ModSecurity误判.AspNetCore.Antiforgery Cookie致403访问拒绝问题
403 Access Denied 错误排查与解决
问题现象
- 客户登录管理面板后,一段时间内会触发403 Access Denied错误,短时间内无法再次访问
- 错误频繁出现在编辑网站文本的操作之后
- 服务器返回500状态码,但核心报错为403权限拒绝
服务器日志分析
7349874592942424484 176.88.108.248 80 127.0.0.1 80 --122d0000-B-- GET /favicon.ico HTTP/1.1 Connection: close Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8 Accept-Encoding: gzip, deflate, br, zstd Accept-Language: tr-TR,tr;q=0.8 Cookie: .AspNetCore.Antiforgery.xxxxxxxxxxxxxxxxxxxxxWBCsC7x5LrYIFTqa3CGRihNU-FLOYGFkHBDQ8W-m36dUubxUZj-xxxxxxxxxxxxxxxxxxxxxxGNgpUY; Language=tr Host: dxxxxxxxxxxxxxxxxxxxx Referer: https://xxxxxxxxxx/Home/Service User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 sec-ch-ua: "Not)A;Brand";v="99", "Brave";v="127", "Chromium";v="127" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" sec-gpc: 1 sec-fetch-site: same-origin sec-fetch-mode: no-cors sec-fetch-dest: image priority: i --122d0000-F-- HTTP/1.1 500 Internal Server Error --122d0000-H-- Message: Access denied with code 403 (phase 2). Pattern match "(?:/\*!?|\*/|[';]--|--[\s\r\n\v\f]|--[^-]*?-|[^&-]#.*?[\s\r\n\v\f]|;?\x00)" at REQUEST_COOKIES:.AspNetCore.Antiforgery.h8nIiv1b7VI. [file "C:
核心问题定位
从日志可以明确:
- 这是WAF(Web应用防火墙)触发的拦截,规则匹配了疑似SQL注入的特征字符串
- 拦截目标是ASP.NET Core的Antiforgery令牌Cookie(
.AspNetCore.Antiforgery.*),令牌中的某些字符被WAF误判为恶意注入代码
解决方案
1. 调整WAF规则,排除Antiforgery Cookie检测
将.AspNetCore.Antiforgery开头的Cookie加入WAF白名单,跳过SQL注入相关规则检测:
- 若使用ModSecurity,添加规则:
(注:942100是常见的SQL注入检测规则ID,需根据你实际使用的WAF规则ID调整)SecRule REQUEST_COOKIES_NAMES "@beginsWith .AspNetCore.Antiforgery" "phase:2,nolog,allow,ctl:ruleRemoveById=942100" - 若使用云WAF,在规则中添加Cookie名称的例外项,排除
.AspNetCore.Antiforgery.*
2. 优化Antiforgery令牌生成配置
修改ASP.NET Core的Antiforgery配置,限制令牌使用的字符集,避免生成易被WAF误判的字符:
services.AddAntiforgery(options => { options.Cookie.Name = ".AspNetCore.Antiforgery"; // 使用更安全的字符集,减少特殊字符 options.TokenProvider = new DefaultAntiforgeryTokenProvider(new AntiforgeryTokenSettings { TokenChars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_", }); });
3. 检查会话与令牌刷新机制
- 确认管理面板的会话超时时间设置,避免因会话过期导致令牌失效后触发WAF拦截
- 确保在长时间编辑操作时,页面能自动刷新Antiforgery令牌(比如通过AJAX定时获取新令牌),避免旧令牌被WAF误判
4. 验证编辑操作的字符传递
检查编辑文本时是否有特殊字符(如#、--、/*等)被意外带入Cookie中——虽然Antiforgery令牌不会直接包含用户输入,但需排除业务逻辑中的异常传递情况
内容的提问来源于stack exchange,提问作者Murat Can Kılıç
相关产品推荐
相关产品推荐

