mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 14:06:36 +08:00
fix(waf): 避免 SQL 特征 /* */ 误匹配 Accept: */*
开启 SQL 注入防护时不再把正常 Accept 头当成攻击。
This commit is contained in:
@@ -502,7 +502,8 @@ local file_inclusion_patterns = {
|
||||
local sql_patterns = {
|
||||
"union select", " or 1=1", "' or '", "\" or \"", "sleep(", "benchmark(",
|
||||
"information_schema", "xp_cmdshell", "load_file(", " into outfile",
|
||||
"/*", "*/", "@@version",
|
||||
-- Avoid bare "/*" / "*/": they match normal Accept: */* headers.
|
||||
"/**/", "/*!", "*/--", "@@version",
|
||||
}
|
||||
local command_patterns = {
|
||||
";wget", ";curl", "|bash", "|sh", "`id`", "$(id)", "&&", "||",
|
||||
|
||||
@@ -717,6 +717,14 @@ local function test_security_check_path_and_sql()
|
||||
rule_groups = { rule(1, false, security_graph({ sql_injection = true })) },
|
||||
bindings = { binding("sec-site", { 1 }) },
|
||||
})
|
||||
reset_request("sec-site", nil, "/")
|
||||
ngx.req.get_headers = function()
|
||||
return { Accept = "*/*" }
|
||||
end
|
||||
decision, err = runtime.debug_execute_graph(runtime.debug_active_rules("sec-site")[1].graph)
|
||||
assert_equal(err, nil, "accept header execute err")
|
||||
assert_equal(decision and decision.kind or "nil", "allow", "Accept */* must not trip SQL")
|
||||
|
||||
reset_request("sec-site", nil, "/")
|
||||
ngx.var.args = "q=1'+union+select+1--"
|
||||
ngx.req.get_uri_args = function()
|
||||
|
||||
Reference in New Issue
Block a user