{"id":109263,"date":"2023-07-05T21:10:21","date_gmt":"2023-07-05T19:10:24","guid":{"rendered":"https:\/\/prohoster.info\/?p=109263"},"modified":"2023-07-06T09:41:50","modified_gmt":"2023-07-06T07:41:50","slug":"uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","title":{"rendered":"Vulnerabilit\u00e0 delle configurazioni Nginx con impostazioni errate del blocco alias","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Alcuni server con nginx rimangono vulnerabili alla tecnica Nginx Alias Traversal, proposta alla conferenza Blackhat nel 2018, che consente di accedere a file e directory situati al di fuori della directory radice definita nella direttiva \"alias\". Il problema si manifesta solo nelle configurazioni con la direttiva \"alias\" posizionata all'interno di un blocco \"location\", il cui parametro non termina con il carattere \"\/\", mentre l'\"alias\" termina con \"\/\".      <center><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 delle configurazioni Nginx con impostazioni errate del blocco alias\" src=\"\/wp-content\/uploads\/2023\/07\/8e1c72da230a72b8a9274bf67728bfed.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>La questione principale \u00e8 che i file per i blocchi con la direttiva alias vengono restituiti tramite l'aggiunta del percorso richiesto, dopo averlo confrontato con la maschera della direttiva location e rimuovendo la parte di percorso specificata in quella maschera. Per l'esempio mostrato sopra, in una configurazione vulnerabile, un attaccante pu\u00f2 richiedere il file \"\/img....\/test.txt\" e questa richiesta rientrer\u00e0 nella maschera specificata in location \"\/img\", dopo di che la parte rimanente \"....\/test.txt\" verr\u00e0 aggiunta al percorso della direttiva alias \"\/var\/images\/\" e alla fine verr\u00e0 richiesto il file \"\/var\/images\/....\/test.txt\". Cos\u00ec, un attaccante pu\u00f2 accedere a qualsiasi file nella directory \"\/var\", non solo ai file in \"\/var\/images\/\", ad esempio, per caricare il log di nginx pu\u00f2 inviare la richiesta \"\/img....\/log\/nginx\/access.log\".    <\/p>\n<p>Nelle configurazioni in cui il valore della direttiva alias non termina con il carattere \"\/\" (ad esempio, \"alias \/var\/images;\"), l'attaccante non pu\u00f2 accedere alla directory genitore, ma pu\u00f2 comunque richiedere un'altra directory in \/var, il cui nome inizia con quello specificato nella configurazione. Ad esempio, richiedendo \"\/img.old\/test.txt\" si pu\u00f2 accedere alla directory \"var\/images.old\/test.txt\".    <\/p>\n<p>Un'analisi dei repository su GitHub ha mostrato che gli errori di configurazione che portano a questo problema si riscontrano ancora in progetti reali. Ad esempio, \u00e8 stata rilevata la presenza del problema nel backend del gestore di password Bitwarden e avrebbe potuto essere utilizzato per accedere a tutti i file nella directory \/etc\/bitwarden (le richieste \/attachments venivano restituite da \/etc\/bitwarden\/attachments\/), inclusa la base di dati con le password \"vault.db\", i certificati e i log, per i quali era sufficiente inviare richieste \"attachments....\/vault.db\", \"attachments....\/identity.pfx\", \"attachments....\/logs\/api.log\" e cos\u00ec via.          <center><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 delle configurazioni Nginx con impostazioni errate del blocco alias\" src=\"\/wp-content\/uploads\/2023\/07\/b62a7b7a643154f3bfa97aa382912ff4.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>  <center><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 delle configurazioni Nginx con impostazioni errate del blocco alias\" src=\"\/wp-content\/uploads\/2023\/07\/369fe9d1583496261ba60c70e788958e.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Il metodo ha funzionato anche con Google HPC Toolkit, in cui le richieste \/static venivano reindirizzate nella cartella \"..\/hpc-toolkit\/community\/front-end\/website\/static\/\". Per ottenere il database con la chiave segreta e le credenziali, l'attaccante poteva inviare richieste \" \/static..\/.secret_key\" e \" \/static..\/db.sqlite3\".  <center><img decoding=\"async\" alt=\"Vulnerabilit\u00e0 delle configurazioni Nginx con impostazioni errate del blocco alias\" src=\"\/wp-content\/uploads\/2023\/07\/ad862dad97b14714efad7e72602c1054.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59383\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435 \u043a\u043e\u0440\u043d\u0435\u0432\u043e\u0433\u043e \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430, \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u0433\u043e \u0432 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u0435 &#171;alias&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044f\u0445 \u0441 \u0434\u0438\u0440\u0435\u043a\u0442\u0438\u0432\u043e\u0439 &#171;alias&#187;, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u043e\u0439 \u0432\u043d\u0443\u0442\u0440\u0438 \u0431\u043b\u043e\u043a\u0430 &#171;location&#187;, \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043d\u0435 \u0437\u0430\u0432\u0435\u0440\u0448\u0430\u0435\u0442\u0441\u044f \u043d\u0430 \u0441\u0438\u043c\u0432\u043e\u043b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":109264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-109263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0439 Nginx \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c\u0438 \u0431\u043b\u043e\u043a\u0430 alias | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-07-05T19:10:24+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-07-06T07:41:50+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 delle configurazioni Nginx con impostazioni errate del blocco alias | ProHoster","description":"Alcuni server con nginx rimangono vulnerabili alla tecnica Nginx Alias Traversal, proposta alla conferenza Blackhat nel 2018, che consente l'accesso a file e directory situati al di fuori.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0439 Nginx \u0441 \u043d\u0435\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u044b\u043c\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430\u043c\u0438 \u0431\u043b\u043e\u043a\u0430 alias | ProHoster","og:description":"\u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u0441 nginx \u043e\u0441\u0442\u0430\u044e\u0442\u0441\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u044b \u0434\u043b\u044f \u0442\u0435\u0445\u043d\u0438\u043a\u0438 Nginx Alias Traversal, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0431\u044b\u043b\u0430 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0430 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat \u0435\u0449\u0451 \u0432 2018 \u0433\u043e\u0434\u0443 \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0444\u0430\u0439\u043b\u0430\u043c \u0438 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430\u043c, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u043c \u0432\u043d\u0435.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/uyazvimost-konfiguraczij-nginx-s-nekorrektnymi-nastrojkami-bloka-alias","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-07-05T19:10:24+00:00","article:modified_time":"2023-07-06T07:41:50+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/109263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=109263"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/109263\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media\/109264"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=109263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=109263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=109263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}