fix(waf): 避免 SQL 特征 /* */ 误匹配 Accept: */*

开启 SQL 注入防护时不再把正常 Accept 头当成攻击。
This commit is contained in:
ryan
2026-07-19 12:46:23 +08:00
parent b75f985815
commit 1ba05ec0bd
2 changed files with 10 additions and 1 deletions
+2 -1
View File
@@ -502,7 +502,8 @@ local file_inclusion_patterns = {
local sql_patterns = {
"union select", " or 1=1", "' or '", "\" or \"", "sleep(", "benchmark(",
"information_schema", "xp_cmdshell", "load_file(", " into outfile",
"/*", "*/", "@@version",
-- Avoid bare "/*" / "*/": they match normal Accept: */* headers.
"/**/", "/*!", "*/--", "@@version",
}
local command_patterns = {
";wget", ";curl", "|bash", "|sh", "`id`", "$(id)", "&&", "||",