簡體   English   中英

來自服務器端安全性掃描程序的上光緩存POST請求

[英]Varnish caching POST requests from Server Side Security scanner

我在Magento ver上經營一個網上商店 2.1.8電子商務平台。

最近,我遇到一個問題,我的網站的前端使用的是完全不同的顏色外觀和布局,無法弄清楚為什么會這樣。

清除Varnish緩存解決了一段時間,因為網站將在一段時間后再次隨機更改外觀。 我不知道Varnish如何緩存不應顯示的內容。

我還將Acunetix用作服務器端掃描程序 ,它每周掃描我的網站是否存在惡意代碼或安全漏洞。 我發現它發送了一個POST請求:

POST /themesettings/index/paneltool/ HTTP/1.1
Content-Length: 1193
Content-Type: multipart/form-data; boundary=-----Boundary_JTWCAHJSKP
Referer: https://www.domain.co.uk/
Cookie: PHPSESSID=sadfq345r234324dfasd; mage-messages= vespaneltool=a%3A6%3A%7Bs%3A52%3A%22ves_themesettings_general%2Fgeneral_settings%2Fdirection%22%3Bs%3A3%3A%22rtl%22%3Bs%3A49%3A%22ves_themesettings_general%2Fgeneral_settings%2Flayout%22%3Bs%3A8%3A%22boxed-lg%22%3Bs%3A52%3A%22ves_themesettings_general%2Fgeneral_settings%2Fmax_width%22%3Bs%3A5%3A%22960px%22%3Bs%3A59%3A%22ves_themesettings_general%2Fgeneral_settings%2Fmax_width_custom%22%3Bs%3A8%3A%22gqwtkdks%22%3Bs%3A47%3A%22ves_themesettings_general%2Fgeneral_settings%2Fskin%22%3Bs%3A8%3A%22blue.css%22%3Bs%3A55%3A%22ves_themesettings_header%2Fgeneral_settings%2Fheader_layout%22%3Bs%3A13%3A%22default.phtml%22%3B%7D; _vwo_uuid_v2=EC7CC959823F97596222AB508A6BB8BE|53a815cb661ea346311131469aaeb1c2; PHPSESSID=oaibesqi4980brc3udl1gdrfb0
Host: www.domain.co.uk
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept: */*

-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="btn-save"

Apply
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="userparams[ves_themesettings_general/general_settings/direction]"

rtl
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="userparams[ves_themesettings_general/general_settings/layout]"

boxed-md
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="userparams[ves_themesettings_general/general_settings/max_width]"

1024px
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="userparams[ves_themesettings_general/general_settings/max_width_custom]"

12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'ð©
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="userparams[ves_themesettings_general/general_settings/skin]"

aquamarine.css
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="userparams[ves_themesettings_header/general_settings/header_layout]"

default2.phtml
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="vespanel"

1
-------Boundary_JTWCAHJSKP
Content-Disposition: form-data; name="vesreset"

0
-------Boundary_JTWCAHJSKP--

上面是Varnish緩存的錯誤設計的配置。 例如aquamarine.css錯誤的緩存CSS文件,應該是red.css

在發布請求后,Varnish是否有可能緩存了此設置? 另外,克服此問題的最佳方法是什么? 是否應該在Acunetix中創建規則來避免使用此URL? 還是創建一個NginX配置來阻止對它的訪問?

嘗試執行以下操作,僅強制Varnish不要嘗試將POST請求使用(或存儲到)緩存中:

sub vcl_recv {
    if (req.method == 'POST') {
       set req.hash_always_miss = true;
    }
}

暫無
暫無

聲明:本站的技術帖子網頁,遵循CC BY-SA 4.0協議,如果您需要轉載,請注明本站網址或者原文地址。任何問題請咨詢:yoyou2525@163.com.

 
粵ICP備18138465號  © 2020-2024 STACKOOM.COM