You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Security antMatcher校验绕过失败,如何构造URL绕过验证?

Spring Security antMatcher 校验绕过方案分析

配置背景

当前项目的Spring Security配置要求所有/admin/**路径必须经过认证,核心代码如下:

public class SpringSecurityConfig extends WebSecurityConfigurerAdapter {
    @Bean
    public HttpFirewall httpFirewall() {
        return new CustomHttpFirewall();
    }

    protected void configure(HttpSecurity httpSecurity) throws Exception {
        httpSecurity.authorizeRequests()
            .antMatchers("/admin/**")
            .authenticated();
    }
}

同时自定义HttpFirewall开启了URL编码特殊字符的允许规则:

public class CustomHttpFirewall extends DefaultHttpFirewall {
    protected void configure(StrictHttpFirewall firewalledRequest) {
        firewalledRequest.setAllowUrlEncodedSlash(true);
        firewalledRequest.setAllowUrlEncodedDoubleSlash(true);
        firewalledRequest.setAllowUrlEncodedPeriod(true);
    }
}

项目使用Spring Security 5.6.3、Spring Framework 2.7.0,未采用JWT认证。

可能的绕过思路及验证

针对你尝试过的双写斜杠、多次编码无效的情况,结合版本特性和配置,可尝试以下几种方向:

1. 大小写差异绕过

AntPathRequestMatcher默认区分大小写,若服务器(如Tomcat)配置了路径大小写不敏感(可通过caseInsensitive参数开启),可构造大小写混合的路径,比如:

  • /Admin/dashboard
  • /ADMIN/user/list

这类路径会被服务器映射到对应的/admin下资源,但AntMatcher的/admin/**规则不会匹配非小写开头的路径,从而绕过认证校验。

2. 空格注入绕过

构造包含URL编码空格(%20)的路径,比如:

  • /admin%20/dashboard
  • /admin /user/list(直接使用空格)

若服务器允许路径中存在空格并自动忽略,会将其解析为/admin/dashboard等目标资源,但AntMatcher会匹配原始路径/admin /dashboard,该路径并不以/admin开头,因此不会触发认证规则。

3. 反斜杠编码绕过

利用URL编码的反斜杠(%5C)构造路径,比如:

  • /%5Cadmin/dashboard

部分服务器(如Tomcat开启allowBackSlash配置时)会将%5C解析为斜杠,最终路径变为/admin/dashboard,但AntMatcher匹配的是原始请求路径/%5Cadmin/dashboard,该路径不属于/admin/**的匹配范围,从而绕过认证。

注意事项

以上方法均依赖服务器的具体配置,并非所有场景都适用。此外,这些方式属于安全漏洞利用手段,仅可用于授权的安全测试与漏洞修复,禁止用于非法访问目的。

内容的提问来源于stack exchange,提问作者coiloffaraday

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 09:05:55