You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ModSecurity阻断WordPress主题编辑器,求正确编写排除规则方案

问题背景

在搭载Virtualmin的VPS上运行ModSecurity 2.9.3和OWASP CRS 3.3.2,已启用REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES规则集,整体运行正常,但使用WordPress主题编辑器保存时会收到403响应(提示“保存失败”),禁用ModSecurity后恢复正常。

尝试的排除规则

在REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf中添加了以下规则,但问题仍未解决:

SecRule REQUEST_URI "@contains /wp-json/wp/v2/template-parts/" \
"id:10000002,\
phase:2,\
pass,\
nolog,\
ctl:ruleRemoveTargetById=949110;ARGS=content,\
ctl:ruleRemoveTargetById=941100;ARGS=content,\
ctl:ruleRemoveTargetById=941160;ARGS=content,\
ctl:ruleRemoveTargetById=941180;ARGS=content,\
ctl:ruleRemoveTargetById=932105;ARGS=content,\
ctl:ruleRemoveTargetById=980130;ARGS=content"

SecRule REQUEST_URI "@contains /wp-json/wp/v2/templates/<hostname>/page/" \
"id:10000003,\
phase:2,\
pass,\
nolog,\
ctl:ruleRemoveTargetById=949110;ARGS=content,\
ctl:ruleRemoveTargetById=941100;ARGS=content,\
ctl:ruleRemoveTargetById=941160;ARGS=content,\
ctl:ruleRemoveTargetById=941180;ARGS=content,\
ctl:ruleRemoveTargetById=932105;ARGS=content,\
ctl:ruleRemoveTargetById=980130"

已确认规则被加载(修改请求URI会导致WordPress完全无法运行),但误报依然存在。

审计日志中的误报示例

触发403时的审计日志内容如下:

--48163009-H--
Message: Warning. Pattern match "(?:;|\\{|\\||\\|\\||&|&amp;&amp;|\\n|\\r|\\$\\(|\\$\\(\\(|`|\\${|&lt;\\(|&gt;\\(|\\(\\s*\\))\\s*(?:{|\\s*\\(\\s*|\w+=(?:[^\\s]*|\\$.*|\\$.*|&lt;.*|&gt;.*|\\'.*\\'|\"*.\")\\s+|!\\s*|\\$)*\\s*(?:'|\")*(?:[\\?\\*\\[\\]\\(\\)\\-\\|+\w'\"\\./\\\\]+/)?[\\\\'\"\]*(?:s[\\\\'\"\]* ..." at ARGS:content. [file "/etc/modsecurity/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "158"] [id "932105"] [msg "Remote Command Execution: Unix Command Injection"] [data "Matched Data: {\x22top found within ARGS:content: &lt;!-- wp:template-part {\x22slug\x22:\x22header\x22,\x22theme\x22:\x22&lt;hostname&gt;\x22,\x22tagName\x22:\x22header\x22} /--&gt;\x0a\x0a&lt;!-- wp:group {\x22tagName\x22:\x22main\x22,\x22style\x22:{\x22spacing\x22:{\x22padding\x22:{\x22top\x22:\x220\x22,\x22right\x22:\x220\x22,\x22bottom\x22:\x220\x22,\x22left\x22:\x220\x22},\x22blockGap\x22:\x220\x22}}} --&gt;\x0a&lt;main class=\x22wp-block-group\x22 style=\x22padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\x2..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"]



Message: Warning. detected XSS using libinjection. [file "/etc/modsecurity/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "55"] [id "941100"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: XSS data found within ARGS:content: &lt;!-- wp:template-part {\x22slug\x22:\x22header\x22,\x22theme\x22:\x22&lt;hostname&gt;\x22,\x22tagName\x22:\x22header\x22} /--&gt;\x0a\x0a&lt;!-- wp:group {\x22tagName\x22:\x22main\x22,\x22style\x22:{\x22spacing\x22:{\x22padding\x22:{\x22top\x22:\x220\x22,\x22right\x22:\x220\x22,\x22bottom\x22:\x220\x22,\x22left\x22:\x220\x22},\x22blockGap\x22:\x220\x22}}} --&gt;\x0a&lt;main class=\x22wp-block-group\x22 style=\x22padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\x2..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"]

Apache-Error: [file "apache2_util.c"] [line 273] [level 3] ModSecurity: Warning. Matched phrase "&lt;!--" at ARGS:content. [file "/etc/modsecurity/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "250"] [id "941180"] [msg "Node-Validator Blacklist Keywords"] [data "Matched Data: &lt;!-- found within ARGS:content: &lt;!-- wp:template-part {\\\\x22slug\\\\x22:\\\\x22header\\\\x22,\\\\x22theme\\\\x22:\\\\x22&lt;hostname&gt;\\\\x22,\\\\x22tagname\\\\x22:\\\\x22header\\\\x22} /--&gt;\\\\x0a\\\\x0a&lt;!-- wp:group {\\\\x22tagname\\\\x22:\\\\x22main\\\\x22,\\\\x22style\\\\x22:{\\\\x22spacing\\\\x22:{\\\\x22padding\\\\x22:{\\\\x22top\\\\x22:\\\\x220\\\\x22,\\\\x22right\\\\x22:\\\\x220\\\\x22,\\\\x22bottom\\\\x22:\\\\x220\\\\x22,\\\\x22left\\\\x22:\\\\x220\\\\x22},\\\\x22blockgap\\\\x22:\\\\x220\\\\x22}}} --&gt;\\\\x0a&lt;main class=\\\\x22wp-block-group\\\\x22 style=\\\\x22padding-top:0;padding-right:0;padding-bottom:0;padding-left:0\\\\x22&gt;&lt;!..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "sit.&lt;hostname&gt;.com"] [uri "/wp-json/wp/v2/templates/&lt;hostname&gt;/page"] [unique_id "Y7-6B6WOVEBhE0cscXvdvgAAERU"]
Apache-Error: [file "apache2_util.c"] [line 273] [level 3] [client 92.46.0.178] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "&lt;hostname&gt;.com"] [uri "/wp-json/wp/v2/templates/&lt;hostname&gt;/page"] [unique_id "Y7-6B6WOVEBhE0cscXvdvgAAERU"]

解决方案

问题已解决,修改后的有效规则如下:

SecRule REQUEST_URI "@beginsWith /wp-json/wp/v2/template" \
"id:10000002,\
phase:2,\
pass,\
nolog,\
ctl:ruleRemoveTargetById=941100;ARGS:content,\
ctl:ruleRemoveTargetById=941160;ARGS:content,\
ctl:ruleRemoveTargetById=941180;ARGS:content,\
ctl:ruleRemoveTargetById=932105;ARGS:content"

修改说明:

  • 将两条规则合并为一条,使用@beginsWith匹配所有模板相关的API请求
  • 将ARGS=content改为ARGS:content(ModSecurity中变量与子项的正确分隔符为冒号)
  • 移除了无需排除的规则ID(如949110、980130)

内容的提问来源于stack exchange,提问作者nonhocapito

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 22:20:40