You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IIS 10中ModSecurity检测模式仍阻断PHP交互的问题求助

问题描述

在IIS 10上安装ModSecurity后,已完成Request-900*.conf.example重命名为.conf、规则创建等操作,但无论将SecRuleEngine设为On还是DetectionOnly模式,PHP页面的所有交互功能均失效(如WordPress登录表单无法提交),仅能浏览静态页面。

错误日志信息

debug.log 错误记录

[06/Mar/2024:07:10:02.227184 +0100] [SERVER/sid#214b7a32ab0][rid#214b7a34ac0][//xmlrpc.php][2] Warning. Match of "eq 0" against "REQBODY_ERROR" required. [file "C:\Program Files\ModSecurity IIS\modsecurity.conf"] [line "64"] [id "200002"] [msg "Failed to parse request body."] [data "XML parser error: XML: Failed parsing document."] [severity "CRITICAL"]

modsecurity.conf 第64行规则

id:'200002', phase:2,t:none,log,deny,status:400,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2

modsec_audit.log 记录

--df680000-F--
HTTP/1.1 500 Internal Server Error
Connection: close
Date: Wed, 06 Mar 2024 06:10:03 +0000
Content-Type: text/xml; charset=UTF-8
Server: Microsoft-IIS/10.0
X-Robots-Tag: noindex, follow

--df680000-E--
<?xml version="1.0" encoding="UTF-8"?>
<methodResponse>
  <fault>
    <value>
      <struct>
        <member>
          <name>faultCode</name>
          <value><int>-32700</int></value>
        </member>
        <member>
          <name>faultString</name>
          <value><string>parse error. not well formed</string></value>
        </member>
      </struct>
    </value>
  </fault>
</methodResponse>

--df680000-H--
Message: XML parser error: XML: Failed parsing document.
Message: Warning. Match of "eq 0" against "REQBODY_ERROR" required. [file "C:\Program Files\ModSecurity IIS\modsecurity.conf"] [line "64"] [id "200002"] [msg "Failed to parse request body."] [data "XML parser error: XML: Failed parsing document."] [severity "CRITICAL"]
Apache-Handler: IIS
Stopwatch: 1709705402227184 1218771 (- - -)
Stopwatch2: 1709705402227184 1218771; combined=0, p1=0, p2=0, p3=0, p4=0, p5=0, sr=0, sw=0, l=0, gc=0
Response-Body-Transformed: Dechunked
Producer: ModSecurity for IIS (STABLE)/2.9.7 (http://www.modsecurity.org/).
Server: ModSecurity Standalone
Engine-Mode: "DETECTION_ONLY"
--df680000-Z--
解决方案

1. 调整请求体解析配置

检查modsecurity.conf中的核心参数,确保针对不同内容类型的解析逻辑正确:

  • 确认表单提交(application/x-www-form-urlencoded)的基础配置:
    SecRequestBodyAccess On
    SecRequestBodyLimit 13107200
    
  • 针对XML内容添加专属解析规则,确保ModSecurity使用正确处理器:
    SecRule REQUEST_HEADERS:Content-Type "@streq application/xml" "id:'100001',phase:1,nolog,pass,ctl:requestBodyProcessor=XML"
    

2. 排除特定路径的规则拦截

如果xmlrpc.php这类路径不需要严格XML解析验证,可直接跳过目标规则:
在自定义规则文件或modsecurity.conf中添加:

SecRule REQUEST_URI "@endsWith /xmlrpc.php" "id:'100002',phase:1,nolog,pass,ctl:ruleRemoveById=200002"

或者修改原规则,仅对非指定路径生效:

id:'200002', phase:2,t:none,log,deny,status:400,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2,chain
SecRule REQUEST_URI "!@endsWith /xmlrpc.php"

3. 临时调整规则动作

将规则200002的deny改为pass,仅记录错误不阻断请求,先恢复交互功能再排查根源:

id:'200002', phase:2,t:none,log,pass,msg:'Failed to parse request body.',logdata:'%{reqbody_error_msg}',severity:2

4. 优化XML解析器配置

添加XML解析限制参数,避免因解析深度或外部实体导致错误:

SecRequestBodyXMLDepthLimit 1000
SecRequestBodyXMLExternalEntities Off

5. 检查IIS基础配置

确认IIS请求筛选未拦截请求体,且PHP FastCGI处理程序配置正确,确保请求体可完整传递给ModSecurity和PHP。

内容的提问来源于stack exchange,提问作者user3488573

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 10:13:21