Skip to main content

Google bot triggering OWASP modsecurity rule 949110

Comments

6 comments

  • cPRex Jurassic Moderator
    Hey there! This isn't a new thing, as this happens with people once in a while when ModSecurity gets overly protective. Here is a similar thread from 10 years ago:
    0
  • ciao70
    Hi, Check the Modsecurity log carefully, because there is probably some other rule that triggers the 949110
    0
  • aeroweb
    Thanks for the info, much appreciated. The strange thing is, we've used modsecurity with the OWASP rules setup on our servers for years now. And yes, we would occasionally get false positives and see the Google Bot being blocked over the years, however in the last 3 days or so we've gotten hundreds of blocks which is very unusual. Do you know if anything has changed recently, have any of the OWASP rules been updated? Thanks
    0
  • cPRex Jurassic Moderator
    You can check and see if there has been an update to the package through the /var/log/dnf.rpm.log log file. On my personal machine, the last OWASP update was Jan 5: 2023-01-05T05:34:47-0500 SUBDEBUG Upgrade: ea-modsec2-rules-owasp-crs-3.3.4-1.1.2.cpanel.x86_64
    0
  • aeroweb
    I do not have a dnf.rpm.log file. I checked the yum.log files and its not in there. I also checked /etc/apache2/conf.d/modsec_vendor_configs/OWASP3 but it appears that the rule files here get updated daily when cPanel runs its update cron.
    0
  • aeroweb
    After further review of both the mod-security logs and Apache logs it appears that the Googlebot is actually triggering rule: 942100 "sql injection attack detected via libinjection" The Google bot seems to be hitting the servers with hundreds of GET requests against WordPress websites using the build in WordPress search feature (/?s=). See below. GET /?s=%E9%9B%B2%E9%A0%82%E9%AB%98%E5%8E%9F%E6%99%AF%E9%BB%9E-%E3%80%90%E2%9C%94%EF%B8%8F%E6%8E%A8%E8%96%A6DD96%C2%B7CC%E2%9C%94%EF%B8%8F%E3%80%91-%E5%9C%A8%E7%B7%9A%E7%A0%B8%E9%87%91%E8%8A%B1-%E9%9B%B2%E9%A0%82%E9%AB%98%E5%8E%9F%E6%99%AF%E9%BB%9Efdxpr-%E3%80%90%E2%9C%94%EF%B8%8F%E6%8E%A8%E8%96%A6DD96%C2%B7CC%E2%9C%94%EF%B8%8F%E3%80%91-%E5%9C%A8%E7%B7%9A%E7%A0%B8%E9%87%91%E8%8A%B1td3t-%E9%9B%B2%E9%A0%82%E9%AB%98%E5%8E%9F%E6%99%AF%E9%BB%9Ebebzt-%E5%9C%A8%E7%B7%9A%E7%A0%B8%E9%87%91%E8%8A%B1epvh
    0

Please sign in to leave a comment.