Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
97d8c1e101 |
@@ -232,7 +232,9 @@ in `bin/state` unless `SWWAF_STATE_DIR` is set, and the default rule file of
|
|||||||
command names (932260), so that a file such as `.gitignore` or a branch
|
command names (932260), so that a file such as `.gitignore` or a branch
|
||||||
such as `docker-build` gets through there. So does what only these rules
|
such as `docker-build` gets through there. So does what only these rules
|
||||||
refuse, such as `|cat /etc/passwd`; path traversal and SQL injection are
|
refuse, such as `|cat /etc/passwd`; path traversal and SQL injection are
|
||||||
still refused there.
|
still refused there. These names, and `redirect_uri` above, are matched
|
||||||
|
without regard to case, as Coraza matches them, so `Path` or `PATH` is
|
||||||
|
treated as `path`.
|
||||||
- The cookies `gitea_flash` and `redirect_to` are not read, and `Referer` is
|
- The cookies `gitea_flash` and `redirect_to` are not read, and `Referer` is
|
||||||
not checked for a Unix command given without arguments (932340) or for
|
not checked for a Unix command given without arguments (932340) or for
|
||||||
Java starting a process (944110); it is checked by every other rule.
|
Java starting a process (944110); it is checked by every other rule.
|
||||||
|
|||||||
@@ -618,10 +618,12 @@ The settings, by group:
|
|||||||
`|cat /etc/passwd`, `wget http://…` and `nc -e /bin/sh …`, and
|
`|cat /etc/passwd`, `wget http://…` and `nc -e /bin/sh …`, and
|
||||||
`file:///etc/passwd`, pass as well. Path traversal (`../`), SQL and
|
`file:///etc/passwd`, pass as well. Path traversal (`../`), SQL and
|
||||||
script injection and PHP, Java and Node.js code are still refused
|
script injection and PHP, Java and Node.js code are still refused
|
||||||
there, and every other parameter keeps all three rules. An app that
|
there, and every other parameter keeps all three rules. These names,
|
||||||
uses one of these parameters as a file on the server, or passes it to
|
and `redirect_uri` in the change before, are matched without regard to
|
||||||
a shell, gets no help from the three rules there (see "Risks the
|
case, as Coraza matches them, so `Path` or `PATH` is treated as
|
||||||
design has to handle").
|
`path`. An app that uses one of these parameters as a file on the
|
||||||
|
server, or passes it to a shell, gets no help from the three rules
|
||||||
|
there (see "Risks the design has to handle").
|
||||||
- The Core Rule Set reads the request without the `gitea_flash` and
|
- The Core Rule Set reads the request without the `gitea_flash` and
|
||||||
`redirect_to` cookies, and does not check `Referer` for a Unix command
|
`redirect_to` cookies, and does not check `Referer` for a Unix command
|
||||||
given without arguments (932340) or for Java starting a process
|
given without arguments (932340) or for Java starting a process
|
||||||
|
|||||||
+2
-1
@@ -56,7 +56,8 @@ SecAction "id:900250,phase:1,pass,nolog,\
|
|||||||
Include @owasp_crs/REQUEST-*.conf
|
Include @owasp_crs/REQUEST-*.conf
|
||||||
|
|
||||||
# The third: redirect_uri is not checked for a URL naming an IP address or
|
# The third: redirect_uri is not checked for a URL naming an IP address or
|
||||||
# localhost.
|
# localhost. Coraza matches a parameter name here, and in the fourth,
|
||||||
|
# without regard to case.
|
||||||
SecRuleUpdateTargetById 931100 "!ARGS:redirect_uri"
|
SecRuleUpdateTargetById 931100 "!ARGS:redirect_uri"
|
||||||
SecRuleUpdateTargetById 934110 "!ARGS:redirect_uri"
|
SecRuleUpdateTargetById 934110 "!ARGS:redirect_uri"
|
||||||
|
|
||||||
|
|||||||
@@ -233,6 +233,16 @@ func TestParametersGiteaSendsNamesInSkipTheListsOfFilesPathsAndCommands(t *testi
|
|||||||
wantResult(t, crs, get("/?path=1'%20OR%20'1'='1"), matched(942100))
|
wantResult(t, crs, get("/?path=1'%20OR%20'1'='1"), matched(942100))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestParameterNamesAreMatchedWithoutRegardToCase(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
crs := atDefaults(t)
|
||||||
|
|
||||||
|
wantChange(t, crs, get("/?Path=.gitignore"), get("/?q=.gitignore"), matched(930120))
|
||||||
|
wantChange(t, crs, get("/?REDIRECT_URI=http://127.0.0.1:52341/"),
|
||||||
|
get("/?next=http://127.0.0.1:52341/"), matched(931100, 934110))
|
||||||
|
}
|
||||||
|
|
||||||
func TestCookiesGiteaFlashAndRedirectToAreNotRead(t *testing.T) {
|
func TestCookiesGiteaFlashAndRedirectToAreNotRead(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user