You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET中如何仅阻止/find_v2/端点的重定向?

问题

我们使用的某个NuGet包存在开放重定向漏洞,攻击者可通过类似https://example.com/find_v2/_click?_t_id=&_t_q=&_t_hit.id=&_t_redirect=https://www.google.com的链接实现任意重定向,漏洞根源是/find_v2/端点接收_t_redirect参数并执行重定向。我们需要仅阻止该端点的所有重定向,站点内其他Find操作、登录页登录成功后的首页重定向需正常保留。

已尝试的无效方案

曾在web.config中添加出站重写规则,但未达到预期效果:

<rewrite>
  <outboundRules>
    <rule name="Rewrite Location Header" preCondition="IsRedirection" enabled="true" stopProcessing="true">
      <match serverVariable="RESPONSE_Location" pattern="http[s]{0,1}://localhost/find_v2/(.*)" />
      <conditions>
      </conditions>
      <action type="Rewrite" value="http://{HTTP_HOST}/static/errors/GeneralError.html" />
    </rule>
    <preConditions>
      <preCondition name="IsRedirection">
        <add input="{RESPONSE_STATUS}" pattern="3\d\d" />
      </preCondition>
    </preConditions>
  </outboundRules>
</rewrite>

该方案要么会阻止全站所有重定向(不符合需求),要么无法精准匹配/find_v2/端点产生的外部重定向(原规则仅匹配Location头包含localhost/find_v2的情况,而漏洞重定向的目标是外部域名)。

可行解决方案

提供两种针对性方案,可根据实际需求选择:

方案1:出站规则精准拦截/find_v2/端点的重定向

这种方案会拦截所有由/find_v2/端点发起的3xx重定向,不影响其他请求的正常重定向:

<rewrite>
  <outboundRules>
    <rule name="Block find_v2 Redirects" preCondition="IsRedirection" enabled="true" stopProcessing="true">
      <!-- 匹配所有Location头内容 -->
      <match serverVariable="RESPONSE_Location" pattern=".*" />
      <conditions>
        <!-- 仅针对原始请求路径以/find_v2/开头的请求 -->
        <add input="{REQUEST_URI}" pattern="^/find_v2/.*" />
      </conditions>
      <!-- 将重定向目标替换为自定义错误页 -->
      <action type="Rewrite" value="http://{HTTP_HOST}/static/errors/GeneralError.html" />
    </rule>
    <preConditions>
      <preCondition name="IsRedirection">
        <add input="{RESPONSE_STATUS}" pattern="3\d\d" />
      </preCondition>
    </preConditions>
  </outboundRules>
</rewrite>

规则说明

  • 预条件IsRedirection确保只处理3xx重定向响应
  • 条件{REQUEST_URI}精准匹配原始请求来自/find_v2/端点,不会影响登录页或其他Find操作的重定向
  • 匹配所有Location头内容,覆盖漏洞可能产生的任意外部重定向目标

方案2:入站规则直接拦截漏洞参数

这种方案从请求源头拦截带有_t_redirect参数的/find_v2/请求,更精准地针对漏洞本身:

<rewrite>
  <rules>
    <rule name="Block find_v2 Redirect Parameter" enabled="true" stopProcessing="true">
      <!-- 匹配所有/find_v2/开头的请求 -->
      <match url="^find_v2/.*" />
      <conditions>
        <!-- 拦截包含_t_redirect参数的请求 -->
        <add input="{QUERY_STRING}" pattern="_t_redirect=.*" />
      </conditions>
      <!-- 直接重定向到错误页 -->
      <action type="Redirect" url="/static/errors/GeneralError.html" redirectType="Permanent" />
    </rule>
  </rules>
</rewrite>

规则说明

  • 直接在请求到达服务器时拦截带有漏洞参数的请求,避免后续处理环节产生重定向
  • 不影响/find_v2/端点的其他正常操作(如无_t_redirect参数的请求)
方案选择建议
  • 如果需要彻底禁止/find_v2/端点的所有重定向操作,选择方案1
  • 如果仅需要阻止漏洞利用(允许/find_v2/端点的其他合法重定向),选择方案2

内容的提问来源于stack exchange,提问作者Posiden104

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 03:25:14