check / check (push) Waiting to run
Every *.rules file in SWWAF_RULES_DIR not named with a leading dot is read at start, and again 2 seconds after the directory's last change. Each request is checked against the rules after the rate limits: log notes a match, block refuses with 403, ban refuses and bans the netblock for SWWAF_ATTACK_BAN_DURATION, made permanent by its next request or attack. path, query and uri are matched as the request line sent them; header:Host and header:Transfer-Encoding are refused. Bans gain a cause. The image ships 00-default.rules. Judgement call: a header sent twice is matched with its values joined by ", ". Judgement call: SWWAF_MAX_BAN_DURATION does not cap a ban for an attack. Not in this unit: offences for rule matches, with the error burst. Model: opus-5-5
27 lines
772 B
Bash
Executable File
27 lines
772 B
Bash
Executable File
#!/bin/sh
|
|
# script/run: build bin/smallwebwaf with script/build and run it, with
|
|
# the settings in the environment. Unless SWWAF_STATE_DIR is set, the
|
|
# state files go in bin/state, beside the binary, and unless
|
|
# SWWAF_RULES_DIR is set, the rule files are those of share/rules.d,
|
|
# which the image ships.
|
|
set -eu
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
|
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|
|
|
main() {
|
|
"$SCRIPT_DIR/build"
|
|
if [ -z "${SWWAF_STATE_DIR+set}" ]; then
|
|
SWWAF_STATE_DIR="$ROOT/bin/state"
|
|
export SWWAF_STATE_DIR
|
|
mkdir -p "$SWWAF_STATE_DIR"
|
|
fi
|
|
if [ -z "${SWWAF_RULES_DIR+set}" ]; then
|
|
SWWAF_RULES_DIR="$ROOT/share/rules.d"
|
|
export SWWAF_RULES_DIR
|
|
fi
|
|
exec "$ROOT/bin/smallwebwaf"
|
|
}
|
|
|
|
main "$@"
|