{"id":109263,"date":"2023-07-05T21:10:21","date_gmt":"2023-07-05T19:10:24","guid":{"rendered":"https:\/\/prohoster.info\/?p=109263"},"modified":"2023-07-06T09:41:50","modified_gmt":"2023-07-06T07:41:50","slug":"uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","title":{"rendered":"Vulnerabilidad en configuraciones de Nginx con configuraciones incorrectas del bloque alias.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Algunos servidores con nginx siguen siendo vulnerables a la t\u00e9cnica de Nginx Alias Traversal, que fue presentada en la conferencia Blackhat en 2018 y permite el acceso a archivos y directorios que est\u00e1n fuera del directorio ra\u00edz definido en la directiva \u00abalias\u00bb. El problema solo se manifiesta en configuraciones donde la directiva \u00abalias\u00bb est\u00e1 ubicada dentro del bloque \u00ablocation\u00bb y su par\u00e1metro no termina en el s\u00edmbolo \u00ab\/\u00bb, mientras que la \u00abalias\u00bb s\u00ed termina en \u00ab\/\u00bb.      <center><img decoding=\"async\" alt=\"Vulnerabilidad en configuraciones de Nginx con configuraciones incorrectas del bloque alias.\" src=\"\/wp-content\/uploads\/2023\/07\/8e1c72da230a72b8a9274bf67728bfed.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>La esencia del problema es que los archivos para los bloques con la directiva alias se entregan mediante la anexi\u00f3n de la ruta solicitada, despu\u00e9s de su coincidencia con la m\u00e1scara de la directiva de ubicaci\u00f3n y la eliminaci\u00f3n de la parte del camino definida en esta m\u00e1scara. Para el ejemplo mostrado anteriormente de configuraci\u00f3n vulnerable, un atacante puede solicitar el archivo \u00ab\/img..\/test.txt\u00bb y esta solicitud caer\u00e1 bajo la m\u00e1scara \u00ab\/img\u00bb especificada en location, despu\u00e9s de lo cual la parte restante \u00ab..\/test.txt\u00bb se anexar\u00e1 a la ruta de la directiva alias \u00ab\/var\/images\/\u00bb, resultando en la solicitud del archivo \u00ab\/var\/images\/..\/test.txt\u00bb. As\u00ed, los atacantes pueden acceder a cualquier archivo en el directorio \u00ab\/var\u00bb, no solo a los archivos en \u00ab\/var\/images\/\u00bb, por ejemplo, para obtener el log de nginx, se puede enviar la solicitud \u00ab\/img..\/log\/nginx\/access.log\u00bb.    <\/p>\n<p>En configuraciones donde el valor de la directiva alias no termina con el s\u00edmbolo \u00ab\/\u00bb (por ejemplo, \u00abalias \/var\/images;\u00bb), el atacante no puede subir al directorio padre, pero puede solicitar otro directorio en \/var, cuyo nombre comience igual que el especificado en la configuraci\u00f3n. Por ejemplo, al solicitar \u00ab\/img.old\/test.txt\u00bb se puede acceder al directorio \u00abvar\/images.old\/test.txt\u00bb.    <\/p>\n<p>El an\u00e1lisis de repositorios en GitHub ha demostrado que los errores de configuraci\u00f3n que llevan a este problema todav\u00eda se encuentran en proyectos reales. Por ejemplo, se identific\u00f3 la presencia del problema en la parte del servidor del gestor de contrase\u00f1as Bitwarden y pudo ser utilizado para acceder a todos los archivos en el directorio \/etc\/bitwarden (las solicitudes \/attachments se entregaban desde \/etc\/bitwarden\/attachments\/), incluidos la base de datos de contrase\u00f1as \u00abvault.db\u00bb, certificados y logs, para obtener los cuales solo era necesario enviar las solicitudes \u00ab\/attachments..\/vault.db\u00bb, \u00ab\/attachments..\/identity.pfx\u00bb, \u00ab\/attachments..\/logs\/api.log\u00bb, etc.          <center><img decoding=\"async\" alt=\"Vulnerabilidad en configuraciones de Nginx con configuraciones incorrectas del bloque alias.\" src=\"\/wp-content\/uploads\/2023\/07\/b62a7b7a643154f3bfa97aa382912ff4.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>  <center><img decoding=\"async\" alt=\"Vulnerabilidad en configuraciones de Nginx con configuraciones incorrectas del bloque alias.\" src=\"\/wp-content\/uploads\/2023\/07\/369fe9d1583496261ba60c70e788958e.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>El m\u00e9todo tambi\u00e9n funcion\u00f3 con Google HPC Toolkit, donde las solicitudes \\\/static se redirig\u00edan al directorio \"..\\\/hpc-toolkit\\\/community\\\/front-end\\\/website\\\/static\\\/\". Para obtener la base de datos con la clave secreta y las credenciales, el atacante podr\u00eda enviar solicitudes \"\\\/static..\\\/\\.secret_key\" y \"\\\/static..\\\/db.sqlite3\".  <center><img decoding=\"async\" alt=\"Vulnerabilidad en configuraciones de Nginx con configuraciones incorrectas del bloque alias.\" src=\"\/wp-content\/uploads\/2023\/07\/ad862dad97b14714efad7e72602c1054.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59383\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0433\u043e \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430, \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u0435 &#171;alias&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u0441 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u043e\u0439 &#171;alias&#187;, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u043e\u0439 \u0432\u043d\u0443\u0442\u0440\u0438 \u0431\u043b\u043e\u043a\u0430 &#171;location&#187;, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043d\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0430\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0438\u043c\u0432\u043e\u043b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":109264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-109263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0439 Nginx \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c\u0438 \u0431\u043b\u043e\u043a\u0430 alias | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-07-05T19:10:24+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-07-06T07:41:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad de configuraciones Nginx con configuraciones incorrectas del bloque alias | ProHoster","description":"Algunos servidores con nginx siguen siendo vulnerables a la t\u00e9cnica Nginx Alias Traversal, que fue propuesta en la conferencia Blackhat en 2018 y permite acceder a archivos y directorios ubicados fuera de su alcance.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0439 Nginx \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c\u0438 \u0431\u043b\u043e\u043a\u0430 alias | ProHoster","og:description":"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-07-05T19:10:24+00:00","article:modified_time":"2023-07-06T07:41:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/109263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=109263"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/109263\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/109264"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=109263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=109263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=109263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}