From 2ab9da8e3697b50c4f774e6947f954ce3be02ffa Mon Sep 17 00:00:00 2001 From: Debian Date: Wed, 3 Jun 2026 13:25:46 +0200 Subject: [PATCH] =?UTF-8?q?fix(waf):=20CRS=20v4=20Regeln=20extrahiert=20+?= =?UTF-8?q?=20Control-Flow-Regeln=20filtern=20=E2=80=94=20v1.2.82?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - crsRules.ts neu: 331 echte CRS v4.7.0 Regeln aus installierten Dateien (v3-Nummernschema war falsch, v4 hat andere IDs — 949152 war skip-Regel) - spoe.go: Regeln ohne Message nicht als Alert speichern Co-Authored-By: Claude Sonnet 4.6 --- VERSION | 2 +- internal/waf/spoe.go | 7 + management-ui/src/pages/WAF/crsRules.ts | 681 ++++++++++++------------ 3 files changed, 344 insertions(+), 346 deletions(-) diff --git a/VERSION b/VERSION index 3a67429..aea1186 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -1.2.81 +1.2.82 diff --git a/internal/waf/spoe.go b/internal/waf/spoe.go index 5ddbb75..0f696c3 100644 --- a/internal/waf/spoe.go +++ b/internal/waf/spoe.go @@ -132,10 +132,17 @@ func (a *SPOEAgent) handle(ctx context.Context, w *encoding.ActionWriter, m *enc } // sendAlert enqueues a WAF alert for async DB write. +// Control-flow rules (pass+nolog with empty message) are skipped — +// they are CRS paranoia-level skip-markers, not real detections. func (a *SPOEAgent) sendAlert(host, clientIP, method, uri string, mr types.MatchedRule, blocked bool) { if a.AlertWriter == nil { return } + // Skip rules with no message — these are CRS skip/control-flow rules + // (e.g. 949011..949018, 911011..911018) that match but carry no alert info. + if mr.Message() == "" && mr.Rule().ID() > 0 { + return + } action := "detected" if blocked && mr.Disruptive() { action = "blocked" diff --git a/management-ui/src/pages/WAF/crsRules.ts b/management-ui/src/pages/WAF/crsRules.ts index 1192198..9e78791 100644 --- a/management-ui/src/pages/WAF/crsRules.ts +++ b/management-ui/src/pages/WAF/crsRules.ts @@ -1,351 +1,342 @@ /** - * OWASP Core Rule Set (CRS) v4.x — rule descriptions. - * Source: https://coreruleset.org / CRS GitHub - * Static map: rule_id → short description (EN). - * New rules added per CRS release; update this file when upgrading CRS. + * OWASP CRS v4.7.0 — rule descriptions (auto-generated from installed CRS). + * Update by running the extraction script when upgrading CRS. */ export const CRS_RULES: Record = { - // ── 900xxx Setup ─────────────────────────────────────────────────────── - 900000: 'CRS: Set paranoia level', - 900001: 'CRS: Set anomaly thresholds', - 900110: 'CRS: Anomaly scoring threshold configuration', - 900200: 'CRS: Allowed HTTP versions', - 900220: 'CRS: Allowed request content types', - - // ── 901xxx Initialization ────────────────────────────────────────────── - 901001: 'CRS: Version check — unsupported CRS version', - 901100: 'CRS: Anomaly scoring initialization', - - // ── 903xxx / 905xxx Protocol enforcement ────────────────────────────── - 903100: 'Protocol enforcement: missing Host header', - 905100: 'Protocol enforcement: HTTP/0.9 request', - - // ── 910xxx IP reputation ─────────────────────────────────────────────── - 910100: 'IP reputation: client IP in GeoIP blocklist', - 910110: 'IP reputation: client IP in DNSBL blocklist', - 910120: 'IP reputation: Sqli/XSS IP reputation', - 910130: 'IP reputation: Spamhaus DROP list', - 910150: 'IP reputation: project Honeypot', - 910160: 'IP reputation: project Honeypot — comment spammer', - 910170: 'IP reputation: project Honeypot — suspicious IP', - 910180: 'IP reputation: known scanners/hacking tool IP', - - // ── 911xxx Method enforcement ────────────────────────────────────────── - 911100: 'Method not allowed for this resource', - - // ── 912xxx DoS / rate limiting ───────────────────────────────────────── - 912120: 'DoS: too many requests from single IP', - - // ── 913xxx Scanner detection ─────────────────────────────────────────── - 913100: 'Scanner: security scanner User-Agent detected', - 913101: 'Scanner: scripting/generic HTTP client User-Agent', - 913102: 'Scanner: web crawler/bot User-Agent', - 913110: 'Scanner: request header associated with security scanner', - 913120: 'Scanner: request filename/argument associated with scanner', - - // ── 920xxx Protocol enforcement (request) ───────────────────────────── - 920100: 'Protocol: invalid HTTP request line', - 920120: 'Protocol: attempted multipart/form-data bypass', - 920121: 'Protocol: attempted multipart/form-data bypass (2)', - 920130: 'Protocol: failed to parse request body', - 920140: 'Protocol: multipart request body failed strict validation', - 920160: 'Protocol: Content-Length HTTP header is not numeric', - 920170: 'Protocol: GET/HEAD request with body content', - 920171: 'Protocol: GET/HEAD request with Transfer-Encoding', - 920180: 'Protocol: POST request missing Content-Length or Transfer-Encoding', - 920181: 'Protocol: Content-Length and Transfer-Encoding headers present', - 920190: 'Protocol: range header contains an invalid last byte value', - 920200: 'Protocol: range header contains too many fields', - 920201: 'Protocol: range header contains too many fields for PDF request', - 920210: 'Protocol: multiple/conflicting connection header data', - 920220: 'Protocol: URL encoding abuse attack attempt', - 920230: 'Protocol: multiple URL encoding detected', - 920240: 'Protocol: URL encoding abuse in request headers', - 920250: 'Protocol: UTF8 encoding abuse attack attempt', - 920260: 'Protocol: Unicode full/half width abuse attack attempt', - 920270: 'Protocol: invalid character in request (null character)', - 920271: 'Protocol: invalid character in request (non-printable)', - 920272: 'Protocol: invalid character in request (outside printable ASCII)', - 920273: 'Protocol: invalid character in request (outside very strict range)', - 920274: 'Protocol: invalid character in request headers (outside very strict range)', - 920280: 'Protocol: request missing Host header', - 920290: 'Protocol: empty Host header', - 920300: 'Protocol: request missing Accept header', - 920310: 'Protocol: request has empty Accept header', - 920311: 'Protocol: request has empty Accept header (2)', - 920320: 'Protocol: request missing User-Agent header', - 920330: 'Protocol: empty User-Agent header', - 920340: 'Protocol: request with content but no Content-Type header', - 920341: 'Protocol: request with content requires Content-Type header', - 920350: 'Protocol: Host header is a numeric IP address', - 920360: 'Protocol: argument name too long', - 920370: 'Protocol: argument value too long', - 920380: 'Protocol: too many arguments in request', - 920390: 'Protocol: total arguments size exceeded', - 920400: 'Protocol: uploaded file too large', - 920410: 'Protocol: total uploaded files size too large', - 920420: 'Protocol: request content type is not allowed', - 920430: 'Protocol: HTTP protocol version not allowed', - 920440: 'Protocol: URL file extension restricted by policy', - 920450: 'Protocol: HTTP header is restricted by policy', - 920460: 'Protocol: abnormal escape character in request', - 920470: 'Protocol: illegal Content-Type header', - 920480: 'Protocol: request Content-Type charset restricted', - 920500: 'Protocol: attempt to access a backup or working file', - 920510: 'Protocol: file extension blocked for security reasons', - 920520: 'Protocol: missing or invalid "nonce" value in request', - - // ── 921xxx HTTP request smuggling ───────────────────────────────────── - 921100: 'Request smuggling: HTTP request smuggling attack', - 921110: 'Request smuggling: HTTP request smuggling in request headers', - 921120: 'Request smuggling: HTTP response splitting attack', - 921130: 'Request smuggling: HTTP response splitting attack (2)', - 921140: 'Request smuggling: HTTP header injection via headers', - 921150: 'Request smuggling: HTTP header injection via parameters (CR/LF)', - 921151: 'Request smuggling: HTTP header injection via parameters (CR/LF, 2)', - 921160: 'Request smuggling: HTTP splitting (CR/LF and header-name found)', - 921170: 'Request smuggling: HTTP parameter pollution', - 921180: 'Request smuggling: HTTP parameter pollution (matched var found)', - - // ── 922xxx File upload ───────────────────────────────────────────────── - 922100: 'File upload: multipart bypass in Content-Disposition', - 922110: 'File upload: multipart bypass in Content-Type', - 922120: 'File upload: filename contains null character', - 922130: 'File upload: filename contains newline', - - // ── 930xxx LFI — local file inclusion ───────────────────────────────── - 930100: 'LFI: path traversal attack (/../)', - 930110: 'LFI: path traversal attack (/../) with special chars', - 930120: 'LFI: OS file access attempt', - 930130: 'LFI: restricted file access attempt', - - // ── 931xxx RFI — remote file inclusion ─────────────────────────────── - 931100: 'RFI: possible remote file inclusion (URL parameter)', - 931110: 'RFI: common RFI vulnerable parameter name + off-domain URL', - 931120: 'RFI: possible remote file inclusion (trailing question mark)', - 931130: 'RFI: possible remote file inclusion (off-domain reference)', - - // ── 932xxx RCE — remote code execution ─────────────────────────────── - 932100: 'RCE: Unix command injection', - 932105: 'RCE: Unix command injection (2)', - 932106: 'RCE: Unix command injection (3)', - 932110: 'RCE: Windows command injection', - 932115: 'RCE: Windows command injection (2)', - 932120: 'RCE: Windows PowerShell command', - 932130: 'RCE: Unix shell expression found', - 932140: 'RCE: Windows FOR/IF command', - 932150: 'RCE: Direct Unix command execution', - 932160: 'RCE: Unix shell code found', - 932170: 'RCE: Shellshock (CVE-2014-6271)', - 932171: 'RCE: Shellshock (CVE-2014-6271, 2)', - 932180: 'RCE: restricted file upload attempted', - 932190: 'RCE: generic code injection attempt', - 932200: 'RCE: Unix shell bypass technique', - 932205: 'RCE: Unix shell bypass technique (2)', - 932206: 'RCE: Unix shell bypass technique (3)', - 932210: 'RCE: Unix shell bypass via env variable', - 932220: 'RCE: Unix shell injection via backtick', - 932230: 'RCE: Unix shell bypass with extended glob', - 932235: 'RCE: Unix shell bypass (5)', - 932236: 'RCE: Unix shell bypass (6)', - 932237: 'RCE: Unix shell bypass (7)', - 932239: 'RCE: Unix shell bypass (8)', - 932240: 'RCE: Unix shell expression (2)', - 932250: 'RCE: Unix file read via redirection', - 932260: 'RCE: Unix command injection (9)', - - // ── 933xxx PHP injection ─────────────────────────────────────────────── - 933100: 'PHP injection: PHP opening tag found', - 933110: 'PHP injection: PHP script file upload', - 933111: 'PHP injection: PHP script file upload (2)', - 933120: 'PHP injection: PHP configuration directive', - 933130: 'PHP injection: PHP variables found', - 933131: 'PHP injection: PHP variables found (2)', - 933140: 'PHP injection: PHP I/O stream found', - 933150: 'PHP injection: high-risk PHP function name found', - 933151: 'PHP injection: medium-risk PHP function name found', - 933160: 'PHP injection: high-risk PHP function call found', - 933161: 'PHP injection: low-risk PHP function call found', - 933170: 'PHP injection: PHP object injection', - 933180: 'PHP injection: variable function call found', - 933190: 'PHP injection: PHP closing tag found', - 933200: 'PHP injection: wrapper scheme detected', - 933210: 'PHP injection: variable function call found (2)', - - // ── 934xxx Node.js injection ─────────────────────────────────────────── - 934100: 'Node.js injection: server-side request forgery attempt', - - // ── 941xxx XSS — cross-site scripting ───────────────────────────────── - 941100: 'XSS: XSS attack detected via libinjection', - 941101: 'XSS: XSS attack detected via libinjection (2)', - 941110: 'XSS: XSS filter — category 1 (script tag)', - 941120: 'XSS: XSS filter — category 2 (event handler)', - 941130: 'XSS: XSS filter — category 3 (attribute name)', - 941140: 'XSS: XSS filter — category 4 (javascript: URI)', - 941150: 'XSS: XSS filter — category 5 (disallowed HTML)', - 941160: 'XSS: NoScript XSS InjectionChecker — HTML injection', - 941170: 'XSS: NoScript XSS InjectionChecker — attribute injection', - 941180: 'XSS: Node-validator blocklist keywords', - 941190: 'XSS: IE XSS filters — attack detected (1)', - 941200: 'XSS: IE XSS filters — attack detected (2)', - 941210: 'XSS: IE XSS filters — attack detected (3)', - 941220: 'XSS: IE XSS filters — attack detected (4)', - 941230: 'XSS: IE XSS filters — attack detected (5)', - 941240: 'XSS: IE XSS filters — attack detected (6)', - 941250: 'XSS: IE XSS filters — attack detected (7)', - 941260: 'XSS: IE XSS filters — attack detected (8)', - 941270: 'XSS: IE XSS filters — attack detected (9)', - 941280: 'XSS: IE XSS filters — attack detected (10)', - 941290: 'XSS: IE XSS filters — attack detected (11)', - 941300: 'XSS: IE XSS filters — attack detected (12)', - 941310: 'XSS: US-ASCII malformed encoding XSS filter', - 941320: 'XSS: possible XSS attack — HTML tag handler', - 941330: 'XSS: IE XSS filters — attack detected (13)', - 941340: 'XSS: IE XSS filters — attack detected (14)', - 941350: 'XSS: UTF-7 encoding XSS — attack detected', - 941360: 'XSS: JSFuck/Hieroglyphy obfuscated JavaScript', - 941370: 'XSS: JavaScript global variable found', - 941380: 'XSS: AngularJS client-side template injection', - 941390: 'XSS: XSS filter — category 10 (JS global variable)', - - // ── 942xxx SQLi — SQL injection ──────────────────────────────────────── - 942100: 'SQLi: SQL injection attack detected via libinjection', - 942101: 'SQLi: SQL injection attack detected via libinjection (2)', - 942110: 'SQLi: SQL injection attack: common injection testing detected', - 942120: 'SQLi: SQL injection attack: SQL operator detected', - 942130: 'SQLi: SQL injection attack: SQL tautology detected', - 942140: 'SQLi: SQL injection attack: common DB names detected', - 942150: 'SQLi: SQL injection attack', - 942151: 'SQLi: SQL injection attack (2)', - 942152: 'SQLi: SQL injection attack (3)', - 942160: 'SQLi: blind SQL injection test using sleep()/benchmark()', - 942170: 'SQLi: SQL benchmark and sleep injection attempts', - 942180: 'SQLi: basic SQL authentication bypass (1)', - 942190: 'SQLi: SQL code execution and information gathering', - 942200: 'SQLi: MySQL comment/space-obfuscated injections and backtick', - 942210: 'SQLi: chained SQL injection (1)', - 942220: 'SQLi: integer overflow attack', - 942230: 'SQLi: conditional SQL injection attempts', - 942240: 'SQLi: MySQL charset switch and MSSQL DoS', - 942250: 'SQLi: MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections', - 942251: 'SQLi: HAVING injection', - 942260: 'SQLi: basic SQL authentication bypass (2)', - 942270: 'SQLi: basic SQL injection — MySQL/Oracle/MSSQL', - 942280: 'SQLi: Postgres pg_sleep injection, waitfor delay', - 942290: 'SQLi: MongoDB SQL injection attempt', - 942300: 'SQLi: MySQL comments, conditions and ch(a)r injections', - 942310: 'SQLi: chained SQL injection (2)', - 942320: 'SQLi: MySQL and PostgreSQL stored procedure injections', - 942330: 'SQLi: classic SQL injection probings detected (1)', - 942340: 'SQLi: basic SQL authentication bypass (3)', - 942350: 'SQLi: MySQL UDF injection and other data/structure manipulation', - 942360: 'SQLi: concatenated basic SQL injection and SQLLFI attacks', - 942361: 'SQLi: basic SQL injection based on keyword ALTER or UNION', - 942370: 'SQLi: classic SQL injection probings detected (2)', - 942380: 'SQLi: SQL injection attack', - 942390: 'SQLi: SQL injection attack (2)', - 942400: 'SQLi: SQL injection attack (3)', - 942410: 'SQLi: SQL injection attack (4)', - 942420: 'SQLi: restricted SQL character anomaly detection (cookies)', - 942421: 'SQLi: restricted SQL character anomaly detection (cookies, 2)', - 942430: 'SQLi: restricted SQL character anomaly detection (args)', - 942431: 'SQLi: restricted SQL character anomaly detection (args, 2)', - 942432: 'SQLi: restricted SQL character anomaly detection (args, 3)', - 942440: 'SQLi: SQL comment sequence detected', - 942450: 'SQLi: SQL hex encoding identified', - 942460: 'SQLi: meta-character anomaly detection alert', - 942470: 'SQLi: SQL injection attack (5)', - 942480: 'SQLi: SQL injection attack (6)', - 942490: 'SQLi: classic SQL injection probings detected (3)', - 942500: 'SQLi: MySQL inline comment detected', - 942510: 'SQLi: SQLi bypass attempt via ticks', - 942511: 'SQLi: SQLi bypass attempt using ticks (2)', - 942520: 'SQLi: SQL injection attack (7)', - 942521: 'SQLi: SQL injection attack (8)', - 942530: 'SQLi: SQL injection attack (9)', - 942540: 'SQLi: SQL injection attack (10)', - 942550: 'SQLi: MySQL injection detected', - - // ── 943xxx Session fixation ──────────────────────────────────────────── - 943100: 'Session fixation: possible session fixation attack (cookie values)', - 943110: 'Session fixation: possible session fixation attack (referrer off-domain)', - 943120: 'Session fixation: possible session fixation attack (no referrer)', - - // ── 944xxx Java attacks ──────────────────────────────────────────────── - 944100: 'Java: remote command execution via Apache Struts, Oracle WebLogic', - 944110: 'Java: remote command execution via Java keywords', - 944120: 'Java: remote command execution — Java deserialization', - 944130: 'Java: suspicious Java class detected', - 944200: 'Java: magic bytes indicative of Java serialization', - 944210: 'Java: Java serialization deserialization gadget (1)', - 944240: 'Java: remote code execution — Java serialization', - 944250: 'Java: restricted Java method detected', - - // ── 949xxx Anomaly scoring ───────────────────────────────────────────── - 949110: 'Anomaly score exceeded: inbound anomaly score (blocking)', - 949111: 'Anomaly score exceeded: inbound anomaly score (PL2)', - - // ── 950xxx–959xxx Data leakage (response) ───────────────────────────── - 950100: 'Data leakage: server-side include attack', - 950130: 'Data leakage: server-side include attack (2)', - 951100: 'Data leakage: SQL error leakage — MySQL error string', - 951110: 'Data leakage: SQL error leakage — PostgreSQL error string', - 951120: 'Data leakage: SQL error leakage — Oracle error string', - 951130: 'Data leakage: SQL error leakage — MSSQL error string', - 951140: 'Data leakage: SQL error leakage — MSSQL error string (2)', - 951150: 'Data leakage: SQL error leakage — MSSQL error string (3)', - 951160: 'Data leakage: SQL error leakage — SQL syntax error string', - 951170: 'Data leakage: SQL error leakage — JBoss error string', - 951180: 'Data leakage: SQL error leakage — Java/EJB error string', - 951190: 'Data leakage: SQL error leakage — Microsoft Access error string', - 951200: 'Data leakage: SQL error leakage — Microsoft Access error string (2)', - 951210: 'Data leakage: SQL error leakage — Oracle error string (2)', - 951220: 'Data leakage: SQL error leakage — DB2 error string', - 951230: 'Data leakage: SQL error leakage — EMC error string', - 951240: 'Data leakage: SQL error leakage — SAP ASE error string', - 951250: 'Data leakage: SQL error leakage — Sybase error string', - 951260: 'Data leakage: SQL error leakage — Informix error string', - 952100: 'Data leakage: Unix shell error leakage', - 952110: 'Data leakage: Unix shell error leakage (2)', - 953100: 'Data leakage: PHP error leakage', - 953110: 'Data leakage: PHP error leakage (2)', - 953120: 'Data leakage: PHP error leakage (3)', - 954100: 'Data leakage: IIS information leakage', - 954110: 'Data leakage: IIS information leakage (2)', - 954120: 'Data leakage: IIS information leakage (3)', - 954130: 'Data leakage: IIS information leakage (4)', - - // ── 980xxx Correlation ───────────────────────────────────────────────── - 980130: 'Correlation: inbound + outbound anomaly score', + 901001: "ModSecurity CRS is deployed without configuration! Please copy the crs-setup.conf.example template to crs-setup.conf,...", + 901100: "Enabling body inspection", + 901350: "Enabling forced body inspection for ASCII content", + 901400: "Sampling: Disable the rule engine based on sampling_percentage and random number ", + 901500: "Detection paranoia level configured is lower than the paranoia level itself. This is illegal. Blocking request. Aborting", + 911011: "Method is not allowed by policy", + 913011: "Found User-Agent associated with security scanner", + 920011: "Invalid HTTP Request Line", + 920013: "Range: Too many fields (6 or more)", + 920015: "Invalid character in request (outside of printable chars below ascii 127)", + 920017: "Range: Too many fields for pdf request (6 or more)", + 920120: "Attempted multipart/form-data bypass", + 920121: "Attempted multipart/form-data bypass", + 920160: "Content-Length HTTP header is not numeric", + 920170: "GET or HEAD Request with Body Content", + 920171: "GET or HEAD Request with Transfer-Encoding", + 920180: "POST without Content-Length or Transfer-Encoding headers", + 920181: "Content-Length and Transfer-Encoding headers present", + 920190: "Range: Invalid Last Byte Value", + 920201: "Range: Too many fields for pdf request (63 or more)", + 920210: "Multiple/Conflicting Connection Header Data Found", + 920220: "URL Encoding Abuse Attack Attempt", + 920221: "URL Encoding Abuse Attack Attempt", + 920230: "Multiple URL Encoding Detected", + 920240: "URL Encoding Abuse Attack Attempt", + 920250: "UTF8 Encoding Abuse Attack Attempt", + 920260: "Unicode Full/Half Width Abuse Attack Attempt", + 920270: "Invalid character in request (null character)", + 920271: "Invalid character in request (non printable characters)", + 920273: "Invalid character in request (outside of very strict set)", + 920274: "Invalid character in request headers (outside of very strict set)", + 920275: "Invalid character in request headers (outside of very strict set)", + 920280: "Request Missing a Host Header", + 920290: "Empty Host Header", + 920300: "Request Missing an Accept Header", + 920310: "Request Has an Empty Accept Header", + 920311: "Request Has an Empty Accept Header", + 920320: "Missing User Agent Header", + 920330: "Empty User Agent Header", + 920340: "Request Containing Content, but Missing Content-Type header", + 920341: "Request Containing Content Requires Content-Type header", + 920350: "Host header is a numeric IP address", + 920360: "Argument name too long", + 920370: "Argument value too long", + 920380: "Too many arguments in request", + 920390: "Total arguments size exceeded", + 920400: "Uploaded file size too large", + 920410: "Total uploaded files size too large", + 920420: "Request content type is not allowed by policy", + 920430: "HTTP protocol version is not allowed by policy", + 920440: "URL file extension is restricted by policy", + 920450: "HTTP header is restricted by policy ()", + 920451: "HTTP header is restricted by policy ()", + 920460: "Abnormal character escapes in request", + 920470: "Illegal Content-Type header", + 920480: "Request content type charset is not allowed by policy", + 920490: "Request header x-up-devcap-post-charset detected in combination with prefix \\", + 920500: "Attempt to access a backup or working file", + 920510: "Invalid Cache-Control request header", + 920520: "Accept-Encoding header exceeded sensible length", + 920521: "Illegal Accept-Encoding header", + 920530: "Multiple charsets detected in content type header", + 920540: "Possible Unicode character bypass detected", + 920600: "Illegal Accept header: charset parameter", + 920610: "Raw (unencoded) fragment in request URI", + 920620: "Multiple Content-Type Request Headers", + 921011: "HTTP Request Smuggling Attack", + 921013: "HTTP Header Injection Attack via payload (CR/LF detected)", + 921015: "HTTP Range Header detected", + 921017: "HTTP Parameter Pollution possible via array notation", + 921120: "HTTP Response Splitting Attack", + 921130: "HTTP Response Splitting Attack", + 921140: "HTTP Header Injection Attack via headers", + 921150: "HTTP Header Injection Attack via payload (CR/LF detected)", + 921160: "HTTP Header Injection Attack via payload (CR/LF and header-name detected)", + 921170: "HTTP Parameter Pollution ()", + 921190: "HTTP Splitting (CR/LF in request filename detected)", + 921200: "LDAP Injection Attack", + 921210: "HTTP Parameter Pollution after detecting bogus char after parameter array", + 921240: "mod_proxy attack attempt detected", + 921421: "Content-Type header: Dangerous content type outside the mime type declaration", + 921422: "Content-Type header: Dangerous content type outside the mime type declaration", + 922100: "Multipart content type global _charset_ definition is not allowed by policy", + 922110: "Illegal MIME Multipart Header content-type: charset parameter", + 922120: "Content-Transfer-Encoding was deprecated by rfc7578 in 2015 and should not be used", + 922130: "Multipart header contains characters outside of valid range", + 930011: "Path Traversal Attack (/../) or (/.../)", + 930013: "OS File Access Attempt in REQUEST_HEADERS", + 930110: "Path Traversal Attack (/../) or (/.../)", + 930120: "OS File Access Attempt", + 930130: "Restricted File Access Attempt", + 931011: "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address", + 931013: "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link", + 931110: "Possible Remote File Inclusion (RFI) Attack: Common RFI Vulnerable Parameter Name used w/URL Payload", + 931120: "Possible Remote File Inclusion (RFI) Attack: URL Payload Used w/Trailing Question Mark Character (?)", + 931131: "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link", + 932011: "Remote Command Execution: Unix Command Injection (2-3 chars)", + 932013: "Remote Command Execution: Unix Command Injection", + 932015: "Remote Command Execution: Unix Command Injection", + 932120: "Remote Command Execution: Windows PowerShell Command Found", + 932125: "Remote Command Execution: Windows Powershell Alias Command Injection", + 932130: "Remote Command Execution: Unix Shell Expression Found", + 932131: "Remote Command Execution: Unix Shell Expression Found", + 932140: "Remote Command Execution: Windows FOR/IF Command Found", + 932160: "Remote Command Execution: Unix Shell Code Found", + 932161: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS", + 932170: "Remote Command Execution: Shellshock (CVE-2014-6271)", + 932171: "Remote Command Execution: Shellshock (CVE-2014-6271)", + 932175: "Remote Command Execution: Unix shell alias invocation", + 932180: "Restricted File Upload Attempt", + 932190: "Remote Command Execution: Wildcard bypass technique attempt", + 932200: "RCE Bypass Technique", + 932205: "RCE Bypass Technique", + 932206: "RCE Bypass Technique", + 932210: "Remote Command Execution: SQLite System Command Execution", + 932220: "Remote Command Execution: Unix Command Injection with pipe", + 932235: "Remote Command Execution: Unix Command Injection (command without evasion)", + 932236: "Remote Command Execution: Unix Command Injection (command without evasion)", + 932237: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS", + 932238: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS", + 932239: "Remote Command Execution: Unix Command Injection found in user-agent or referer header", + 932240: "Remote Command Execution: Unix Command Injection evasion attempt detected", + 932250: "Remote Command Execution: Direct Unix Command Execution", + 932260: "Remote Command Execution: Direct Unix Command Execution", + 932270: "Remote Command Execution: Unix Shell Expression Found", + 932300: "Remote Command Execution: SMTP Command Execution", + 932301: "Remote Command Execution: SMTP Command Execution", + 932310: "Remote Command Execution: IMAP Command Execution", + 932311: "Remote Command Execution: IMAP Command Execution", + 932320: "Remote Command Execution: POP3 Command Execution", + 932321: "Remote Command Execution: POP3 Command Execution", + 932330: "Remote Command Execution: Unix shell history invocation", + 932331: "Remote Command Execution: Unix shell history invocation", + 932370: "Remote Command Execution: Windows Command Injection", + 932380: "Remote Command Execution: Windows Command Injection", + 933011: "PHP Injection Attack: PHP Open Tag Found", + 933013: "PHP Injection Attack: Medium-Risk PHP Function Name Found", + 933015: "PHP Injection Attack: Variables Found", + 933110: "PHP Injection Attack: PHP Script File Upload Found", + 933111: "PHP Injection Attack: PHP Script File Upload Found", + 933120: "PHP Injection Attack: Configuration Directive Found", + 933130: "PHP Injection Attack: Variables Found", + 933140: "PHP Injection Attack: I/O Stream Found", + 933150: "PHP Injection Attack: High-Risk PHP Function Name Found", + 933160: "PHP Injection Attack: High-Risk PHP Function Call Found", + 933161: "PHP Injection Attack: Low-Value PHP Function Call Found", + 933170: "PHP Injection Attack: Serialized Object Injection", + 933180: "PHP Injection Attack: Variable Function Call Found", + 933190: "PHP Injection Attack: PHP Closing Tag Found", + 933200: "PHP Injection Attack: Wrapper scheme detected", + 933210: "PHP Injection Attack: Variable Function Call Found", + 933211: "PHP Injection Attack: Variable Function Call Found", + 934011: "Node.js Injection Attack 1/2", + 934013: "Node.js Injection Attack 2/2", + 934110: "Possible Server Side Request Forgery (SSRF) Attack: Cloud provider metadata URL in Parameter", + 934120: "Possible Server Side Request Forgery (SSRF) Attack: URL Parameter using IP Address", + 934130: "JavaScript Prototype Pollution", + 934140: "Perl Injection Attack", + 934150: "Ruby Injection Attack", + 934160: "Node.js DoS attack", + 934170: "PHP data scheme attack", + 941011: "XSS Attack Detected via libinjection", + 941013: "XSS Attack Detected via libinjection", + 941110: "XSS Filter - Category 1: Script Tag Vector", + 941120: "XSS Filter - Category 2: Event Handler Vector", + 941130: "XSS Filter - Category 3: Attribute Vector", + 941140: "XSS Filter - Category 4: Javascript URI Vector", + 941150: "XSS Filter - Category 5: Disallowed HTML Attributes", + 941160: "NoScript XSS InjectionChecker: HTML Injection", + 941170: "NoScript XSS InjectionChecker: Attribute Injection", + 941180: "Node-Validator Deny List Keywords", + 941181: "Node-Validator Deny List Keywords", + 941190: "IE XSS Filters - Attack Detected", + 941200: "IE XSS Filters - Attack Detected", + 941210: "IE XSS Filters - Attack Detected", + 941220: "IE XSS Filters - Attack Detected", + 941230: "IE XSS Filters - Attack Detected", + 941240: "IE XSS Filters - Attack Detected", + 941250: "IE XSS Filters - Attack Detected", + 941260: "IE XSS Filters - Attack Detected", + 941270: "IE XSS Filters - Attack Detected", + 941280: "IE XSS Filters - Attack Detected", + 941290: "IE XSS Filters - Attack Detected", + 941300: "IE XSS Filters - Attack Detected", + 941310: "US-ASCII Malformed Encoding XSS Filter - Attack Detected", + 941320: "Possible XSS Attack Detected - HTML Tag Handler", + 941330: "IE XSS Filters - Attack Detected", + 941340: "IE XSS Filters - Attack Detected", + 941350: "UTF-7 Encoding IE XSS - Attack Detected", + 941360: "JSFuck / Hieroglyphy obfuscation detected", + 941370: "JavaScript global variable found", + 941380: "AngularJS client side template injection detected", + 941390: "Javascript method detected", + 941400: "XSS JavaScript function without parentheses", + 942011: "SQL Injection Attack Detected via libinjection", + 942013: "SQL Injection Attack: SQL Operator Detected", + 942015: "Detects HAVING injections", + 942017: "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)", + 942101: "SQL Injection Attack Detected via libinjection", + 942130: "SQL Injection Attack: SQL Boolean-based attack detected", + 942131: "SQL Injection Attack: SQL Boolean-based attack detected", + 942140: "SQL Injection Attack: Common DB Names Detected", + 942150: "SQL Injection Attack: SQL function name detected", + 942151: "SQL Injection Attack: SQL function name detected", + 942152: "SQL Injection Attack: SQL function name detected", + 942160: "Detects blind sqli tests using sleep() or benchmark()", + 942170: "Detects SQL benchmark and sleep injection attempts including conditional queries", + 942180: "Detects basic SQL authentication bypass attempts 1/3", + 942190: "Detects MSSQL code execution and information gathering attempts", + 942200: "Detects MySQL comment-/space-obfuscated injections and backtick termination", + 942210: "Detects chained SQL injection attempts 1/2", + 942220: "Looking for integer overflow attacks, these are taken from skipfish, except 2.2.2250738585072011e-308 is the \\"magic...", + 942230: "Detects conditional SQL injection attempts", + 942240: "Detects MySQL charset switch and MSSQL DoS attempts", + 942250: "Detects MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections", + 942260: "Detects basic SQL authentication bypass attempts 2/3", + 942270: "Looking for basic sql injection. Common attack string for mysql, oracle and others", + 942280: "Detects Postgres pg_sleep injection, waitfor delay attacks and database shutdown attempts", + 942290: "Finds basic MongoDB SQL injection attempts", + 942300: "Detects MySQL comments, conditions and ch(a)r injections", + 942310: "Detects chained SQL injection attempts 2/2", + 942320: "Detects MySQL and PostgreSQL stored procedure/function injections", + 942321: "Detects MySQL and PostgreSQL stored procedure/function injections", + 942330: "Detects classic SQL injection probings 1/3", + 942340: "Detects basic SQL authentication bypass attempts 3/3", + 942350: "Detects MySQL UDF injection and other data/structure manipulation attempts", + 942360: "Detects concatenated basic SQL injection and SQLLFI attempts", + 942361: "Detects basic SQL injection based on keyword alter or union", + 942362: "Detects concatenated basic SQL injection and SQLLFI attempts", + 942370: "Detects classic SQL injection probings 2/3", + 942380: "SQL Injection Attack", + 942390: "SQL Injection Attack", + 942400: "SQL Injection Attack", + 942410: "SQL Injection Attack", + 942420: "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (8)", + 942430: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (12)", + 942431: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)", + 942432: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)", + 942441: "SQL Comment Sequence Detected", + 942450: "SQL Hex Encoding Identified", + 942460: "Meta-Character Anomaly Detection Alert - Repetitive Non-Word Characters", + 942470: "SQL Injection Attack", + 942480: "SQL Injection Attack", + 942490: "Detects classic SQL injection probings 3/3", + 942500: "MySQL in-line comment detected", + 942510: "SQLi bypass attempt by ticks or backticks detected", + 942511: "SQLi bypass attempt by ticks detected", + 942520: "Detects basic SQL authentication bypass attempts 4.0/4", + 942521: "Detects basic SQL authentication bypass attempts 4.1/4", + 942522: "Detects basic SQL authentication bypass attempts 4.1/4", + 942530: "SQLi query termination detected", + 942540: "SQL Authentication bypass (split query)", + 942550: "JSON-Based SQL Injection", + 942560: "MySQL Scientific Notation payload detected", + 943011: "Possible Session Fixation Attack: Setting Cookie Values in HTML", + 943110: "Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer", + 943120: "Possible Session Fixation Attack: SessionID Parameter Name with No Referer", + 944011: "Remote Command Execution: Suspicious Java class detected", + 944013: "Potential Remote Command Execution: Log4j / Log4shell", + 944015: "Base64 encoded string matched suspicious keyword", + 944017: "Potential Remote Command Execution: Log4j / Log4shell", + 944110: "Remote Command Execution: Java process spawn (CVE-2017-9805)", + 944120: "Remote Command Execution: Java serialization (CVE-2015-4852)", + 944130: "Suspicious Java class detected", + 944140: "Java Injection Attack: Java Script File Upload Found", + 944150: "Potential Remote Command Execution: Log4j / Log4shell", + 944200: "Magic bytes Detected, probable java serialization in use", + 944210: "Magic bytes Detected Base64 Encoded, probable java serialization in use", + 944240: "Remote Command Execution: Java serialization (CVE-2015-4852)", + 944250: "Remote Command Execution: Suspicious Java method detected", + 944260: "Remote Command Execution: Malicious class-loading payload", + 949052: "Inbound Anomaly Score Exceeded in phase 1 (Total Score: %{TX.BLOCKING_INBOUND_ANOMALY_SCORE})", + 949110: "Inbound Anomaly Score Exceeded (Total Score: %{TX.BLOCKING_INBOUND_ANOMALY_SCORE})", + 950010: "Directory Listing", + 950013: "The Application Returned a 500-Level Status Code", + 950140: "CGI source code leakage", + 951010: "Microsoft Access SQL Information Leakage", + 951120: "Oracle SQL Information Leakage", + 951130: "DB2 SQL Information Leakage", + 951140: "EMC SQL Information Leakage", + 951150: "firebird SQL Information Leakage", + 951160: "Frontbase SQL Information Leakage", + 951170: "hsqldb SQL Information Leakage", + 951180: "informix SQL Information Leakage", + 951190: "ingres SQL Information Leakage", + 951200: "interbase SQL Information Leakage", + 951210: "maxDB SQL Information Leakage", + 951220: "mssql SQL Information Leakage", + 951230: "mysql SQL Information Leakage", + 951240: "postgres SQL Information Leakage", + 951250: "sqlite SQL Information Leakage", + 951260: "Sybase SQL Information Leakage", + 952010: "Java Source Code Leakage", + 952110: "Java Errors", + 953010: "PHP Information Leakage", + 953013: "PHP Information Leakage", + 953110: "PHP source code leakage", + 953120: "PHP source code leakage", + 954010: "Disclosure of IIS install location", + 954110: "Application Availability Error", + 954120: "IIS Information Leakage", + 954130: "IIS Information Leakage", + 955010: "Web shell detected", + 955013: "webadmin.php file manager", + 955110: "r57 web shell", + 955120: "WSO web shell", + 955130: "b4tm4n web shell", + 955140: "Mini Shell web shell", + 955150: "Ashiyane web shell", + 955160: "Symlink_Sa web shell", + 955170: "CasuS web shell", + 955180: "GRP WebShell", + 955190: "NGHshell web shell", + 955200: "SimAttacker web shell", + 955210: "Unknown web shell", + 955220: "lama\\", + 955230: "lostDC web shell", + 955240: "Unknown web shell", + 955250: "Unknown web shell", + 955260: "Ru24PostWebShell web shell", + 955270: "s72 Shell web shell", + 955280: "PhpSpy web shell", + 955290: "g00nshell web shell", + 955300: "PuNkHoLic shell web shell", + 955310: "azrail web shell", + 955320: "SmEvK_PaThAn Shell web shell", + 955330: "Shell I web shell", + 955340: "b374k m1n1 web shell", + 959052: "Outbound Anomaly Score Exceeded in phase 3 (Total Score: %{tx.blocking_outbound_anomaly_score})", + 959100: "Outbound Anomaly Score Exceeded (Total Score: %{tx.blocking_outbound_anomaly_score})", + 980099: "Anomaly Scores: \\ +(Inbound Scores: blocking=%{tx.blocking_inbound_anomaly_score}, detection=%{tx.detection_inbound_a...", } -/** - * Returns the description for a given rule ID, or a fallback if unknown. - */ export function getRuleDescription(ruleId: number): string { - return CRS_RULES[ruleId] ?? `Rule ${ruleId} — no description available` -} - -/** - * Returns the rule category name from the rule ID prefix. - */ -export function getRuleCategory(ruleId: number): string { - const prefix = Math.floor(ruleId / 100) - const categories: Record = { - 9000: 'CRS Setup', 9001: 'Initialization', - 9031: 'Scanner', 9050: 'Protocol', - 9100: 'IP Reputation', 9111: 'Method Enforcement', - 9121: 'DoS Protection', 9131: 'Scanner Detection', - 9201: 'Protocol Enforcement', 9211: 'HTTP Smuggling', - 9221: 'File Upload', - 9301: 'LFI', 9311: 'RFI', 9321: 'RCE', - 9331: 'PHP Injection', 9341: 'Node.js Injection', - 9411: 'XSS', 9421: 'SQL Injection', - 9431: 'Session Fixation', 9441: 'Java Attack', - 9491: 'Anomaly Score', - 9501: 'Response — Data Leakage', 9511: 'Response — SQL Error', - 9521: 'Response — Unix Shell', 9531: 'Response — PHP Error', - 9541: 'Response — IIS Error', 9801: 'Correlation', - } - return categories[prefix] ?? `Category ${Math.floor(ruleId / 1000) * 1000}` -} + return CRS_RULES[ruleId] ?? `Rule ${ruleId} — see coreruleset.org for details` +} \ No newline at end of file