Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

上传的压缩包里面包含jsp或exe文件解压会被拦截有办法解决吗? #51

Open
yupd opened this issue Nov 1, 2023 · 5 comments

Comments

@yupd
Copy link

yupd commented Nov 1, 2023

场景是系统升级一般会上传一个zip包,里面包含各种各样的文件。

@jvm-rasp
Copy link
Owner

jvm-rasp commented Nov 1, 2023

拦截的日志发一下

@jvm-rasp
Copy link
Owner

jvm-rasp commented Nov 1, 2023

默认策略不会拦截,只有告警

@yupd
Copy link
Author

yupd commented Nov 1, 2023

拦截的日志发一下

jrasp-attack-0.log

开启 "file_upload_action": 1
实际上传的是个zip包,里面有个 .sha256 后缀的文件命中了 .sh 黑名单就给阻断了。

@yupd
Copy link
Author

yupd commented Nov 1, 2023

我的做法是添加一个允许写入的url白名单,里面把类似上传压缩包的配置白名单,但是感觉不太好,得把业务系统涉及的url都得给穷举出来。

@xl1605368195
Copy link
Collaborator

可以增加url白名单,先解决误报。先不要开阻断,确认没有误报后在开启

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants