ºìÁªLinuxÃÅ»§
Linux°ïÖú

OpenRASP·¢²¼0.20°æ±¾£¬Ó¦ÓÃ×ÔÎÒ±£»¤°²È«½â¾ö·½°¸

·¢²¼Ê±¼ä:2017-10-27 09:07:27À´Ô´:ºìÁª×÷Õß:baihuo
×î½ü¼¸Ä꣬Web¹¥»÷ÊֶοªÊ¼±äµÃ¸´ÔÓ£¬¹¥»÷ÃæÒ²Ô½À´Ô½¹ã¡£´«Í³µÄ°²È«·À»¤ÊֶΣ¬WAF¡¢IDS µÈµÈ£¬´ó¶àÊÇ»ùÓÚ¹æÔò£¬ÒѾ­²»ÄÜÂú×ãÆóÒµ¶Ô°²È«µÄ»ù±¾ÐèÇó¡£Gartner ÔÚ2014ÄêÌá³öÁË "Ó¦ÓÃ×ÔÎÒ±£»¤" ¼¼ÊõµÄ¸ÅÄ¼´ "¶ÔÓ¦Ó÷þÎñµÄ±£»¤£¬²»Ó¦¸ÃÒÀÀµÓÚÍⲿϵͳ£»Ó¦ÓÃÓ¦¸Ã¾ß±¸×ÔÎÒ±£»¤µÄÄÜÁ¦"¡£

Ϊ´Ë£¬°Ù¶ÈÍÆ³öÁË¿ªÔ´µÄ×ÔÊÊÓ¦°²È«²úÆ· -- OpenRASP£¬Ï£Íûͨ¹ý¿ªÔ´Ãâ·ÑµÄÐÎʽ£¬Èøü¶àµÄÈ˲ÎÓë½øÀ´£¬²¢Èû¥ÁªÍø±äµÃ¸ü¼Ó°²È«¡£

ÏÖÔÚ£¬OpenRASP ÒÑ·¢²¼ 0.20 °æ±¾¡£·¢²¼Ê±¼ä£º2017.10.26

ÖØ´ó±ä¸ü

ÐÔÄÜÓÅ»¯

ÓÉÓÚ jni ÐÔÄÜÌ«²î£¬ÎÒÃǾö¶¨Ê¹Óà Mozilla Rhino ×îÐÂ°æ±¾Ìæ»»µô j2v8

ÔÚ×µÄÇé¿öÏ£¬¶Ô·þÎñÆ÷Ó°ÏìÔÚ 2% ×óÓÒ£¬¾ßÌå¿É²é¿´ÐÔÄܲâÊÔ±¨¸æ

·ÅÆú¶Ô WebLogic µÄÖ§³Ö

API ±ä¸ü

Ôö¼Ó SQL tokenize ½Ó¿Ú: RASP.sql_tokenize

Ôö¼Ó SESSION Ð޸ĽӿÚ: context.session.getSession / context.session.setSession

readFile ½Ó¿Ú£¬µ±Îļþ²»´æÔÚʱ£¬½«²»ÔÙµ÷Óòå¼þ

Hook µã±ä¸ü

Ôö¼Ó webdav hook µã£¬¿É¼ì²é MOVE¡¢COPY ²Ù×÷

À¹½ØÈÕÖ¾±ä¸ü

Ôö¼Ó HTTP Referer ×Ö¶Î

Ôö¼Ó request_id ²ÎÊý£¬ÓÃÓÚ±êʶһ¸ö¹¥»÷

Ôö¼Ó event_type ×ֶΣ¬ÓÃÓÚ±êÖ¾ÈÕÖ¾ÀàÐÍ

attack_time ×ֶθÄÃûΪ event_time

attack_params ×ֶθÄΪ JSON ÐÎʽ£¨ÒÔǰÊÇ×Ö·û´®£¬ÐèÒªÖØÐÂÅäÖÃES mapping)

ÐÂÔö¹¦ÄÜ

Ö§³Ö×Ô¶¨ÒåÀ¹½ØÒ³Ãæ

ͨ¹ý block.url ÅäÖÃ

ĬÈÏÊÇС¿ÖÁúÒ³Ãæ

Ôö¼Ó·þÎñÆ÷°²È«»ùÏß¼ì²é¹¦ÄÜ£¬Ä¿Ç°½öÖ§³Ö tomcat

manager/html Èõ¿ÚÁî

JSESSION 먦Æô httpOnly

tomcatÒÔrootÆô¶¯

ĬÈ쵀 webapps ûÓÐɾ³ý

µ±·¢Éú¹¥»÷£¬²å¼þ»á¶îÍâÊä³ö confidence ×ֶΣ¬ÓÃÓÚ±êʶ¼ì²â½á¹û¿É¿¿ÐÔ

ËùÓÐÏìÓ¦Ôö¼Ó X-Protected-By: OpenRASP ÏìӦͷ

Ö§³Ö HTTP ±¨¾¯ÍÆËÍ

Ôö¼Ó¶Ô Jetty¡¢JBoss 5~6 ·þÎñÆ÷µÄÖ§³Ö

Ôö¼Ó log.maxstack ÅäÖÃÑ¡ÏÓÃÓÚÅäÖà alarm ÈÕÖ¾Àï×î´ó¶ÑÕ»

Èí¼þÏêÇ飺https://github.com/baidu/openrasp/releases/tag/v0.20

ÏÂÔØµØÖ·£ºhttp://gitee.com/mirrors/OpenRASP

À´×Ô:¿ªÔ´ÖйúÉçÇø
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ