You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Magento2站点遭Netsparker扫描及滥用,ACL URL封禁规则优化求助

Fixing False Positives with Haproxy ACLs for SQLi Protection in Magento 2

It looks like your current Haproxy ACLs are too broad and are catching legitimate Magento 2 requests, which is why you're seeing frontend errors. Let's break down the issues and fix this with more targeted, efficient rules:

Why Your Current Config Causes Errors

Your url_reg rules match the entire URL string (path + query parameters), which means they'll flag normal requests that happen to contain SQL keywords in their path, product names, or valid filter parameters. For example, a Magento category filter for "selectable" products might trigger the SELECT rule, or a page with content mentioning "procedure" could get blocked.

Optimized Solution

Here's a refined approach that minimizes false positives while still blocking malicious SQLi attempts:

  1. Target only query parameter values
    Use urlp_reg instead of url_reg—this restricts your regex checks to the values of URL query parameters (where SQLi attacks almost always occur), not the entire URL path.

  2. Use word boundaries to match full keywords
    Add \b around your SQL keywords to ensure you're matching complete words, not partial strings (e.g., \bSELECT\b won't match "SELECTION" in a product name).

  3. Combine rules for efficiency
    Merge all your SQLi keywords into a single ACL to reduce rule processing overhead.

Updated Haproxy Config

frontend https bind *:443 ssl crt... 

# SQL Injection Prevention: Target query params, match full malicious keywords
acl sqli_malicious urlp_reg -i \b(WAITFOR|WHERE|DELAY|DECLARE|SLEEP|NSFTW|DUAL|SELECT|convert|exec|bexec|procedure|dblink|r87\.com|xp_dirtree|pg_sleep|dbms_pipe|CTXSYS\.DRITHSX\.SN|GET_HOST_ADDRESS)\b

# Tarpit malicious requests (adjust to "deny" if you prefer immediate rejection)
http-request tarpit if sqli_malicious

Additional Best Practices

  • Test first with dry runs: Use haproxy -c -f /etc/haproxy/haproxy.cfg to validate your config syntax, then test legitimate requests (like category pages, search, product filters) with curl to ensure they aren't blocked.
  • Log blocked requests: Enable detailed Haproxy logging to review what's being intercepted. Add a log format like this to your frontend:
    log-format "%ci:%cp [%t] %ft %b/%s %TR/%Tw/%Tc/%Tr/%Ta %ST %B %CC %CS %tsc %ac/%fc/%bc/%sc/%rc %sq/%bq %hr %hs %{+Q}r"
    
    Check your logs to identify any false positives and adjust your regex accordingly (e.g., remove keywords that appear in legitimate traffic).
  • Layer with your existing rate limiting: Keep your sticky-table rate limiting as the first line of defense—this will throttle most automated scanners before they even hit your SQLi ACLs, reducing load on your server and minimizing the chance of false positives.
  • Target specific malicious domains: For known bad domains like r87.com, you can add a separate ACL to block any parameter containing that domain explicitly:
    acl malicious_domain urlp_reg -i r87\.com
    http-request tarpit if malicious_domain
    

This approach balances security and functionality, ensuring you block Netsparker-style SQLi scans without breaking your Magento 2 frontend.

内容的提问来源于stack exchange,提问作者Johnny Klaus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:33:58