mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-06 23:56:37 +08:00
fix(waf): 避免 SQL 特征 /* */ 误匹配 Accept: */*
开启 SQL 注入防护时不再把正常 Accept 头当成攻击。
This commit is contained in:
@@ -502,7 +502,8 @@ local file_inclusion_patterns = {
|
|||||||
local sql_patterns = {
|
local sql_patterns = {
|
||||||
"union select", " or 1=1", "' or '", "\" or \"", "sleep(", "benchmark(",
|
"union select", " or 1=1", "' or '", "\" or \"", "sleep(", "benchmark(",
|
||||||
"information_schema", "xp_cmdshell", "load_file(", " into outfile",
|
"information_schema", "xp_cmdshell", "load_file(", " into outfile",
|
||||||
"/*", "*/", "@@version",
|
-- Avoid bare "/*" / "*/": they match normal Accept: */* headers.
|
||||||
|
"/**/", "/*!", "*/--", "@@version",
|
||||||
}
|
}
|
||||||
local command_patterns = {
|
local command_patterns = {
|
||||||
";wget", ";curl", "|bash", "|sh", "`id`", "$(id)", "&&", "||",
|
";wget", ";curl", "|bash", "|sh", "`id`", "$(id)", "&&", "||",
|
||||||
|
|||||||
@@ -717,6 +717,14 @@ local function test_security_check_path_and_sql()
|
|||||||
rule_groups = { rule(1, false, security_graph({ sql_injection = true })) },
|
rule_groups = { rule(1, false, security_graph({ sql_injection = true })) },
|
||||||
bindings = { binding("sec-site", { 1 }) },
|
bindings = { binding("sec-site", { 1 }) },
|
||||||
})
|
})
|
||||||
|
reset_request("sec-site", nil, "/")
|
||||||
|
ngx.req.get_headers = function()
|
||||||
|
return { Accept = "*/*" }
|
||||||
|
end
|
||||||
|
decision, err = runtime.debug_execute_graph(runtime.debug_active_rules("sec-site")[1].graph)
|
||||||
|
assert_equal(err, nil, "accept header execute err")
|
||||||
|
assert_equal(decision and decision.kind or "nil", "allow", "Accept */* must not trip SQL")
|
||||||
|
|
||||||
reset_request("sec-site", nil, "/")
|
reset_request("sec-site", nil, "/")
|
||||||
ngx.var.args = "q=1'+union+select+1--"
|
ngx.var.args = "q=1'+union+select+1--"
|
||||||
ngx.req.get_uri_args = function()
|
ngx.req.get_uri_args = function()
|
||||||
|
|||||||
Reference in New Issue
Block a user