You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助编写ModSecurity/CRS误报白名单规则(规则951220/951120)

解决ModSecurity CRS 4.0.0-rc1 SQL信息泄露规则误报问题

针对你的交易平台/sale/相关页面因商品内容触发951220(MSSQL信息泄露)和951120(Oracle信息泄露)规则的误报,以下是精准的自定义排除方案,无需关闭整个/sale/目录的CRS防护能力:

核心思路

通过自定义规则仅在特定商品页面路径下排除误报规则,保留其余/sale/目录及全站的CRS防护逻辑。

自定义排除规则编写

创建自定义规则文件(例如/etc/modsecurity.d/rules/custom-exclusions.conf),根据你的页面结构选择以下方案:

方案1:精准匹配商品详情页路径(推荐)

如果商品详情页URL格式为/sale/item/[数字ID](如/sale/item/123),用正则匹配缩小排除范围:

# 仅针对商品详情页排除指定SQL信息泄露规则
SecRule REQUEST_URI "@rx ^/sale/item/\d+$" \
    "id:1000001,\
    phase:1,\
    pass,\
    nolog,\
    ctl:ruleRemoveById=951220,951120"

方案2:匹配/sale/开头的所有路径(范围更广)

若暂时无法确定精准商品页面路径,可先使用前缀匹配:

# 针对所有/sale/开头的请求排除指定SQL信息泄露规则
SecRule REQUEST_URI "@beginsWith /sale/" \
    "id:1000002,\
    phase:1,\
    pass,\
    nolog,\
    ctl:ruleRemoveById=951220,951120"

规则参数说明

  • id:1000001:自定义规则ID,需避免与CRS内置规则ID(900000+)冲突
  • phase:1:在请求头阶段设置规则排除,确保整个请求周期生效
  • pass:不中断后续规则执行,仅完成排除设置
  • nolog:不记录该规则的日志,避免日志冗余
  • ctl:ruleRemoveById=951220,951120:移除指定的两条CRS误报规则

配置生效步骤

  1. 确保自定义规则文件在CRS规则之后加载,修改Nginx配置:
modsecurity on;
modsecurity_rules_file /etc/modsecurity.d/crs/crs-setup.conf;
modsecurity_rules_file /etc/modsecurity.d/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf;
modsecurity_rules_file /etc/modsecurity.d/crs/rules/*.conf;
# 自定义规则放在CRS规则之后
modsecurity_rules_file /etc/modsecurity.d/rules/custom-exclusions.conf;
  1. 重启Nginx服务:
systemctl restart nginx

验证

访问触发误报的商品页面,确认不再返回403;同时查看ModSecurity日志(默认路径/var/log/modsec_audit.log),确认951220和951120规则未被触发。

内容的提问来源于stack exchange,提问作者peppy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 03:05:33