å¤æ©è½ãªã¦ã§ããµã¼ãã¼ã¨ãã¦2004å¹´ã«ç»å ´ããNginxã¯ã2023å¹´6ææç¹ã§ã¯æ¥çãããã·ã§ã¢ã¨ãªãã»ã©äººæ°ãéãããµã¼ãã¼ã§ãããããªNginxã®è¨å®ã«ããã¦ãã¹ã©ãã·ã¥ãä¸ã¤ä»ãããä»ããªããã®å·®ã§å¤§ããªã»ãã¥ãªãã£ãã¼ã«ãã§ãã¦ãã¾ãåé¡ã«ã¤ãã¦ã大æãã¹ã¯ã¼ãããã¼ã¸ã£ã¼ãGoogle製ã®ãã¼ã«ã®ä¾ãã¨ãããã¦ã»ãã¥ãªãã£ã¢ããªã¹ãã®ããã¨ã«ã»ããã¢ããããããã°ã§è§£èª¬ãã¦ãã¾ãã Hunting for Nginx Alias Traversals in the wild https://labs.hakaioffsec.com/nginx-alias-traversal/ Nginxã®è¨å®ã«ã¯ãç¹å®ã®URLã¸ã®ã¢ã¯ã»ã¹ãã©ãå¦çããã¹ãããè¨è¿°ã§ãããlocationãã¨ãããã£ã¬ã¯ãã£ããåå¨ãã¦ãããURLããµã¼ãã¼å ã®ãã¡ã¤ã«ã«å¯¾å¿ãããã®ã«ããå©ç¨ããã¦ãã¾ããä¾
{{#tags}}- {{label}}
{{/tags}}