You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Nginx Ingress中自定义规则允许含指定queryString的流量?

在Ingress Nginx的ModSecurity中配置允许含'qwerty'的Query String流量

实现思路

通过添加自定义ModSecurity规则,匹配包含目标值的查询字符串/参数值,直接允许该请求或跳过后续安全检查。

具体配置方案

根据你的需求选择以下两种规则之一,添加到现有配置的末尾(ModSecurity规则顺序影响执行逻辑,自定义规则需放在移除规则之后):

方案1:允许任意Query参数值包含'qwerty'的请求

适用于只要某个参数的值里有'qwerty'就放行的场景(比如?foo=qwerty或?bar=abcqwerty123):

Include /etc/nginx/owasp-modsecurity-crs/nginx-modsecurity.conf
SecRuleEngine On
SecRuleRemoveById 920210 920230 920420 920440 920350 930120 930100 930110 941331 941130 941150 941160 941340 942370 942360 942330 942340 942260 942200 942120 942110 942430 942190 942380 942440 932100 931130

# 自定义规则:放行参数值含'qwerty'的请求
SecRule ARGS "@contains qwerty" "id:1000001,phase:2,allow,nolog,msg:'Allow requests with qwerty in query parameter values'"

方案2:允许整个Query String包含'qwerty'的请求

适用于只要查询字符串中存在'qwerty'这个子串就放行的场景(比如?id=123&token=qwerty或?search=qwertyuiop):

Include /etc/nginx/owasp-modsecurity-crs/nginx-modsecurity.conf
SecRuleEngine On
SecRuleRemoveById 920210 920230 920420 920440 920350 930120 930100 930110 941331 941130 941150 941160 941340 942370 942360 942330 942340 942260 942200 942120 942110 942430 942190 942380 942440 932100 931130

# 自定义规则:放行查询字符串含'qwerty'的请求
SecRule QUERY_STRING "@contains qwerty" "id:1000001,phase:1,allow,nolog,msg:'Allow requests with qwerty in query string'"

规则参数说明

  • id:1000001:自定义规则ID,确保唯一(OWASP CRS规则以9开头,建议自定义ID从1000000开始)
  • phase:1/2:执行阶段,phase:1在请求头解析后执行,phase:2在请求体/参数解析后执行
  • allow:直接允许该请求,跳过后续所有ModSecurity规则检查
  • nolog:不记录该放行请求到ModSecurity日志(可根据调试需求移除)
  • msg:日志描述,方便排查规则执行情况

可选调整

  • 如果需要精确匹配参数值等于'qwerty',将@contains替换为@eq
  • 如果不需要跳过所有规则,仅需绕过特定误判规则,可将allow替换为ctl:ruleRemoveById=XXX(XXX为目标规则ID)

内容的提问来源于stack exchange,提问作者priya natarajan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 14:01:35