ModSecurity bypass training with OWASP rules (Apache2 x ModSecurity v3 x PHP 7)
10K+
ModSecurity bypass training with OWASP rules (Apache2 x ModSecurity v3 x PHP 7)
$ docker run -d --rm -v ${PWD}:/var/www/html/current -p 8081:80 --name modsec_lab nbeguier/apache-modsecurity3-php7
# Default HTTP page
$ curl http://localhost:8081/index.html
# Default phpinfo
$ curl http://localhost:8081/hidden.php
# Shared directory
$ curl http://localhost:8081/current/
# In your current directory
$ git clone https://github.com/SEC642/modsec
# firefox http://localhost:8081/current/modsec/
# Play with XSS Input and try to bypass mod_security
$ curl -s 'http://localhost:8081/current/modsec/index.php' --data 'xss=hello' -w "%{http_code}\n" -o /dev/null
200
$ curl -s 'http://localhost:8081/current/modsec/index.php' --data 'xss=<script>alert(XSS)</script>' -w "%{http_code}\n" -o /dev/null
403
Licensed under the Apache License, Version 2.0 (the "License").
Copyright 2020-2021 Nicolas BEGUIER; (nbeguier - nicolas_beguier[at]hotmail[dot]com)
Content type
Image
Digest
Size
110.5 MB
Last updated
almost 6 years ago
docker pull nbeguier/apache-modsecurity3-php7