{"id":109263,"date":"2023-07-05T21:10:21","date_gmt":"2023-07-05T19:10:24","guid":{"rendered":"https:\/\/prohoster.info\/?p=109263"},"modified":"2023-07-06T09:41:50","modified_gmt":"2023-07-06T07:41:50","slug":"uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","title":{"rendered":"Vuln\u00e9rabilit\u00e9 des configurations Nginx avec des param\u00e8tres de bloc alias incorrects","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Certains serveurs avec nginx restent vuln\u00e9rables \u00e0 la technique Nginx Alias Traversal, qui a \u00e9t\u00e9 propos\u00e9e lors de la conf\u00e9rence Blackhat en 2018, permettant d'acc\u00e9der \u00e0 des fichiers et des r\u00e9pertoires situ\u00e9s en dehors du r\u00e9pertoire racine d\u00e9fini dans la directive \u00ab alias \u00bb. Le probl\u00e8me ne se manifeste que dans les configurations o\u00f9 la directive \u00ab alias \u00bb est situ\u00e9e dans un bloc \u00ab location \u00bb, dont le param\u00e8tre ne se termine pas par le caract\u00e8re \u00ab \/ \u00bb, tandis que \u00ab alias \u00bb se termine par \u00ab \/ \u00bb.      <center><img decoding=\"async\" alt=\"Vuln\u00e9rabilit\u00e9 des configurations Nginx avec des param\u00e8tres de bloc alias incorrects\" src=\"\/wp-content\/uploads\/2023\/07\/8e1c72da230a72b8a9274bf67728bfed.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>L'essence du probl\u00e8me est que les fichiers pour les blocs avec la directive alias sont livr\u00e9s en attachant le chemin demand\u00e9, apr\u00e8s l'avoir mis en correspondance avec le masque de la directive location et en retirant la partie de chemin sp\u00e9cifi\u00e9e dans ce masque. Pour l'exemple de configuration vuln\u00e9rable ci-dessus, un attaquant peut demander le fichier \u00ab \/img..\/test.txt \u00bb et cette demande sera couverte par le masque sp\u00e9cifi\u00e9 dans location \u00ab \/img \u00bb, apr\u00e8s quoi la queue restante \u00ab ..\/test.txt \u00bb sera attach\u00e9e au chemin de la directive alias \u00ab \/var\/images\/ \u00bb et au final le fichier \u00ab \/var\/images\/..\/test.txt \u00bb sera demand\u00e9. Ainsi, les attaquants peuvent acc\u00e9der \u00e0 n'importe quel fichier dans le r\u00e9pertoire \u00ab \/var \u00bb, et pas seulement aux fichiers dans \u00ab \/var\/images\/ \u00bb, par exemple, pour t\u00e9l\u00e9charger le journal nginx, il suffit d'envoyer la demande \u00ab \/img..\/log\/nginx\/access.log \u00bb.    <\/p>\n<p>Dans les configurations o\u00f9 la valeur de la directive alias ne se termine pas par le caract\u00e8re \u00ab \/ \u00bb (par exemple \u00ab alias \/var\/images; \u00bb), l'attaquant ne peut pas remonter au r\u00e9pertoire parent, mais peut demander un autre r\u00e9pertoire dans \/var, dont le nom commence par celui sp\u00e9cifi\u00e9 dans la configuration. Par exemple, en demandant \u00ab \/img.old\/test.txt \u00bb, on peut acc\u00e9der au r\u00e9pertoire \u00ab var\/images.old\/test.txt \u00bb.    <\/p>\n<p>L'analyse des d\u00e9p\u00f4ts sur GitHub a montr\u00e9 que les erreurs de configuration \u00e0 l'origine du probl\u00e8me sont encore pr\u00e9sentes dans des projets r\u00e9els. Par exemple, un probl\u00e8me a \u00e9t\u00e9 identifi\u00e9 dans la partie serveur du gestionnaire de mots de passe Bitwarden et pouvait \u00eatre utilis\u00e9 pour acc\u00e9der \u00e0 tous les fichiers dans le r\u00e9pertoire \/etc\/bitwarden (les demandes \/attachments \u00e9taient servies depuis \/etc\/bitwarden\/attachments\/), y compris la base de donn\u00e9es de mots de passe stock\u00e9e \u00ab vault.db \u00bb, le certificat et les journaux, pour lesquels il suffisait d'envoyer les demandes \u00ab \/attachments..\/vault.db \u00bb, \u00ab \/attachments..\/identity.pfx \u00bb, \u00ab \/attachments..\/logs\/api.log \u00bb, etc.          <center><img decoding=\"async\" alt=\"Vuln\u00e9rabilit\u00e9 des configurations Nginx avec des param\u00e8tres de bloc alias incorrects\" src=\"\/wp-content\/uploads\/2023\/07\/b62a7b7a643154f3bfa97aa382912ff4.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>  <center><img decoding=\"async\" alt=\"Vuln\u00e9rabilit\u00e9 des configurations Nginx avec des param\u00e8tres de bloc alias incorrects\" src=\"\/wp-content\/uploads\/2023\/07\/369fe9d1583496261ba60c70e788958e.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>La m\u00e9thode a \u00e9galement fonctionn\u00e9 avec Google HPC Toolkit, o\u00f9 les requ\u00eates \/static \u00e9taient redirig\u00e9es vers le r\u00e9pertoire \u00ab .. \/hpc-toolkit\/community\/front-end\/website\/static\/ \u00bb. Pour obtenir la base de donn\u00e9es avec la cl\u00e9 secr\u00e8te et les identifiants, l'attaquant pouvait envoyer des requ\u00eates \u00ab \/static.. \/ .secret_key \u00bb et \u00ab \/static.. \/ db.sqlite3 \u00bb.  <center><img decoding=\"async\" alt=\"Vuln\u00e9rabilit\u00e9 des configurations Nginx avec des param\u00e8tres de bloc alias incorrects\" src=\"\/wp-content\/uploads\/2023\/07\/ad862dad97b14714efad7e72602c1054.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59383\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0433\u043e \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430, \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u0435 &#171;alias&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u0441 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u043e\u0439 &#171;alias&#187;, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u043e\u0439 \u0432\u043d\u0443\u0442\u0440\u0438 \u0431\u043b\u043e\u043a\u0430 &#171;location&#187;, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043d\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0430\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0438\u043c\u0432\u043e\u043b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":109264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-109263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0439 Nginx \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c\u0438 \u0431\u043b\u043e\u043a\u0430 alias | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-07-05T19:10:24+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-07-06T07:41:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 des configurations Nginx avec des r\u00e9glages incorrects du bloc alias | ProHoster","description":"Certains serveurs utilisant nginx restent vuln\u00e9rables \u00e0 la technique Nginx Alias Traversal, pr\u00e9sent\u00e9e lors de la conf\u00e9rence Blackhat en 2018, permettant d'acc\u00e9der \u00e0 des fichiers et r\u00e9pertoires plac\u00e9s en dehors.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0439 Nginx \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c\u0438 \u0431\u043b\u043e\u043a\u0430 alias | ProHoster","og:description":"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-07-05T19:10:24+00:00","article:modified_time":"2023-07-06T07:41:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/109263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=109263"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/109263\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media\/109264"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=109263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=109263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=109263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}