【腾讯云代码分析】经典案例分享:路径穿越漏洞 #1086
xiohuang9
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
规则介绍
路径穿越漏洞(也称为目录遍历漏洞)是一种常见的Web应用程序安全漏洞,攻击者可以利用这个漏洞访问服务器上的任意文件或目录,从而导致数据泄露、篡改或删除等安全问题。
下列案例对应代码分析Xcheck工具中的规则:path_traversal——用于检测和防止路径遍历攻击,确保文件路径安全。
经典案例
代码案例
问题解析
这段代码是一个Spring Boot应用程序中的文件上传功能,但存在以下安全隐患:
AI修复建议
检查文件名称
规则使用说明
规则添加
![image](https://private-user-images.githubusercontent.com/160583399/339199638-3f63b32b-715a-4475-8883-962c077a93ef.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkxMDM4MjYsIm5iZiI6MTczOTEwMzUyNiwicGF0aCI6Ii8xNjA1ODMzOTkvMzM5MTk5NjM4LTNmNjNiMzJiLTcxNWEtNDQ3NS04ODgzLTk2MmMwNzdhOTNlZi5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjA5JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIwOVQxMjE4NDZaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT1jMGQwZGJjYjY4YzM2OWI4ZWQ1MjJmMDQ2NjA1NDc3NjAzMzRlNjkwZWZlYjk1YWQwZWY4NmZjNTRhZjMxZmZiJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.MWK980YPikfXrJZ_0nYtg3kgKH_0zpK_8Df4OAHZdQs)
![image](https://private-user-images.githubusercontent.com/160583399/339199653-c70b8437-e819-4305-9629-0c3d07d318d4.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkxMDM4MjYsIm5iZiI6MTczOTEwMzUyNiwicGF0aCI6Ii8xNjA1ODMzOTkvMzM5MTk5NjUzLWM3MGI4NDM3LWU4MTktNDMwNS05NjI5LTBjM2QwN2QzMThkNC5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjA5JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIwOVQxMjE4NDZaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0xYWU3MWIyMTU0NGJlNWZlZjQ4NjdlMjFhOTczOTM1ZjcxODkwYjE5MWYyNGMyMTNmMTQwNjU1YzA3ZjhkNzA3JlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.fD5qHAd8WoD6vG9IxwQH-aE8sKMrAcGTkwPw-lpYdRE)
进入页面,点击方案->规则配置 -> 自定义规则包-> 添加规则 ->搜索规则名path_traversal->选择需要添加的规则 ->批量添加规则
规则包选择
![image](https://private-user-images.githubusercontent.com/160583399/339199684-61e35877-60e0-47cc-8dfa-8b807d6ea33a.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkxMDM4MjYsIm5iZiI6MTczOTEwMzUyNiwicGF0aCI6Ii8xNjA1ODMzOTkvMzM5MTk5Njg0LTYxZTM1ODc3LTYwZTAtNDdjYy04ZGZhLThiODA3ZDZlYTMzYS5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjA5JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIwOVQxMjE4NDZaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0zYTg3MzA0Zjc4ZWQ0OGE4YjBlYjI2NjQwMTBiOTc5ZTNmNmUyMjAyMmNkZDI1ZWY2YjgzZDAzYWQ0NGFkNmFmJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.2hC0G88jHjS2Yqq_Xj5TAG5sTwf4JzIIqZFigDmwbK8)
可以直接勾选对应语言的 强化安全规则包
Beta Was this translation helpful? Give feedback.
All reactions