This project is archived and is in readonly mode.
Response Splitting Attack reported by mod_security
-
Daniel Tsadok
I have the exact same issue - it seems to be related to the way Rails handles its cookies, particularly CRLF's: http://en.wikipedia.org/wiki/HTT...
So could this be a security issue in Rails? The Wikipedia page suggests URL-encoding the cookies...
(I'm not a security expert - I just want to get my app to work with mod_security. What I wrote above is simply what I've gathered from a bit of research)
-
Ryan Stenhouse
This issue is still present. For time time being, switching to using the Active Record session store is a viable work around - however something as serious as this does need to be addressed.
Specific issue:
Message: Access denied with code 400 (phase 2). Pattern match "%0[ad]" at REQUEST_HEADERS:Cookie. [id "950910"] [msg "HTTP Response Splitting Attack. Matched signature <%0a>"] [severity "ALERT"]
While the CRs and LFs in the response body are being properly URI-Encoded (%0A), it is still enough to trigger the alert from mod_security. I for one am certainly not going to turn off part of mod_security's protection for my application although I'm sure mod_security could be tweaked to be more lenient for the requests being sent from Apache to Mongrel.
One solution would be to cease using the Cookie Session Store as the default and reverting back to the old database driven approach, especially since this is a security issue (albeit a minor one).
-
DHH
- Assigned user set to Rick
-
Pratik
- Assigned user changed from Rick to Michael Koziarski
- Title changed from Rails 2.1.0: mod_security reports a Response Splitting Attack to Response Splitting Attack reported by mod_security
Any idea koz ?
-
Ryan Bigg
Koz, any idea?
-
Ryan Bigg
Automatic cleanup of spam.