Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - AvalZ/modsecurity-cli: A CLI wrapper for libmodsecurity (v3.0.10) · GitHub
Skip to content

Latest commit

History

27 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

ModSecurity CLI

A CLI wrapper for libmodsecurity to quickly test payloads against Rules in a headless mode, without having to set up a full-fledged web testing environment.

This wrapper is still in development, and some ModSecurity features could be missing. Most ModSecurity methods are implemented via pymodsecurity (requires manual building -- PR pending on the official repository),

Getting started

To run modsecurity-cli, you will need a few setup steps.

Setup

  1. Compile and Install ModSecurity v3.0.10
  2. Install pymodsecurity
  3. Clone the OWASP CoreRuleSet
  4. Run the CLI!

Here's the detail for each step.

Compile ModSecurity v3.0.10

First of all, you will need to install ModSecurity v3.0.10 on your system. Currently, this is a nightmaretricky process, since you will need to build ModSecurity v3.0.10 from source (although some distros might have an updated registry with ModSecurity 3.0.10 already available *coff*arch*coff*)

Install pymodsecurity

In modsecurity-cli ModSecurity methods are implemented via pymodsecurity. Since development on the official repository stopped on ModSecurity v3.0.3, we opened a PR.

Current workaround: clone our fork and build it from source

Clone the OWASP CoreRuleSet

To detect incoming payloads, you need a Rule Set. The de facto standard is the OWASP CoreRuleSet, but of course you can choose any Rule Set you want, or customize the OWASP CRS.

To run the recommended settings, just clone the OWASP CRS in the project folder:

git clone git@github.com:coreruleset/coreruleset.git

Run the CLI!

Check ModSecurity version

$ python3 main.py --version

Evaluate a single parameter

$ python3 main.py "<script>alert(1)</script>"20

If you want to see the breakdown of matched rules, just use --verbose

$ python3 main.py "<script>alert(1)</script>" --verboseGET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules - 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected - 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler - 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 20

+ rules are the ones that are actually matched, while - rules apply to different paranoia levels (1 by default)

You can set a specific Paranoia Level to calculate the score (the default PL is 1)

$ python3 main.py "<script>alert(1)</script>" -v -PL 2GET http://www.modsecurity.org/test?q=%3Cscript%3Ealert%281%29%3C%2Fscript%3E
# Matched rules + 920320 [+2/PL2] - Missing User Agent Header - 920273 [+5/PL4] - Invalid character in request (outside of very strict set) + 941100 [+5/PL1] - XSS Attack Detected via libinjection + 941110 [+5/PL1] - XSS Filter - Category 1: Script Tag Vector + 941160 [+5/PL1] - NoScript XSS InjectionChecker: HTML Injection + 941390 [+5/PL1] - Javascript method detected + 941320 [+5/PL2] - Possible XSS Attack Detected - HTML Tag Handler + 942131 [+5/PL2] - SQL Injection Attack: SQL Boolean-based attack detected - 942431 [+3/PL3] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6) - 942432 [+3/PL4] - Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2) + 949110 [+0/PL1] - Inbound Anomaly Score Exceeded (Total Score: 43)Total Score (from matched rules): 32

WARNING! You can see that it prints two Total Scores. One (32) is calculated by matched rules (+), while the other one (43) is the error message from rule 949110 (which is calculated at Paranoia Level 4).

If you don't want this message, you can either increase the Anomaly Score threshold via your conf/crs-setup.conf, or by removing rule 949110 file entirely (not advised).

modsecurity-cli has many options, check out the --help for all details! (a wiki is coming)

$ python3 main.py --help

TODOs

This CLI wrapper is still under development, so you might not find some features that are interesting to you just yet.

Here's the list of our current and future steps:

  • ModSecurity from CLI
  • Import all rules in a folder
  • Support GET parameters evaluation
  • Support Request Header evaluation
  • Set default config to avoid matching rule 901001
  • Score based on Paranoia Level (basic config uses PL/4, then we filter on a given PL - default: 1)
  • Support POST request evaluation
  • Full URI evaluation
  • Create Python package
  • Wiki to fully document every option
  • Integration with regrets
  • Response evaluation (currently supports requests only)

If you want to contribute by adding something from the list, PRs are welcome 😎

Contributors

About

A CLI wrapper for libmodsecurity (v3.0.10)

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages