ืžื‘ื ื” ื—ื“ืฉ ืฉืœ Nemesida WAF Free ืขื‘ื•ืจ NGINX

ืžื‘ื ื” ื—ื“ืฉ ืฉืœ Nemesida WAF Free ืขื‘ื•ืจ NGINX
ื‘ืฉื ื” ืฉืขื‘ืจื” ืฉื—ืจืจื ื• ืืช Nemesida WAF Free, ืžื•ื“ื•ืœ ื“ื™ื ืžื™ ืขื‘ื•ืจ NGINX ืฉื—ื•ืกื ื”ืชืงืคื•ืช ืขืœ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜. ื‘ื ื™ื’ื•ื“ ืœื’ืจืกื” ื”ืžืกื—ืจื™ืช, ื”ืžื‘ื•ืกืกืช ืขืœ ืœืžื™ื“ืช ืžื›ื•ื ื”, ื”ื’ืจืกื” ื”ื—ื™ื ืžื™ืช ืžื ืชื—ืช ื‘ืงืฉื•ืช ืจืง ื‘ืฉื™ื˜ืช ื”ื—ืชื™ืžื”.

ืชื›ื•ื ื•ืช ืฉืœ ืฉื—ืจื•ืจ Nemesida WAF 4.0.129

ืœืคื ื™ ื”ืžื”ื“ื•ืจื” ื”ื ื•ื›ื—ื™ืช, ื”ืžื•ื“ื•ืœ ื”ื“ื™ื ืžื™ Nemesida WAF ืชืžืš ืจืง ื‘-Nginx Stable 1.12, 1.14 ื•-1.16. ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ืžื•ืกื™ืคื” ืชืžื™ื›ื” ื‘-Nginx Mainline, ื”ื—ืœ ืž-1.17, ื•-Nginx Plus, ื”ื—ืœ ืž-1.15.10 (R18).

ืœืžื” ืœืขืฉื•ืช ืขื•ื“ WAF?


NAXSI ื•-mod_security ื”ื ื›ื ืจืื” ืžื•ื“ื•ืœื™ ื”-WAF ื”ื—ื™ื ืžื™ื™ื ื”ืคื•ืคื•ืœืจื™ื™ื ื‘ื™ื•ืชืจ, ื•-mod_security ืžืงื•ื“ื ื‘ืื•ืคืŸ ืคืขื™ืœ ืขืœ ื™ื“ื™ Nginx, ืื ื›ื™ ื‘ืชื—ื™ืœื” ื ืขืฉื” ื‘ื• ืฉื™ืžื•ืฉ ืจืง ื‘-Apache2. ืฉื ื™ ื”ืคืชืจื•ื ื•ืช ื”ื ื—ื™ื ืžื™ื™ื, ืงื•ื“ ืคืชื•ื— ื•ื™ืฉ ืœื”ื ืžืฉืชืžืฉื™ื ืจื‘ื™ื ื‘ืจื—ื‘ื™ ื”ืขื•ืœื. ืขื‘ื•ืจ mod_security, ืขืจื›ื•ืช ื—ืชื™ืžื•ืช ื‘ื—ื™ื ื ื•ืžืกื—ืจื™ื•ืช ื–ืžื™ื ื•ืช ืชืžื•ืจืช 500$ ืœืฉื ื”, ืขื‘ื•ืจ NAXSI ื™ืฉ ืกื˜ ื—ืชื™ืžื•ืช ื—ื™ื ื ืžื”ืงื•ืคืกื”, ื•ืชื•ื›ืœื• ืœืžืฆื•ื ื’ื ืกื˜ื™ื ื ื•ืกืคื™ื ืฉืœ ื›ืœืœื™ื, ื›ืžื• doxsi.

ื”ืฉื ื” ื‘ื“ืงื ื• ืืช ื”ืคืขื•ืœื” ืฉืœ NAXSI ื•ืฉืœ Nemesida WAF Free. ื‘ืงืฆืจื” ืขืœ ื”ืชื•ืฆืื•ืช:

  • NAXSI ืื™ื ื• ืžื‘ืฆืข ืคืขื ื•ื— ื›ืคื•ืœ ืฉืœ ื›ืชื•ื‘ืช URL ื‘ืงื•ื‘ืฆื™ Cookie
  • ืœ-NAXSI ืœื•ืงื— ื”ืจื‘ื” ืžืื•ื“ ื–ืžืŸ ืœื”ื’ื“ื™ืจ - ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ื’ื“ืจื•ืช ื›ืœืœ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื™ื—ืกืžื• ืืช ืจื•ื‘ ื”ื‘ืงืฉื•ืช ื‘ืขื‘ื•ื“ื” ืขื ื™ื™ืฉื•ื ืื™ื ื˜ืจื ื˜ (ื”ืจืฉืื”, ืขืจื™ื›ืช ืคืจื•ืคื™ืœ ืื• ื—ื•ืžืจ, ื”ืฉืชืชืคื•ืช ื‘ืกืงืจื™ื ื•ื›ื•') ื•ื™ืฉ ืฆื•ืจืš ืœื™ืฆื•ืจ ืจืฉื™ืžื•ืช ื—ืจื™ื’ื™ื , ืžื” ืฉืžืฉืคื™ืข ืœืจืขื” ืขืœ ื”ืื‘ื˜ื—ื”. Nemesida WAF Free ืขื ื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืœื ื‘ื™ืฆืขื” ื•ืœื• ื—ื™ื•ื‘ื™ ืฉื’ื•ื™ ืื—ื“ ื‘ื–ืžืŸ ื”ืขื‘ื•ื“ื” ืขื ื”ืืชืจ.
  • ืžืกืคืจ ื”ื”ืชืงืคื•ืช ืฉื”ื•ื—ืžืฆื• ืขื‘ื•ืจ NAXSI ื’ื‘ื•ื” ืคื™ ื›ืžื”, ื•ื›ื•'.

ืœืžืจื•ืช ื”ื—ืกืจื•ื ื•ืช, ืœ-NAXSI ื•ืœ-mod_security ื™ืฉ ืœืคื—ื•ืช ืฉื ื™ ื™ืชืจื•ื ื•ืช - ืงื•ื“ ืคืชื•ื— ื•ืžืกืคืจ ืจื‘ ืฉืœ ืžืฉืชืžืฉื™ื. ืื ื• ืชื•ืžื›ื™ื ื‘ืจืขื™ื•ืŸ ืœื—ืฉื•ืฃ ืืช ืงื•ื“ ื”ืžืงื•ืจ, ืืš ืื™ื ื ื• ื™ื›ื•ืœื™ื ืœืขืฉื•ืช ื–ืืช ืขื“ื™ื™ืŸ ืขืงื‘ ื‘ืขื™ื•ืช ืืคืฉืจื™ื•ืช ืขื "ืคื™ืจืื˜ื™ื•ืช" ืฉืœ ื”ื’ืจืกื” ื”ืžืกื—ืจื™ืช, ืืš ื›ื“ื™ ืœืคืฆื•ืช ืขืœ ื—ืกืจื•ืŸ ื–ื”, ืื ื• ื—ื•ืฉืคื™ื ื‘ืžืœื•ืื ืืช ืชื•ื›ืŸ ืขืจื›ืช ื”ื—ืชื™ืžื•ืช. ืื ื• ืžืขืจื™ื›ื™ื ืคืจื˜ื™ื•ืช ื•ืžืฆื™ืขื™ื ืœืš ืœืืžืช ื–ืืช ื‘ืขืฆืžืš ื‘ืืžืฆืขื•ืช ืฉืจืช ืคืจื•ืงืกื™.

ืชื›ื•ื ื•ืช ืฉืœ Nemesida WAF Free:

  • ืžืกื“ ื ืชื•ื ื™ื ืื™ื›ื•ืชื™ ืฉืœ ื—ืชื™ืžื•ืช ืขื ืžืกืคืจ ืžื™ื ื™ืžืœื™ ืฉืœ ื—ื™ื•ื‘ื™ ื›ื•ื–ื‘ ื•ืฉืœื™ืœื™ ื›ื•ื–ื‘.
  • ื”ืชืงื ื” ื•ืขื“ื›ื•ืŸ ืžื”ืžืื’ืจ (ื–ื” ืžื”ื™ืจ ื•ื ื•ื—);
  • ืื™ืจื•ืขื™ื ืคืฉื•ื˜ื™ื ื•ืžื•ื‘ื ื™ื ืขืœ ืชืงืจื™ื•ืช, ื•ืœื "ื‘ืœื’ืŸ" ื›ืžื• NAXSI;
  • ื‘ื—ื™ื ื ืœื—ืœื•ื˜ื™ืŸ, ืื™ืŸ ื”ื’ื‘ืœื•ืช ืขืœ ื›ืžื•ืช ื”ืชืขื‘ื•ืจื”, ืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ื•ื›ื•'.

ืœืกื™ื›ื•ื, ืืชืŸ ืžืกืคืจ ืฉืื™ืœืชื•ืช ืœื”ืขืจื›ืช ื”ื‘ื™ืฆื•ืขื™ื ืฉืœ WAF (ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ื• ื‘ื›ืœ ืื—ื“ ืžื”ืื–ื•ืจื™ื: URL, ARGS, Headers & Body):

')) un","ion se","lect 1,2,3,4,5,6,7,8,9,0,11#"] ')) union/**/select/**/1,/**/2,/**/3,/**/4,/**/5,/**/6,/**/7,/**/8,/**/9,/**/'some_text',/**/11#"] union(select(1),2,3,4,5,6,7,8,9,0x70656e746573746974,11)#"] ')) union+/*!select*/ (1),(2),(3),(4),(5),(6),(7),(8),(9),(0x70656e746573746974),(11)#"] ')) /*!u%6eion*/ /*!se%6cect*/ (1),(2),(3),(4),(5),(6),(7),(8),(9.),(0x70656e746573746974),(11)#"] ')) %2f**%2funion%2f**%2fselect (1),(2),(3),(4),(5),(6),(7),(8),(9),(0x70656e746573746974),(11)#"] %5B%221807182982%27%29%29%20uni%22%2C%22on
%20sel%22%2C%22ect%201%2C2%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C%2some_text%27%2C11%23%22%5D
cat /et?/pa?swd
cat /et'c/pa'ss'wd
cat /et*/pa**wd
e'c'ho 'swd test pentest' |awk '{print "cat /etc/pas"$1}' |bas'h
cat /etc/passwd
cat$u+/etc$u/passwd$u
<svg/onload=alert()//

ืื ื”ื‘ืงืฉื•ืช ืœื ื™ื™ื—ืกืžื•, ืกื‘ื™ืจ ืœื”ื ื™ื— ืฉื”-WAF ื™ื—ืžื™ืฅ ืืช ื”ืžืชืงืคื” ื”ืืžื™ืชื™ืช. ืœืคื ื™ ื”ืฉื™ืžื•ืฉ ื‘ื“ื•ื’ืžืื•ืช, ื•ื“ื ืฉื”-WAF ืื™ื ื• ื—ื•ืกื ื‘ืงืฉื•ืช ืœื’ื™ื˜ื™ืžื™ื•ืช.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”