Wildfly上Java应用特定URL存在Host头攻击漏洞求助
问题根源
当请求URL(如/app)末尾不带斜杠时,Wildfly的Undertow容器会自动触发302重定向,将请求导向带斜杠的URL(/app/)。这个重定向的Location头直接使用请求中的Host字段生成,这一步发生在应用过滤器执行之前,导致你配置的AppFilter完全没机会拦截并修正恶意Host头,从而暴露漏洞。
解决方案
1. 禁用容器自动尾斜杠重定向
直接关闭Wildfly的自动重定向功能,让请求直接进入应用过滤器处理。在standalone.xml的undertow子系统中,修改servlet-container配置:
<subsystem xmlns="urn:jboss:domain:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="other"> <server name="default-server"> <http-listener name="default" socket-binding="http" redirect-socket="https" enable-http2="true"/> <host name="default-host" alias="localhost"> <location name="/" handler="welcome-content"/> <filter-ref name="server-header"/> <filter-ref name="x-powered-by-header"/> </host> </server> <servlet-container name="default" redirect-servlet-path="false"> <!-- 添加此属性 --> <jsp-config/> <websockets/> </servlet-container> <!-- 其他配置... --> </subsystem>
添加redirect-servlet-path="false"后,容器不再自动重定向不带斜杠的URL,请求会直接进入你的AppFilter,由过滤器处理Host头校验逻辑。
2. 在容器层面配置Host头校验
如果不想禁用重定向,可以在Undertow层面添加Host头过滤,确保所有请求(包括容器重定向的请求)都使用合法的Host值。在standalone.xml中添加自定义过滤器:
<subsystem xmlns="urn:jboss:domain:undertow:12.0"> <!-- 定义过滤器 --> <filters> <!-- 自定义Host校验过滤器 --> <filter name="valid-host-filter" class-name="com.foo.bar.ValidHostFilter" module="com.foo.bar"/> <!-- 或用内置重写过滤器强制替换Host头 --> <rewrite name="rewrite-host" redirect="true"> <rule pattern="^.*$" substitution="http://your-valid-host:80%U" flags="R"/> </rewrite> </filters> <!-- 在host中引用过滤器(高优先级确保先执行) --> <server name="default-server"> <host name="default-host" alias="localhost"> <filter-ref name="valid-host-filter" priority="1"/> <!-- 若使用重写过滤器则替换为:<filter-ref name="rewrite-host"/> --> </host> </server> <!-- 其他配置... --> </subsystem>
自定义的ValidHostFilter需要你实现Host头白名单校验逻辑,非法请求直接返回错误;重写过滤器则直接将Host替换为合法值,确保重定向的Location头安全。
3. 应用层面补充防护
作为额外防护,可以在web.xml中添加<security-constraint>限制非法Host的请求:
<security-constraint> <web-resource-collection> <web-resource-name>Valid Hosts Only</web-resource-name> <url-pattern>/*</url-pattern> </web-resource-collection> <auth-constraint/> </security-constraint> <security-constraint> <web-resource-collection> <web-resource-name>Allowed Hosts</web-resource-name> <url-pattern>/*</url-pattern> </web-resource-collection> <auth-constraint> <role-name>*</role-name> </auth-constraint> <host-name>localhost</host-name> <host-name>your-valid-domain.com</host-name> </security-constraint>
该配置会拒绝来自非法Host的请求,需注意它依赖容器处理逻辑,要确保优先级设置正确。
为什么之前的修改无效
你修改root_path和添加url-pattern的操作无效,核心原因是容器的自动重定向发生在应用过滤器链执行之前——当请求/app时,Wildfly已经完成重定向响应,你的AppFilter根本没机会被调用,所以这些应用层面的配置无法影响这个过程。
内容的提问来源于stack exchange,提问作者ijm3

