Skip to content

Information disclosure - statuscode response containing WAF type #1975

Open
@erikvdijk

Description

@erikvdijk

The response status code of a blocked request contains the text: "ModSecurity Action"
This way an attacker could find for specific security holes in this product.

It would be great if this text could be changed by parameter, or not send at all.

Code:
https://github.com/SpiderLabs/ModSecurity/blob/v2/master/iis/mymodule.cpp#L670

(this is my first bug report, sorry for any possible missing information)

Metadata

Metadata

Assignees

No one assigned

    Labels

    2.xRelated to ModSecurity version 2.xPlatform - IIS

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions