Kuburitswa kwe lighttpd 1.4.54 http server ine URL normalization yakagoneswa

rakabudiswa kuburitswa kweakareruka http server lighttpd 1.4.54. Iyo vhezheni nyowani inoratidzira 149 shanduko, kunyanya kuisirwa kweiyo URL normalization nekukasira, rework ye mod_webdav, uye performance optimization basa.

Kubva lighttpd 1.4.54 zvachinja Maitiro eSeva ane hukama neURL yekumisikidza paunenge uchigadzirisa zvikumbiro zveHTTP. Sarudzo dzekutarisa kwakasimba kwehunhu mumusoro weHost inobatiswa, kujairana kwezvinongedzo zvinotumirwa mumisoro uye kuvharika kwezvinongedzo neasina kupukunyuka kudzora mavara kunogoneswa zvakare. Iyo normalization process inosanganisira otomatiki shanduko ye '\' kuenda ku '/', '%2F' kuenda ku '/', '%20' kuenda '+', kugadzirisa uye kubviswa kwezvikamu zvenzira dzefaira ne '.' madhairekitori. uye '..', kugadzirisa mavara akatiza '-', '.', '_' uye '~'.

Kana uchida, iyo URL yekugadzirisa maitiro inogona kuchinjwa muzvirongwa uchishandisa sarudzo "header-strict", "host-strict", "host-normalize", "url-normalize", "url-normalize-unreserved", "url -normalize-inodiwa" ",
"url-ctrls-reject", "url-path-2f-decode", "url-path-dotseg-remove" uye "url-query-20-plus", izvo zvino zvakagadzirirwa "kugonesa".

Dzimwe shanduko dzinosanganisira kugadziridza kwakazara kwemodhi_webdav module, iyo yakaita kuti zvikwanise kuzadzisa kuenderana kwakazara nezvakatsanangurwa, kuvandudza mashandiro uye kuvimbika. Pakati pekuenderana-kutyora shanduko kune mod_webdav kuvharika kwezvisina kukwana zvikumbiro zvePUT. Mod_auth inowedzera tsigiro yeSHA-256 algorithm yehashing authentication paramita (HTTP Auth Digest).
A new module, mod_maxminddb, yakakurudzirwa kutsiva mod_geoip (mod_geoip ikozvino yaregwa).

Source: opennet.ru

Voeg