You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ModSecurity误判.AspNetCore.Antiforgery Cookie致403访问拒绝问题

403 Access Denied 错误排查与解决

问题现象

  • 客户登录管理面板后,一段时间内会触发403 Access Denied错误,短时间内无法再次访问
  • 错误频繁出现在编辑网站文本的操作之后
  • 服务器返回500状态码,但核心报错为403权限拒绝

服务器日志分析

7349874592942424484 176.88.108.248 80 127.0.0.1 80
--122d0000-B--
GET /favicon.ico HTTP/1.1
Connection: close
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Accept-Encoding: gzip, deflate, br, zstd
Accept-Language: tr-TR,tr;q=0.8
Cookie: .AspNetCore.Antiforgery.xxxxxxxxxxxxxxxxxxxxxWBCsC7x5LrYIFTqa3CGRihNU-FLOYGFkHBDQ8W-m36dUubxUZj-xxxxxxxxxxxxxxxxxxxxxxGNgpUY; Language=tr
Host: dxxxxxxxxxxxxxxxxxxxx
Referer: https://xxxxxxxxxx/Home/Service
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36
sec-ch-ua: "Not)A;Brand";v="99", "Brave";v="127", "Chromium";v="127"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Windows"
sec-gpc: 1
sec-fetch-site: same-origin
sec-fetch-mode: no-cors
sec-fetch-dest: image
priority: i

--122d0000-F--
HTTP/1.1 500 Internal Server Error

--122d0000-H--
Message: Access denied with code 403 (phase 2). Pattern match "(?:/\*!?|\*/|[';]--|--[\s\r\n\v\f]|--[^-]*?-|[^&-]#.*?[\s\r\n\v\f]|;?\x00)" at REQUEST_COOKIES:.AspNetCore.Antiforgery.h8nIiv1b7VI. [file "C:

核心问题定位

从日志可以明确:

  • 这是WAF(Web应用防火墙)触发的拦截,规则匹配了疑似SQL注入的特征字符串
  • 拦截目标是ASP.NET Core的Antiforgery令牌Cookie(.AspNetCore.Antiforgery.*),令牌中的某些字符被WAF误判为恶意注入代码

解决方案

1. 调整WAF规则,排除Antiforgery Cookie检测

将.AspNetCore.Antiforgery开头的Cookie加入WAF白名单,跳过SQL注入相关规则检测:

  • 若使用ModSecurity,添加规则:
    SecRule REQUEST_COOKIES_NAMES "@beginsWith .AspNetCore.Antiforgery" "phase:2,nolog,allow,ctl:ruleRemoveById=942100"
    
    (注:942100是常见的SQL注入检测规则ID,需根据你实际使用的WAF规则ID调整)
  • 若使用云WAF,在规则中添加Cookie名称的例外项,排除.AspNetCore.Antiforgery.*

2. 优化Antiforgery令牌生成配置

修改ASP.NET Core的Antiforgery配置,限制令牌使用的字符集,避免生成易被WAF误判的字符:

services.AddAntiforgery(options =>
{
    options.Cookie.Name = ".AspNetCore.Antiforgery";
    // 使用更安全的字符集,减少特殊字符
    options.TokenProvider = new DefaultAntiforgeryTokenProvider(new AntiforgeryTokenSettings
    {
        TokenChars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_",
    });
});

3. 检查会话与令牌刷新机制

  • 确认管理面板的会话超时时间设置,避免因会话过期导致令牌失效后触发WAF拦截
  • 确保在长时间编辑操作时,页面能自动刷新Antiforgery令牌(比如通过AJAX定时获取新令牌),避免旧令牌被WAF误判

4. 验证编辑操作的字符传递

检查编辑文本时是否有特殊字符(如#、--、/*等)被意外带入Cookie中——虽然Antiforgery令牌不会直接包含用户输入,但需排除业务逻辑中的异常传递情况

内容的提问来源于stack exchange,提问作者Murat Can Kılıç

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 22:45:00