GSA / GSA/ansible-https-proxy

Disable Unwanted HTTP Methods in NGINX

Ouverte
#11 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
Aucune donnée de langage
Étoiles
10
Forks
5
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

>Draft CIS Benchmark 1.1.12

## Description
HTTP methods (or verbs) allow for different actions to be requested from the web server at a specified path.

## Rationale
Most web sites only require `GET`, `POST` and `HEAD` to function correctly. Web applications may also require other verbs (e.g. `DELETE`). In order to narrow vectors of attack, it is recommended to only enable the required verbs.

## Remediation
To remove unneeded methods and only allow `GET`, `POST` and `HEAD` (for example), add the following in to a `server` block in your `nginx.conf`. The reason for 444 as a response is because it contains no information and can help mitigate automated attacks. ``` if ($request_method !~ ^(GET|HEAD|POST)$) { return 444; } ```

## Audit
Use a tool like curl to send a request with a method which should not be supported (e.g. `DELETE`) and compare the output to a supported method (e.g. `GET`). ``` # curl -X DELETE http://localhost/index.html curl: (52) Empty reply from server # curl -X GET http://localhost/index.html .... ```

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.