store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 18, 2013 5:38 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 1 post ] 
Author Message
 Post subject: Modsecurity multipart bypass vulnerability
Unread postPosted: Fri Jun 15, 2012 11:28 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
Thjere is a vulnerability in modsecurity that can be used to bypass certain rules under certain conditions. You can read more about it here:

https://community.qualys.com/blogs/secu ... t-bypasses

We (unlike the core rules) already had rules for all of these cases, so if you are using the real time rules or ASL you should be fine. You are encouraged to upgrade to 2.6.6 as it contains a better multi-part processing engine that mitigates this entire class of attacks. Defense in Depth is always a good thing, and some of the rules to prevent these attacks from working may interfere with strange applications (although so far we havent seen any reports to that effect and some of these rules are pretty old).

To upgrade just run this command as root:

yum -y upgrade mod_security

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 1 post ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group