GSA / GSA/ansible-https-proxy

Disable Unwanted HTTP Methods in NGINX

未关闭
#11 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
没有语言数据
星标
10
派生
5
PR 合并指标
30 天内没有已合并 PR

描述

>Draft CIS Benchmark 1.1.12

## Description
HTTP methods (or verbs) allow for different actions to be requested from the web server at a specified path.

## Rationale
Most web sites only require `GET`, `POST` and `HEAD` to function correctly. Web applications may also require other verbs (e.g. `DELETE`). In order to narrow vectors of attack, it is recommended to only enable the required verbs.

## Remediation
To remove unneeded methods and only allow `GET`, `POST` and `HEAD` (for example), add the following in to a `server` block in your `nginx.conf`. The reason for 444 as a response is because it contains no information and can help mitigate automated attacks. ``` if ($request_method !~ ^(GET|HEAD|POST)$) { return 444; } ```

## Audit
Use a tool like curl to send a request with a method which should not be supported (e.g. `DELETE`) and compare the output to a supported method (e.g. `GET`). ``` # curl -X DELETE http://localhost/index.html curl: (52) Empty reply from server # curl -X GET http://localhost/index.html .... ```

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。