IIS 10中ModSecurity检测模式仍阻断PHP交互的问题求助
问题描述
在IIS 10上安装ModSecurity后,已完成Request-900*.conf.example重命名为.conf、规则创建等操作,但无论将SecRuleEngine设为On还是DetectionOnly模式,PHP页面的所有交互功能均失效(如WordPress登录表单无法提交),仅能浏览静态页面。
错误日志信息
debug.log 错误记录
[06/Mar/2024:07:10:02.227184 +0100] [SERVER/sid#214b7a32ab0][rid#214b7a34ac0][//xmlrpc.php][2] Warning. Match of "eq 0" against "REQBODY_ERROR" required. [file "C:\Program Files\ModSecurity IIS\modsecurity.conf"] [line "64"] [id "200002"] [msg "Failed to parse request body."] [data "XML parser error: XML: Failed parsing document."] [severity "CRITICAL"]
modsecurity.conf 第64行规则
id:'200002', phase:2,t:none,log,deny,status:400,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2
modsec_audit.log 记录
--df680000-F-- HTTP/1.1 500 Internal Server Error Connection: close Date: Wed, 06 Mar 2024 06:10:03 +0000 Content-Type: text/xml; charset=UTF-8 Server: Microsoft-IIS/10.0 X-Robots-Tag: noindex, follow --df680000-E-- <?xml version="1.0" encoding="UTF-8"?> <methodResponse> <fault> <value> <struct> <member> <name>faultCode</name> <value><int>-32700</int></value> </member> <member> <name>faultString</name> <value><string>parse error. not well formed</string></value> </member> </struct> </value> </fault> </methodResponse> --df680000-H-- Message: XML parser error: XML: Failed parsing document. Message: Warning. Match of "eq 0" against "REQBODY_ERROR" required. [file "C:\Program Files\ModSecurity IIS\modsecurity.conf"] [line "64"] [id "200002"] [msg "Failed to parse request body."] [data "XML parser error: XML: Failed parsing document."] [severity "CRITICAL"] Apache-Handler: IIS Stopwatch: 1709705402227184 1218771 (- - -) Stopwatch2: 1709705402227184 1218771; combined=0, p1=0, p2=0, p3=0, p4=0, p5=0, sr=0, sw=0, l=0, gc=0 Response-Body-Transformed: Dechunked Producer: ModSecurity for IIS (STABLE)/2.9.7 (http://www.modsecurity.org/). Server: ModSecurity Standalone Engine-Mode: "DETECTION_ONLY" --df680000-Z--
解决方案
1. 调整请求体解析配置
检查modsecurity.conf中的核心参数,确保针对不同内容类型的解析逻辑正确:
- 确认表单提交(
application/x-www-form-urlencoded)的基础配置:SecRequestBodyAccess On SecRequestBodyLimit 13107200 - 针对XML内容添加专属解析规则,确保ModSecurity使用正确处理器:
SecRule REQUEST_HEADERS:Content-Type "@streq application/xml" "id:'100001',phase:1,nolog,pass,ctl:requestBodyProcessor=XML"
2. 排除特定路径的规则拦截
如果xmlrpc.php这类路径不需要严格XML解析验证,可直接跳过目标规则:
在自定义规则文件或modsecurity.conf中添加:
SecRule REQUEST_URI "@endsWith /xmlrpc.php" "id:'100002',phase:1,nolog,pass,ctl:ruleRemoveById=200002"
或者修改原规则,仅对非指定路径生效:
id:'200002', phase:2,t:none,log,deny,status:400,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2,chain SecRule REQUEST_URI "!@endsWith /xmlrpc.php"
3. 临时调整规则动作
将规则200002的deny改为pass,仅记录错误不阻断请求,先恢复交互功能再排查根源:
id:'200002', phase:2,t:none,log,pass,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2
4. 优化XML解析器配置
添加XML解析限制参数,避免因解析深度或外部实体导致错误:
SecRequestBodyXMLDepthLimit 1000 SecRequestBodyXMLExternalEntities Off
5. 检查IIS基础配置
确认IIS请求筛选未拦截请求体,且PHP FastCGI处理程序配置正确,确保请求体可完整传递给ModSecurity和PHP。
内容的提问来源于stack exchange,提问作者user3488573
相关产品推荐
相关产品推荐

