You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ModSecurity拦截Google Tag Manager iframe:白名单规则失效求助

ModSecurity(Comodo WAF)拦截Google Tag Manager noscript iframe问题排查与解决

问题描述

ModSecurity(Comodo WAF)拦截了Google Tag Manager的noscript iframe,尽管/etc/modsecurity/comodo/19_Outgoing_FilterInFrame.conf配置文件中存在Google Tag Manager的白名单规则,但该规则未生效。尝试修改正则表达式后仍无法解决,需排查原因并修复。

错误日志

[Tue May 16 18:19:38.745674 2023] [:error] [pid 1796577:tid 140122351191808] [remote CLIENT.IP.ADDRESS:55326] [client CLIENT.IP.ADDRESS] ModSecurity: Access denied with code 403 (phase 4). Match of "rx \\ssrc=\\x22https:\\/\\/www\\.googletagmanager\\.com\\/ns\\.html\\?id=GTM|\\ssrc=\\x22https:\\/\\/w\\.soundcloud\\.com\\/player\\/\\?url=" against "TX:0" required. [file "/etc/modsecurity/comodo/19_Outgoing_FilterInFrame.conf"] [line "14"] [id "214540"] [rev "5"] [msg "COMODO WAF: Possibly malicious iframe tag in output||web.site|F|3"] [data "Matched Data: <iframe \\x0a\\x09\\x09height=\\x220\\x22 width=\\x220\\x22 style=\\x22display:none found within TX:0: <iframe \\x0a\\x09\\x09height=\\x220\\x22 width=\\x220\\x22 style=\\x22display:none"] [severity "ERROR"] [tag "CWAF"] [tag "FilterInFrame"] [hostname "web.site"] [uri "/index.php"] [unique_id "ZGOtGn8OVNnjiBWdgt2VdgADRxI"]

[Tue May 16 18:19:38.865218 2023] [:error] [pid 1796577:tid 140122167179008] [client CLIENT.IP.ADDRESS:55326] [client CLIENT.IP.ADDRESS] ModSecurity: Warning. Operator GE matched 4 at TX:outgoing_points. [file "/etc/modsecurity/comodo/20_Outgoing_FiltersEnd.conf"] [line "38"] [id "214940"] [rev "2"] [msg "COMODO WAF: Outbound Points Exceeded| Total Points: 4|web.site|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "FiltersEnd"] [hostname "web.site"] [uri "/index.php"] [unique_id "ZGOtGn8OVNnjiBWdgt2VdgADRxI"]

配置文件内容(/etc/modsecurity/comodo/19_Outgoing_FilterInFrame.conf)

SecRule RESPONSE_BODY "<[^a-zA-Z0-9_]{0,}iframe[^>]{1,}?\bstyle[^a-zA-Z0-9_]{0,}?=[^a-zA-Z0-9_]{0,}?[\x22']{0,1}[^a-zA-Z0-9_]{0,}?\bdisplay\b[^a-zA-Z0-9_]{0,}?:[^a-zA-Z0-9_]{0,}?\bnone\b" \
        "id:214540,chain,msg:'COMODO WAF: Possibly malicious iframe tag in output||%{tx.domain}|%{tx.mode}|3',phase:4,capture,block,setvar:'tx.outgoing_points=+%{tx.points_limit3}',setvar:'tx.points=+%{tx.points_limit3}',logdata:'Matched Data: %{TX.0} found within %{MATCHED_VAR_NAME}: %{MATCHED_VAR}',ctl:auditLogParts=+E,t:replaceComments,rev:5,severity:3,tag:'CWAF',tag:'FilterInFrame'"
SecRule &REQUEST_COOKIES:sugar_user_theme "@eq 0" \
        "chain,t:none"
SecRule TX:0 "!@rx \ssrc=\x22https:\/\/www\.googletagmanager\.com\/ns\.html\?id=GTM|\ssrc=\x22https:\/\/w\.soundcloud\.com\/player\/\?url=" \
        "t:none,t:urlDecodeUni"

SecRule RESPONSE_BODY "(?i:<[\t\n\r ]{0,}IFRAME[\t\n\r ]{0,}?[^>]{0,}?src=\x22javascript:)" \
        "id:214550,msg:'COMODO WAF: Malicious iframe+javascript tag in output||%{tx.domain}|%{tx.mode}|3',phase:4,capture,block,setvar:'tx.outgoing_points=+%{tx.points_limit3}',setvar:'tx.points=+%{tx.points_limit3}',logdata:'Matched Data: %{TX.0} found within %{MATCHED_VAR_NAME}: %{MATCHED_VAR}',ctl:auditLogParts=+E,t:none,rev:1,severity:3,tag:'CWAF',tag:'FilterInFrame'"

SecMarker SECMARKER_214400

网站实际使用的iframe代码

<!-- Google Tag Manager (noscript) -->
<noscript><iframe height="0" width="0" style="display:none;visibility:hidden" data-src="https://www.googletagmanager.com/ns.html?id=GTM-XXXZZZ" class="lazyload" src="data:image/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw=="></iframe></noscript>
<!-- End Google Tag Manager (noscript) -->

问题分析

  1. 白名单规则匹配范围有限:现有规则仅匹配src=属性,但网站的iframe使用data-src存储GTM的真实地址,src属性是占位的base64图片,导致规则无法识别这是合法的GTM iframe。
  2. 链规则触发逻辑:ID为214540的链规则逻辑为:
    • 第一步:匹配所有包含display:none样式的iframe
    • 第二步:检查请求中不存在sugar_user_theme cookie
    • 第三步:检查匹配到的iframe片段(TX:0)不包含白名单的src格式,满足条件则触发拦截

解决方案

方案1:修改白名单规则支持data-src

修改配置文件中ID为214540的第三行规则,扩展正则以同时匹配src=和data-src=:

SecRule TX:0 "!@rx \s(?:src|data-src)=\x22https:\/\/www\.googletagmanager\.com\/ns\.html\?id=GTM|\ssrc=\x22https:\/\/w\.soundcloud\.com\/player\/\?url=" \
        "t:none,t:urlDecodeUni"

修改后重启ModSecurity服务生效:

systemctl restart apache2 # 或对应web服务的重启命令

方案2:临时禁用该拦截规则(应急用)

若需快速恢复业务,可临时禁用ID为214540的规则,在配置文件末尾添加:

SecRuleRemoveById 214540

注意:此方案会关闭所有display:none iframe的恶意检测,仅建议应急使用。

方案3:调整iframe代码(若业务允许)

将GTM地址直接放到src属性中,移除data-src和懒加载配置(会影响懒加载效果,需权衡):

<!-- Google Tag Manager (noscript) -->
<noscript><iframe height="0" width="0" style="display:none;visibility:hidden" src="https://www.googletagmanager.com/ns.html?id=GTM-XXXZZZ"></iframe></noscript>
<!-- End Google Tag Manager (noscript) -->

内容的提问来源于stack exchange,提问作者Francesco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 15:34:56