最新的 naxsi 模块是不是有问题呢

2015-12-28 14:37:06 +08:00
 mrbaiwei
2015/12/28 14:09:06 [debug] 14757#0: *4924 is rule [1007] whitelisted in zone ARGS for item attack
2015/12/28 14:09:06 [debug] 14757#0: *4924 extra: exception happened in |NAME
2015/12/28 14:09:06 [debug] 14757#0: *4924 rule 1007 is disabled somewhere
2015/12/28 14:09:06 [debug] 14757#0: *4924 hashing varname [attack]
2015/12/28 14:09:06 [debug] 14757#0: *4924 hashing varname attack - 'wl:X_VAR:attack'
2015/12/28 14:09:06 [debug] 14757#0: *4924 hashing varname attack - 'wl:X_VAR:attack|NAME'
2015/12/28 14:09:06 [debug] 14757#0: *4924 hashing uri#1 / ($URL:X|URI)
2015/12/28 14:09:06 [debug] 14757#0: *4924 hashing uri#3 #/ ($URL:X|ZONE|NAME)
2015/12/28 14:09:06 [debug] 14757#0: *4924 hashing MIX #/#attack or ($URL:x|$X_VAR:y|NAME)
2015/12/28 14:09:06 [error] 14757#0: *4924 NAXSI_FMT: ip=1.1.1.1&server=www.x.com&uri=/&learning=0&vers=0.54&total_processed=726&total_blocked=10&block=1&cscore0=$SQL&score0=8&zone0=ARGS|NAME&id0=1007&var_name0=attack, client: 1.1.1.1, server: localhost, request: "HEAD /?attack=1 HTTP/1.0", host: "www. x.com"

MainRule "str:attack" "msg:ddos" "mz:ARGS|BODY" "s:$SQL:8" id:1007;
BasicRule wl:1007;
白名单无效, nginx 版本是 1.8.0
naxsi https://github.com/nbs-system/naxsi
1699 次点击
所在节点    问与答
0 条回复

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/246669

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX