×î½ü¼¸Ä꣬Web¹¥»÷ÊֶοªÊ¼±äµÃ¸´ÔÓ£¬¹¥»÷ÃæÒ²Ô½À´Ô½¹ã¡£´«Í³µÄ°²È«·À»¤ÊֶΣ¬WAF¡¢IDS µÈµÈ£¬´ó¶àÊÇ»ùÓÚ¹æÔò£¬ÒѾ²»ÄÜÂú×ãÆóÒµ¶Ô°²È«µÄ»ù±¾ÐèÇó¡£Gartner ÔÚ2014ÄêÌá³öÁË "Ó¦ÓÃ×ÔÎÒ±£»¤" ¼¼ÊõµÄ¸ÅÄ¼´ "¶ÔÓ¦Ó÷þÎñµÄ±£»¤£¬²»Ó¦¸ÃÒÀÀµÓÚÍⲿϵͳ£»Ó¦ÓÃÓ¦¸Ã¾ß±¸×ÔÎÒ±£»¤µÄÄÜÁ¦"¡£
Ϊ´Ë£¬°Ù¶ÈÍÆ³öÁË¿ªÔ´µÄ×ÔÊÊÓ¦°²È«²úÆ· -- OpenRASP£¬Ï£Íûͨ¹ý¿ªÔ´Ãâ·ÑµÄÐÎʽ£¬Èøü¶àµÄÈ˲ÎÓë½øÀ´£¬²¢Èû¥ÁªÍø±äµÃ¸ü¼Ó°²È«¡£
ÏÖÔÚ£¬OpenRASP ÒÑ·¢²¼ 0.20 °æ±¾¡£·¢²¼Ê±¼ä£º2017.10.26
ÖØ´ó±ä¸ü
ÐÔÄÜÓÅ»¯
ÓÉÓÚ jni ÐÔÄÜÌ«²î£¬ÎÒÃǾö¶¨Ê¹Óà Mozilla Rhino ×îÐÂ°æ±¾Ìæ»»µô j2v8
ÔÚ×µÄÇé¿öÏ£¬¶Ô·þÎñÆ÷Ó°ÏìÔÚ 2% ×óÓÒ£¬¾ßÌå¿É²é¿´ÐÔÄܲâÊÔ±¨¸æ
·ÅÆú¶Ô WebLogic µÄÖ§³Ö
API ±ä¸ü
Ôö¼Ó SQL tokenize ½Ó¿Ú: RASP.sql_tokenize
Ôö¼Ó SESSION Ð޸ĽӿÚ: context.session.getSession / context.session.setSession
readFile ½Ó¿Ú£¬µ±Îļþ²»´æÔÚʱ£¬½«²»ÔÙµ÷Óòå¼þ
Hook µã±ä¸ü
Ôö¼Ó webdav hook µã£¬¿É¼ì²é MOVE¡¢COPY ²Ù×÷
À¹½ØÈÕÖ¾±ä¸ü
Ôö¼Ó HTTP Referer ×Ö¶Î
Ôö¼Ó request_id ²ÎÊý£¬ÓÃÓÚ±êʶһ¸ö¹¥»÷
Ôö¼Ó event_type ×ֶΣ¬ÓÃÓÚ±êÖ¾ÈÕÖ¾ÀàÐÍ
attack_time ×ֶθÄÃûΪ event_time
attack_params ×ֶθÄΪ JSON ÐÎʽ£¨ÒÔǰÊÇ×Ö·û´®£¬ÐèÒªÖØÐÂÅäÖÃES mapping)
ÐÂÔö¹¦ÄÜ
Ö§³Ö×Ô¶¨ÒåÀ¹½ØÒ³Ãæ
ͨ¹ý block.url ÅäÖÃ
ĬÈÏÊÇС¿ÖÁúÒ³Ãæ
Ôö¼Ó·þÎñÆ÷°²È«»ùÏß¼ì²é¹¦ÄÜ£¬Ä¿Ç°½öÖ§³Ö tomcat
manager/html Èõ¿ÚÁî
JSESSION 먦Æô httpOnly
tomcatÒÔrootÆô¶¯
ĬÈ쵀 webapps ûÓÐɾ³ý
µ±·¢Éú¹¥»÷£¬²å¼þ»á¶îÍâÊä³ö confidence ×ֶΣ¬ÓÃÓÚ±êʶ¼ì²â½á¹û¿É¿¿ÐÔ
ËùÓÐÏìÓ¦Ôö¼Ó X-Protected-By: OpenRASP ÏìӦͷ
Ö§³Ö HTTP ±¨¾¯ÍÆËÍ
Ôö¼Ó¶Ô Jetty¡¢JBoss 5~6 ·þÎñÆ÷µÄÖ§³Ö
Ôö¼Ó log.maxstack ÅäÖÃÑ¡ÏÓÃÓÚÅäÖà alarm ÈÕÖ¾Àï×î´ó¶ÑÕ»
Èí¼þÏêÇ飺https://github.com/baidu/openrasp/releases/tag/v0.20
ÏÂÔØµØÖ·£ºhttp://gitee.com/mirrors/OpenRASP
À´×Ô:¿ªÔ´ÖйúÉçÇø
                  	
				
