已执行修复仍未解决OWASP ZAP代理泄露(40025)告警求助
解决OWASP ZAP的Proxy Disclosure [40025]告警问题
我使用OWASP ZAP验证规则时,触发了以下失败告警:
FAIL-NEW: Proxy Disclosure [40025] x 1 https://test.my-site.com (200 OK)
ZAP官方给出的解决方案:
在代理服务器及源站Web/应用服务器上禁用'TRACE'方法;若无需用于CORS(跨域资源共享)等场景,在代理服务器及源站Web/应用服务器上禁用'OPTIONS'方法;为Web和应用服务器配置自定义错误页面,避免HTTP错误时泄露可被指纹识别的产品特定错误页面;配置所有代理、应用服务器及Web服务器,防止在'Server'和'X-Powered-By' HTTP响应头中泄露技术及版本信息。
已执行的修复操作
- 在
.htaccess文件中阻止TRACE、TRACK和OPTIONS方法,配置如下:RewriteEngine On # Disable TRACE and TRACK HTTP methods RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK) RewriteRule .* - [F] # Disable OPTIONS HTTP method RewriteCond %{REQUEST_METHOD} ^OPTIONS RewriteRule .* - [R=405,L] - 移除包含服务器信息的响应头:
- X-Powered-By:响应头中未发现该字段
- Server:已移除Apache标识,仅保留空的
Server头部
尽管执行了上述所有操作,告警问题仍未解决,若有信息不明确之处可补充更多内容。
补充扫描细节
终端执行全量扫描时出现相关警告和错误(截图:
),扫描结果XML中的告警详情如下:
<alertitem> <pluginid>40025</pluginid> <alertRef>40025</alertRef> <alert>Proxy Disclosure</alert> <name>Proxy Disclosure</name> <riskcode>2</riskcode> <confidence>2</confidence> <riskdesc>Medium (Medium)</riskdesc> <confidencedesc>Medium</confidencedesc> <desc><p>1 proxy server(s) were detected or fingerprinted. This information helps a potential attacker to determine </p><p> - A list of targets for an attack against the application.</p><p> - Potential vulnerabilities on the proxy servers that service the application.</p><p> - The presence or absence of any proxy-based components that might cause attacks against the application to be detected, prevented, or mitigated. </p></desc> <instances> <instance> <uri>https://test.my-site.com</uri> <method>GET</method> <param></param> <attack>TRACE, OPTIONS methods with 'Max-Forwards' header. TRACK method.</attack> <evidence></evidence> </instance> </instances> <count>1</count> <solution><p>Disable the 'TRACE' method on the proxy servers, as well as the origin web/application server.</p><p>Disable the 'OPTIONS' method on the proxy servers, as well as the origin web/application server, if it is not required for other purposes, such as 'CORS' (Cross Origin Resource Sharing).</p><p>Configure the web and application servers with custom error pages, to prevent 'fingerprintable' product-specific error pages being leaked to the user in the event of HTTP errors, such as 'TRACK' requests for non-existent pages.</p><p>Configure all proxies, application servers, and web servers to prevent disclosure of the technology and version information in the 'Server' and 'X-Powered-By' HTTP response headers.</p><p></p></solution> <otherinfo><p>Using the TRACE, OPTIONS, and TRACK methods, the following proxy servers have been identified between OWASP ZAP and the application/web server: </p><p>- Unknown</p><p>The following web/application server has been identified: </p><p>- Unknown</p><p></p></otherinfo> <reference><p>https://tools.ietf.org/html/rfc7231#section-5.1.2</p></reference> <cweid>200</cweid> <wascid>45</wascid> <sourceid>231</sourceid> </alertitem>
恳请协助解决该问题。
内容的提问来源于stack exchange,提问作者Paladin
相关产品推荐
相关产品推荐

