ºìÁªLinuxÃÅ»§
Linux°ïÖú

fedaro 8 ²»ÄÜʹÓÃIPµØÖ··ÃÎʺͲ»ÄÜÌá½»ÎÊÌâµÄ½â¾ö

·¢²¼Ê±¼ä:2008-06-18 10:40:14À´Ô´:ºìÁª×÷Õß:Osllgre
×÷ÕߣººÚÉ«ÒøÔÂ
Ê×ÏÈÒª¸ÐлһÏ ³É¶¼-feeling£¬Ã»ÓÐËûµÄÈÈÐİïÖú£¬Õâ¸öÎÊÌâÎÒÏëÎÒÊÇ»ù±¾½â¾ö²»ÁËÁË¡£ÔÙ´ÎÖÔÐĵĸÐл¡£

ÕâÁ½Ì칫˾µÄ·þÎñÆ÷×°ÁËfedora8 £¬µ«ÊÇ֮ǰµÄϵͳÔÚlinuxÏÂÈ´²»ÄÜÕý³£µÄÖ´ÐУ¬Ê×ÏÈ£¬·þÎñÆ÷Ö»ÄÜÓÃÓòÃû·ÃÎÊ£¬²»ÄÜÓÃIP·ÃÎÊ£¬È»ºó£¬ËùÓÐ±íµ¥POSTµÄÌá½»£¨submit£©¶¼²»ÄÜÖ´ÐУ¬ÔÚÓ¢ÎÄ»·¾³ÏÂÓÐЩ¿ÉÒÔ£¬µ«ÊÇÔÚÖÐÎÄ»·¾³Ï¶¼²»¿ÉÒÔ£¬²»¹ÜÊǼòÖл¹ÊÇ·±ÖУ¬¶ÔÓÚÕâ¸öÎÊÌ⣬ÓôÃÆÁËÒ»´óÉÏÎ磬¿ÉÊÇ»¹ÊÇûÓнâ¾ö¡£

ÖÕÓÚÔÚ ³É¶¼-feeling µÄ°ïÖúÏ£¬¸ã¶¨ÁËÕâ¸öÎÊÌâ¡£

ÏÐÑÔÉÙÐ𣬽øÈëÕûÌ壬ÏÂÃæÊǽâ¾ö·½·¨£º

IP²»ÄÜ·ÃÎʽâ¾ö£º
modsecurity_crs_21_protocol_anomalies.conf µÚ55ÐÐÊ×¼ÓÉÏÒ»¸ö#

55ÐÐÄÚÈÝ£ºSecRule REQUEST_HEADERS:Host "^[\d\.]+$" "deny,log,auditlog,status:400,msg:'Host header is a numeric IP address', severity:'2',,id:'960017',"

POST´íÎó£º
ÒòΪûÓдíÎóÐÅÏ¢£¬ÎÒ²»ÖªµÀÊDz»ÊÇÕâ¸ö£º
modsecurity_crs_20_protocol_violations.conf µÚ52Ðк͵Ú53ÐÐÐÐÊ×¼ÓÉÏ#

52ÐÐÄÚÈÝ£ºSecRule REQUEST_METHOD "^POST$" "chain,deny,log,auditlog,status:400,msg:'POST request must have a Content-Length header',,id:'960012',severity:'4'"
53ÐÐÄÚÈÝ£ºSecRule &REQUEST_HEADERS:Content-Length "@eq 0"

Èç¹û»¹ÊDz»ÐУ¬¸É´àÖ±½Ó±à¼­
modsecurity_crs_10_config.confµÄµÚ53ÐУ¬½« On ¸ÄΪ Off

53ÐÐÄÚÈÝ£ºSecRuleEngine On

È»ºóÖØÆôapache£ºservice httpd restart
¿´À´linux»¹ÓкÜÔ¶µÄ·Ҫ×ߣ¬LAMP£¬long£¬long
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 1 ÌõÆÀÂÛ

  1. leaf1988 ÓÚ 2008-06-18 22:18:36·¢±í:

    »¹ÓÐÈËÓÃfedora8×öserver£¬Ôõô²»ÓÃCENTOSÄØ¡£×îÆðÂëËÙ¶ÈÒªºÃЩ£¬Íâ¼Ó¸üÎȶ¨Ð©¡£