GSA / GSA/ansible-https-proxy

Disable Unwanted HTTP Methods in NGINX

Abierto
#11 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Sin datos de lenguaje
Estrellas
10
Forks
5
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

>Draft CIS Benchmark 1.1.12

## Description
HTTP methods (or verbs) allow for different actions to be requested from the web server at a specified path.

## Rationale
Most web sites only require `GET`, `POST` and `HEAD` to function correctly. Web applications may also require other verbs (e.g. `DELETE`). In order to narrow vectors of attack, it is recommended to only enable the required verbs.

## Remediation
To remove unneeded methods and only allow `GET`, `POST` and `HEAD` (for example), add the following in to a `server` block in your `nginx.conf`. The reason for 444 as a response is because it contains no information and can help mitigate automated attacks. ``` if ($request_method !~ ^(GET|HEAD|POST)$) { return 444; } ```

## Audit
Use a tool like curl to send a request with a method which should not be supported (e.g. `DELETE`) and compare the output to a supported method (e.g. `GET`). ``` # curl -X DELETE http://localhost/index.html curl: (52) Empty reply from server # curl -X GET http://localhost/index.html .... ```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.