[文章作者:张宴 本文版本:v1.2 最后修改:2010.05.24 转载请注明原文链接:http://blog.zyan.cc/nginx_0day/]

  注:2010年5月23日14:00前阅读本文的朋友,请按目前v1.1版本的最新配置进行设置。

  昨日,80Sec 爆出Nginx具有严重的0day漏洞,详见《Nginx文件类型错误解析漏洞》。只要用户拥有上传图片权限的Nginx+PHP服务器,就有被入侵的可能。

  其实此漏洞并不是Nginx的漏洞,而是PHP PATH_INFO的漏洞,详见:http://bugs.php.net/bug.php?id=50852&edit=1

  例如用户上传了一张照片,访问地址为http://www.domain.com/images/test.jpg,而test.jpg文件内的内容实际上是PHP代码时,通过http://www.domain.com/images/test.jpg/abc.php就能够执行该文件内的PHP代码。

  网上提供的临时解决方法有:

  方法①、修改php.ini,设置cgi.fix_pathinfo = 0;然后重启php-cgi。此修改会影响到使用PATH_INFO伪静态的应用,例如我以前博文的URL:http://blog.zyan.cc/read.php/348.htm 就不能访问了。

  方法②、在nginx的配置文件添加如下内容后重启:if ( $fastcgi_script_name ~ \..*\/.*php ) {return 403;}。该匹配会影响类似 http://www.domain.com/software/5.0/test.php(5.0为目录),http://www.domain.com/goto.php/phpwind 的URL访问。

  方法③、对于存储图片的location{...},或虚拟主机server{...},只允许纯静态访问,不配置PHP访问。例如在金山逍遥网论坛、SNS上传的图片、附件,会传送到专门的图片、附件存储服务器集群上(pic.xoyo.com),这组服务器提供纯静态服务,无任何动态PHP配置。各大网站几乎全部进行了图片服务器分离,因此Nginx的此次漏洞对大型网站影响不大。



  本人再提供一种修改nginx.conf配置文件的临时解决方法,兼容“http://blog.zyan.cc/demo/0day/phpinfo.php/test”的PATH_INFO伪静态,拒绝“http://blog.zyan.cc/demo/0day/phpinfo.jpg/test.php”的漏洞攻击:
location ~* .*\.php($|/)
{
      if ($request_filename ~* (.*)\.php) {
            set $php_url $1;
      }
      if (!-e $php_url.php) {
            return 403;
      }

      fastcgi_pass  127.0.0.1:9000;
      fastcgi_index index.php;
      include fcgi.conf;
}


  也可将以下内容写在fcgi.conf文件中,便于多个虚拟主机引用:
if ($request_filename ~* (.*)\.php) {
    set $php_url $1;
}
if (!-e $php_url.php) {
    return 403;
}

fastcgi_param  GATEWAY_INTERFACE  CGI/1.1;
fastcgi_param  SERVER_SOFTWARE    nginx;

fastcgi_param  QUERY_STRING       $query_string;
fastcgi_param  REQUEST_METHOD     $request_method;
fastcgi_param  CONTENT_TYPE       $content_type;
fastcgi_param  CONTENT_LENGTH     $content_length;

fastcgi_param  SCRIPT_FILENAME    $document_root$fastcgi_script_name;
fastcgi_param  SCRIPT_NAME        $uri;
fastcgi_param  REQUEST_URI        $request_uri;
fastcgi_param  DOCUMENT_URI       $document_uri;
fastcgi_param  DOCUMENT_ROOT      $document_root;
fastcgi_param  SERVER_PROTOCOL    $server_protocol;

fastcgi_param  REMOTE_ADDR        $remote_addr;
fastcgi_param  REMOTE_PORT        $remote_port;
fastcgi_param  SERVER_ADDR        $server_addr;
fastcgi_param  SERVER_PORT        $server_port;
fastcgi_param  SERVER_NAME        $server_name;

# PHP only, required if PHP was built with --enable-force-cgi-redirect
fastcgi_param  REDIRECT_STATUS    200;




  附:文章修改历史

  ● [2010年05月21日] [Version 1.0] 新建

  ● [2010年05月23日] [Version 1.1] 针对网友michael提出的“如果构造一个形如/..trojan.jpg/dummy.php/?abcd=1,似乎可以绕过防范的nginx配置”,进行了配置修改,防范了此类情况发生。提供测试的URL如下,拒绝漏洞访问:
  http://blog.zyan.cc/demo/0day/phpinfo.jpg (里面是PHP代码)
  http://blog.zyan.cc/demo/0day/phpinfo.jpg/.php
  http://blog.zyan.cc/demo/0day/phpinfo.jpg/dummy.php
  http://blog.zyan.cc/demo/0day/phpinfo.jpg/dummy.php/?abcd=1

  同时兼容正常的PATH_INFO伪静态请求,测试URL如下:
  http://blog.zyan.cc/demo/0day/phpinfo.php (这是正常的PHP文件)
  http://blog.zyan.cc/demo/0day/phpinfo.php/test
  http://blog.zyan.cc/demo/0day/phpinfo.php/news123.html
  http://blog.zyan.cc/read.php/348.htm

  ● [2010年05月24日] [Version 1.2] 修正文字描述错误。


Tags: , ,



技术大类 » Web服务器 | 评论(481) | 引用(0) | 阅读(139329)
seo Email
2025-11-18 17:30
I am thankful to you for sharing this plethora of useful information. I found this resource utmost beneficial for me. Thanks a lot for hard work. M88 Slot
SDFFS Email
2025-11-18 18:57
What a fantabulous post this has been. Never seen this kind of useful post. I am grateful to you and expect more number of posts like these. Thank you very much.  1xbet new promo code
온라인카지노 Email
2025-11-22 09:32
온라인슬롯, 슬롯사이트, 먹튀검증, 온라인카지노, 토토사이트, 카지노 커뮤니티, 슬롯커뮤니티, 무료슬롯체험, 온라인바카라, 에볼루션카지노, 프라그마틱슬롯https://kkuns.com
카지노사이트 Email Homepage
2025-11-22 12:18
온라인슬롯, 슬롯사이트, 먹튀검증, 온라인카지노, 토토사이트, 카지노 커뮤니티, 슬롯커뮤니티, 무료슬롯체험, 온라인바카라, 에볼루션카지노, 프라그마틱슬롯카지노사이트  https://kkuns.com
웹툰사이트 Email Homepage
2025-11-22 15:53
해피툰 | 무료웹툰 | 웹툰사이트 | 무료웹툰사이트
웹툰사이트 Email Homepage
2025-11-22 15:54
해피툰 | 무료웹툰 | 웹툰사이트 | 무료웹툰사이트웹툰사이트https://xn--z27bt9c1e.comhttps://xn--z27bt9c1e.com
seo Email
2025-11-23 16:08
I haven’t any word to appreciate this post.....Really i am impressed from this post....the person who create this post it was a great human..thanks for shared this with us.  edi toto  I really appreciate this wonderful post that you have provided for us. I assure this would be beneficial for most of the people.  situs online  Some truly wonderful work on behalf of the owner of this internet site , perfectly great articles .  situs slot
seo Email
2025-11-23 16:08
Thanks For sharing this Superb article.I use this Article to show my assignment in college.it is useful For me Great Work.  situs slot  This is just the information I am finding everywhere. Thanks for your blog, I just subscribe your blog. This is a nice blog..  slot gacor
SDFSFD Email
2025-11-24 15:45
I wanted to thank you for this great read!! I definitely enjoying every little bit of it I have you bookmarked to check out new stuff you post.  olxtoto
BGFGD Email Homepage
2025-11-25 12:48
온라인슬롯, 슬롯사이트, 먹튀검증, 온라인카지노, 토토사이트, 카지노 커뮤니티, 슬롯커뮤니티, 무료슬롯체험, 온라인바카라, 에볼루션카지노, 프라그마틱슬롯https://kkuns.com
슬롯 사이트 Email Homepage
2025-11-26 09:28
I haven’t any word to appreciate this post.....Really i am impressed from this post....the person who create this post it was a great human..thanks for shared this with us. https://xn--bb0bo0gz8cfzm9zonug.net
SDFDSFDS Email
2025-11-26 22:03
thanks this is good blog.  สล็อตเว็บตรง
Brooke Email Homepage
2025-11-26 22:25
The comparison of different mitigation approaches is also valuable. Each workaround has its own trade-offs, especially for sites that rely heavily on pseudo-static URLs or complex routing. Platinum Promotions
Brooke Email
2025-11-26 22:28
The comparison of different mitigation approaches is also valuable. Each workaround has its own trade-offs, especially for sites that rely heavily on pseudo-static URLs or complex routing. Platinum Promotions
afdsfds Email
2025-11-27 15:35
I’m going to read this. I’ll be sure to come back. thanks for sharing. and also This article gives the light in which we can observe the reality. this is very nice one and gives indepth information. thanks for this nice article...  Slot Qris  I read a article under the same title some time ago, but this articles quality is much, much better. How you do this..  board game illustration
DSFDSFDS Email
2025-11-29 15:42
It was wondering if I could use this write-up on my other website, I will link it back to your website though.Great Thanks.  mawartoto togel
dsgsd Email
2025-11-29 23:09
Private Transfer Geneva to Méribel offers exclusive, comfortable transportation from Geneva Airport directly to the Méribel ski resort. With professional drivers, personalized pickup times, and spacious vehicles for luggage and ski equipment, it ensures a smooth, stress-free journey. Ideal for families, groups, or solo travelers seeking privacy, convenience, and reliable mountain transfers  Private transfer Geneva to Meribel
dsgsd Email
2025-11-29 23:12
Akses bermain di sakongtoto kini semakin mudah berkat sistem yang dirancang untuk memberikan kenyamanan maksimal bagi setiap pemain. Platform ini hadir dengan fitur lengkap serta tampilan modern sehingga aktivitas memilih pasaran maupun memasang angka dapat dilakukan tanpa hambatan.  sakongtoto
ASDFFDS Email
2025-11-30 17:24
Recently, I have commenced a blog the info you give on this site has encouraged and benefited me hugely. Thanks for all of your time & work.  teslatoto
RecruitWest
2025-12-2 23:38
Here at RecruitWest, we understand the importance of forklift operator jobs in our business and the huge and positive impact they have on our nation's growth. forklift operator jobs
分页: 24/25 第一页 上页 19 20 21 22 23 24 25 下页 最后页
发表评论
表情
emotemotemotemotemot
emotemotemotemotemot
emotemotemotemotemot
emotemotemotemotemot
emotemotemotemotemot
打开HTML
打开UBB
打开表情
隐藏
记住我
昵称   密码   游客无需密码
网址   电邮   [注册]