You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何针对特定文件的请求内容拦截?我的ModSecurity规则为何无效?

问题:ModSecurity规则多次配置均未生效,求排查错误

我已多次尝试配置规则,以下是我的三次尝试,但均未生效,请问我哪里出错了?

第一次尝试

SecRule REQUEST_FILENAME "@endsWith /wp-admin/admin-ajax.php" \
        "id:1001, \
        deny, \
        t:none, \
        tag: 'Admin ajax post Silderz', chain"
        SecRule REQUEST_BODY "@rx Silderz"

第二次尝试

SecRule REQUEST_FILENAME "^/wp-admin/admin-ajax\.php$" \
        "id:1001, \
        deny, \
        t:none, \
        tag: 'Admin ajax post Silderz', chain"
        SecRule REQUEST_BODY "action=Silderz\&nonce=\w{1,}"

第三次尝试

SecRule REQUEST_FILENAME "^/wp-admin/admin-ajax\.php$" \
        "id:1001, \
        deny, \
        t:none, \
        tag: 'Admin ajax post Silderz', chain"
        SecRule REQUEST_BODY "^action=Silderz\&nonce=\w{1,}$"

实际请求的FormData

action: 
Silderz
nonce: 
4e2cad2579

请求头信息

:authority: www.bursterksed.com
:method: POST
:path: /wp-admin/admin-ajax.php
:scheme: https
accept: application/json, text/javascript, */*; q=0.01
accept-encoding: gzip, deflate, br
accept-language: tr-TR,tr;q=0.9,en-US;q=0.8,en;q=0.7,az;q=0.6,de;q=0.5,fr;q=0.4,ru;q=0.3,pt;q=0.2,hu;q=0.1
content-length: 34
content-type: application/x-www-form-urlencoded; charset=UTF-8
.......
.......
.......

错误原因分析

  1. 第一次尝试:
    直接匹配REQUEST_BODY中的"Silderz"本身逻辑没问题,但对于application/x-www-form-urlencoded类型的请求,ModSecurity会自动解析请求体到ARGS集合,直接匹配原始请求体易受编码、格式干扰,可靠性低。

  2. 第二次、第三次尝试:
    正则中的\&属于冗余转义,ModSecurity正则里&无需转义,转义后会匹配字面量\&,但实际请求体中是普通&,导致匹配失败;第三次的^和$锚定整个请求体,若请求体存在额外空格(如FormData换行提交后实际编码为无换行的URL格式),也会导致匹配失效。


正确规则配置

推荐使用ARGS集合匹配表单参数,避免请求体格式干扰:

SecRule REQUEST_FILENAME "@endsWith /wp-admin/admin-ajax.php" \
        "id:1001, \
        deny, \
        t:none, \
        tag:'Admin ajax post Silderz', \
        chain"
    SecRule ARGS:action "@rx ^Silderz$" \
        "chain"
    SecRule ARGS:nonce "@rx ^\w+$"

若坚持匹配REQUEST_BODY,修正正则转义问题:

SecRule REQUEST_FILENAME "^/wp-admin/admin-ajax\.php$" \
        "id:1001, \
        deny, \
        t:none, \
        tag:'Admin ajax post Silderz', \
        chain"
    SecRule REQUEST_BODY "@rx action=Silderz&nonce=\w+"

额外排查点

  • 确认ModSecurity已启用,规则文件被正确加载;
  • 查看ModSecurity审计日志(如/var/log/modsec_audit.log),检查规则是否触发或被其他规则拦截;
  • 若REQUEST_FILENAME返回完整路径而非相对路径,替换为REQUEST_URI匹配:SecRule REQUEST_URI "@endsWith /wp-admin/admin-ajax.php"

内容的提问来源于stack exchange,提问作者Pasalar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 12:35:24