ASP.NET中如何仅阻止/find_v2/端点的重定向?
问题
我们使用的某个NuGet包存在开放重定向漏洞,攻击者可通过类似https://example.com/find_v2/_click?_t_id=&_t_q=&_t_hit.id=&_t_redirect=https://www.google.com的链接实现任意重定向,漏洞根源是/find_v2/端点接收_t_redirect参数并执行重定向。我们需要仅阻止该端点的所有重定向,站点内其他Find操作、登录页登录成功后的首页重定向需正常保留。
已尝试的无效方案
曾在web.config中添加出站重写规则,但未达到预期效果:
<rewrite> <outboundRules> <rule name="Rewrite Location Header" preCondition="IsRedirection" enabled="true" stopProcessing="true"> <match serverVariable="RESPONSE_Location" pattern="http[s]{0,1}://localhost/find_v2/(.*)" /> <conditions> </conditions> <action type="Rewrite" value="http://{HTTP_HOST}/static/errors/GeneralError.html" /> </rule> <preConditions> <preCondition name="IsRedirection"> <add input="{RESPONSE_STATUS}" pattern="3\d\d" /> </preCondition> </preConditions> </outboundRules> </rewrite>
该方案要么会阻止全站所有重定向(不符合需求),要么无法精准匹配/find_v2/端点产生的外部重定向(原规则仅匹配Location头包含localhost/find_v2的情况,而漏洞重定向的目标是外部域名)。
可行解决方案
提供两种针对性方案,可根据实际需求选择:
方案1:出站规则精准拦截/find_v2/端点的重定向
这种方案会拦截所有由/find_v2/端点发起的3xx重定向,不影响其他请求的正常重定向:
<rewrite> <outboundRules> <rule name="Block find_v2 Redirects" preCondition="IsRedirection" enabled="true" stopProcessing="true"> <!-- 匹配所有Location头内容 --> <match serverVariable="RESPONSE_Location" pattern=".*" /> <conditions> <!-- 仅针对原始请求路径以/find_v2/开头的请求 --> <add input="{REQUEST_URI}" pattern="^/find_v2/.*" /> </conditions> <!-- 将重定向目标替换为自定义错误页 --> <action type="Rewrite" value="http://{HTTP_HOST}/static/errors/GeneralError.html" /> </rule> <preConditions> <preCondition name="IsRedirection"> <add input="{RESPONSE_STATUS}" pattern="3\d\d" /> </preCondition> </preConditions> </outboundRules> </rewrite>
规则说明
- 预条件
IsRedirection确保只处理3xx重定向响应 - 条件
{REQUEST_URI}精准匹配原始请求来自/find_v2/端点,不会影响登录页或其他Find操作的重定向 - 匹配所有Location头内容,覆盖漏洞可能产生的任意外部重定向目标
方案2:入站规则直接拦截漏洞参数
这种方案从请求源头拦截带有_t_redirect参数的/find_v2/请求,更精准地针对漏洞本身:
<rewrite> <rules> <rule name="Block find_v2 Redirect Parameter" enabled="true" stopProcessing="true"> <!-- 匹配所有/find_v2/开头的请求 --> <match url="^find_v2/.*" /> <conditions> <!-- 拦截包含_t_redirect参数的请求 --> <add input="{QUERY_STRING}" pattern="_t_redirect=.*" /> </conditions> <!-- 直接重定向到错误页 --> <action type="Redirect" url="/static/errors/GeneralError.html" redirectType="Permanent" /> </rule> </rules> </rewrite>
规则说明
- 直接在请求到达服务器时拦截带有漏洞参数的请求,避免后续处理环节产生重定向
- 不影响
/find_v2/端点的其他正常操作(如无_t_redirect参数的请求)
方案选择建议
- 如果需要彻底禁止
/find_v2/端点的所有重定向操作,选择方案1 - 如果仅需要阻止漏洞利用(允许
/find_v2/端点的其他合法重定向),选择方案2
内容的提问来源于stack exchange,提问作者Posiden104
相关产品推荐
相关产品推荐

