store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 11:15 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: Bug in antispam rules
Unread postPosted: Wed Jun 23, 2010 9:43 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Please make sure you are running the latest WAF rules, there is a bug in the antispam rules that will generate False Positives. To update your rules, just run this command as root:

asl -u

The specific false positive is rule #300186, so if for some reason you can not update your rules than disable this rule. We recommend you update your rules.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Bug in antispam rules
Unread postPosted: Wed Jun 23, 2010 11:08 am 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Thanks Mike - reported as FP earlier, but to keep clients working I disabled the rule, is there a command/location to view which rules have been disabled? I noticed there are several asl commands now (-er/dr - Re-enable/Disable modsec rule by signature ID), but not one to view all disabled rules...


Top
 Profile  
 
 Post subject: Re: Bug in antispam rules
Unread postPosted: Wed Jun 23, 2010 12:33 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Great question, for now you'll have to look at these files:

Code:
/etc/asl/disabled_signatures


Those are any globally disabled rules.

Quote:
/etc/asl/vhost_disabled_signatures


Those are any disabled rules for specific vhosts.

In the future this will all be visible in the GUI and we're planning big changes in the way the rules are managed and displayed too, including classes (which have overlapping rules, so you could disable all PHP rules, or just PHP-SQL rules, etc.) We're going to roll classes out where it makes the most sense for things like the spam rules, so you can say "disabled all gambling rules for this vhost". In the longer term we'd like to expose spam rules to domain owners, but thats a big lift and change in the auth model so theres no timeline yet on that feature. Its something we have to think very carefully about as we dont want a domain owner to be able to disable rules that protect the server, and then open your box up to full compromise.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Bug in antispam rules
Unread postPosted: Wed Jun 23, 2010 2:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Thanks Mike, that's really useful to know. When an ID is manually removed from /etc/asl/(vhost_)disabled_signatures does anything need to be run (e.g. asl -u)?
Have removed 300186 but another ID is still there (yeah, I remember doing this once before), have no idea what it relates to... Would be useful to add comments when disabling rules or even to have a way of looking up a rule by ID (just blue-sky-thinking, not feature-requesting).


Top
 Profile  
 
 Post subject: Re: Bug in antispam rules
Unread postPosted: Wed Jun 23, 2010 2:36 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
You don't want to edit files like /etc/asl/disabled_signatures manually. Instead run the command to enable the rule again (asl -er <number>).

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Bug in antispam rules
Unread postPosted: Wed Jun 23, 2010 2:43 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Ah yeah! makes complete sense.
Add reference back to file, ran asl -er 300186, it worked fine with some expected output.
Thanks breun


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group