---nb7Vj0mJ---I--

---nb7Vj0mJ---J--

---nb7Vj0mJ---Z--

0f4da132-524e-465e-bf05-8c1360116d86-original

All 8 comments

_User csanders-git commented on date 2017-05-18 02:53:32:_

not sure about the first one, couldn't replicate that but it is missing a host header cause it's empty

_User neesinch commented on date 2017-05-18 03:10:18:_

csanders-git I purposely removed the Host: it was showing my public domain. I have attached one of such image causing this issue. Can someone try it on their setup and update?

_User csanders-git commented on date 2017-05-18 03:11:45:_

I ran the request given as follows with the provided rule not triggering. The below did not trigger 930110 on my test setup.
screenshot from 2017-05-17 23-11-30

_User neesinch commented on date 2017-05-18 03:17:39:_

csanders-git I am not sure what's causing that failure in your lab setup. As I mentioned some images are not being blocked by this rule where as some are. One such image is uploaded along with the issue. Can you please try that in your lab environment?

_User csanders-git commented on date 2017-05-18 03:18:42:_

ahh didn't see the image, thank you -- sorry :)

_User lifeforms commented on date 2017-05-18 13:26:07:_

I have an open issue for this false positive: #597

We hope to address it in a future update, but for now, writing a custom whitelist rule is your only option. You could add the following to your configuration to disable this check on your upload endpoint. Note that it might enable LFI injections, but unfortunately more fine grained control is not possible at this point. Edit: I recommend removing this configuration once we have fixed the issue:

SecRule REQUEST_FILENAME "@streq /Common/ManualUploadChunks" \
    "id:123456,phase:1,t:none,nolog,pass,\
        ctl:ruleRemoveTargetById=930110;REQUEST_BODY"

Thanks for your report. If you are interested in tracking it further, please subscribe to issue #597.

_User neesinch commented on date 2017-05-19 00:39:07:_

lifeforms thanks for the update, I know with this approach i am opening another hole. but we don;t have any option as of now.

Our team has been having this issue recently. Is there an update on when this will be fixed?

Was this page helpful?
0 / 5 - 0 ratings

Related issues

CRS-migration-bot picture CRS-migration-bot  路  13Comments

CRS-migration-bot picture CRS-migration-bot  路  8Comments

CRS-migration-bot picture CRS-migration-bot  路  7Comments

CRS-migration-bot picture CRS-migration-bot  路  5Comments

CRS-migration-bot picture CRS-migration-bot  路  11Comments