Hello!
÷ÌÁÄÉÍÉÒ ëÏÞÅÔËÏ×, Positive Research Center, ÏÂÎÁÒÕÖÉÌ ÐÒÏÂÌÅÍÕ ×
nginx/Windows, ËÏÔÏÒÁÑ ÐÏÚ×ÏÌÑÅÔ × ÎÅËÏÔÏÒÙÈ ÓÌÕÞÁÑÈ ÏÂÈÏÄÉÔØ
ÏÇÒÁÎÉÞÅÎÉÑ ÂÅÚÏÐÁÓÎÏÓÔÉ (CVE-2011-4963).
ðÒÉ ÒÁÂÏÔÅ ÐÏÄ Windows ÓÕÝÅÓÔ×ÕÅÔ ÍÎÏÇÏ ÓÐÏÓÏÂÏ× ÐÏÌÕÞÉÔØ ÄÏÓÔÕÐ Ë
ÏÄÎÏÍÕ É ÔÏÍÕ ÖÅ ÆÁÊÌÕ, É nginx ÕÞÉÔÙ×ÁÌ ÎÅ ×ÓÅ ×ÏÚÍÏÖÎÙÅ ÓÐÏÓÏÂÙ.
÷ ÒÅÚÕÌØÔÁÔÅ ÂÙÌÏ ×ÏÚÍÏÖÎÏ ÐÏÌÕÞÉÔØ ÄÏÓÔÕÐ Ë ÆÁÊÌÕ, ÚÁËÒÙÔÏÍÕ Ó
ÐÏÍÏÝØÀ ÏÇÒÁÎÉÞÅÎÉÊ ÄÏÓÔÕÐÁ ×ÉÄÁ
location /directory/ {
deny all;
}
ÚÁÐÒÏÓÉ× ÅÇÏ ËÁË "/directory::$index_allocation/file", ÌÉÂÏ
"/directory:$i30:$index_allocation/file", ÌÉÂÏ
"/directory./file".
ðÒÏÂÌÅÍÁ ÉÓÐÒÁ×ÌÅÎÁ × nginx/Windows 1.3.1, 1.2.1.
ðÒÉ ÉÓÐÏÌØÚÏ×ÁÎÉÉ ÂÏÌÅÅ ÓÔÁÒÙÈ ×ÅÒÓÉÊ × ËÁÞÅÓÔ×Å ×ÒÅÍÅÎÎÏÇÏ
ÒÅÛÅÎÉÑ ÍÏÖÎÏ ×ÏÓÐÏÌØÚÏ×ÁÔØÓÑ ËÏÎÆÉÇÕÒÁÃÉÅÊ ×ÉÄÁ:
location ~ "(\.|:\$)" {
deny all;
}
Maxim Dounin