Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Response Splitting Attack reported by mod_security

#690

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

I use the apache proxy to forward traffic to mongrel. The apache has

mod_security enabled and since I made an update to Rails 2.1.0

mod_security blocks access with the following message:

[24/Jul/2008:16:13:36 +0200]

[myhost/sid#988eef8][rid#a29a550][/myapp/][1] Access denied with code

400 (phase 2). Pattern match "%0[ad]" at REQUEST_HEADERS:Cookie. [id

"950910"] [msg "HTTP Response Spli

tting Attack. Matched signature <%0a>"] [severity "ALERT"]

I don't know what exactly is causing this. I am using

restful_authentication.

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.7 (GNU/Linux)

Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iD8DBQFIiJUVCNjA0nfhW7wRApu8AKDk9LU37uOpdogLGcnjJM+PG8r+qQCgl48P

VMDMiC0VZpXzAW5OOwyc+LE=

=NIF1

-----END PGP SIGNATURE-----

Reported by Christian Nolte · July 24th, 2008 @ 03:45 PM

State: new
Milestone: 3.x
Assigned to: Michael Koziarski Michael Koziarski
Importance: none

Activity

  1. Daniel Tsadok
    Daniel Tsadok

    I have the exact same issue - it seems to be related to the way Rails handles its cookies, particularly CRLF's: http://en.wikipedia.org/wiki/HTT...

    So could this be a security issue in Rails? The Wikipedia page suggests URL-encoding the cookies...

    (I'm not a security expert - I just want to get my app to work with mod_security. What I wrote above is simply what I've gathered from a bit of research)

    October 6th, 2008 @ 11:56 PM

  2. Ryan Stenhouse
    Ryan Stenhouse

    This issue is still present. For time time being, switching to using the Active Record session store is a viable work around - however something as serious as this does need to be addressed.

    Specific issue:

    Message: Access denied with code 400 (phase 2). Pattern match "%0[ad]" at REQUEST_HEADERS:Cookie. [id "950910"] [msg "HTTP Response Splitting Attack. Matched signature <%0a>"] [severity "ALERT"]

    While the CRs and LFs in the response body are being properly URI-Encoded (%0A), it is still enough to trigger the alert from mod_security. I for one am certainly not going to turn off part of mod_security's protection for my application although I'm sure mod_security could be tweaked to be more lenient for the requests being sent from Apache to Mongrel.

    One solution would be to cease using the Cookie Session Store as the default and reverting back to the old database driven approach, especially since this is a security issue (albeit a minor one).

    October 29th, 2008 @ 01:42 PM

  3. DHH
    DHH
    • Assigned user set to Rick

    October 30th, 2008 @ 10:38 AM

  4. Pratik
    Pratik
    • Assigned user changed from Rick to Michael Koziarski
    • Title changed from Rails 2.1.0: mod_security reports a Response Splitting Attack to Response Splitting Attack reported by mod_security

    Any idea koz ?

    March 13th, 2009 @ 11:00 AM

  5. Ryan Bigg
  6. Jeremy Kemper
    Jeremy Kemper
    • Milestone changed from 2.x to 3.x

    May 4th, 2010 @ 06:48 PM

  7. Ryan Bigg
    Ryan Bigg

    Automatic cleanup of spam.

    November 8th, 2010 @ 01:53 AM

  8. bingbing