Spring Security antMatcher校验绕过失败,如何构造URL绕过验证?
配置背景
当前项目的Spring Security配置要求所有/admin/**路径必须经过认证,核心代码如下:
public class SpringSecurityConfig extends WebSecurityConfigurerAdapter { @Bean public HttpFirewall httpFirewall() { return new CustomHttpFirewall(); } protected void configure(HttpSecurity httpSecurity) throws Exception { httpSecurity.authorizeRequests() .antMatchers("/admin/**") .authenticated(); } }
同时自定义HttpFirewall开启了URL编码特殊字符的允许规则:
public class CustomHttpFirewall extends DefaultHttpFirewall { protected void configure(StrictHttpFirewall firewalledRequest) { firewalledRequest.setAllowUrlEncodedSlash(true); firewalledRequest.setAllowUrlEncodedDoubleSlash(true); firewalledRequest.setAllowUrlEncodedPeriod(true); } }
项目使用Spring Security 5.6.3、Spring Framework 2.7.0,未采用JWT认证。
可能的绕过思路及验证
针对你尝试过的双写斜杠、多次编码无效的情况,结合版本特性和配置,可尝试以下几种方向:
1. 大小写差异绕过
AntPathRequestMatcher默认区分大小写,若服务器(如Tomcat)配置了路径大小写不敏感(可通过caseInsensitive参数开启),可构造大小写混合的路径,比如:
/Admin/dashboard/ADMIN/user/list
这类路径会被服务器映射到对应的/admin下资源,但AntMatcher的/admin/**规则不会匹配非小写开头的路径,从而绕过认证校验。
2. 空格注入绕过
构造包含URL编码空格(%20)的路径,比如:
/admin%20/dashboard/admin /user/list(直接使用空格)
若服务器允许路径中存在空格并自动忽略,会将其解析为/admin/dashboard等目标资源,但AntMatcher会匹配原始路径/admin /dashboard,该路径并不以/admin开头,因此不会触发认证规则。
3. 反斜杠编码绕过
利用URL编码的反斜杠(%5C)构造路径,比如:
/%5Cadmin/dashboard
部分服务器(如Tomcat开启allowBackSlash配置时)会将%5C解析为斜杠,最终路径变为/admin/dashboard,但AntMatcher匹配的是原始请求路径/%5Cadmin/dashboard,该路径不属于/admin/**的匹配范围,从而绕过认证。
注意事项
以上方法均依赖服务器的具体配置,并非所有场景都适用。此外,这些方式属于安全漏洞利用手段,仅可用于授权的安全测试与漏洞修复,禁止用于非法访问目的。
内容的提问来源于stack exchange,提问作者coiloffaraday

