Skip to content
Toggle navigation
P
Projects
G
Groups
S
Snippets
Help
CnChunfeng
/
ichunt_lua_waf
This project
Loading...
Sign in
Toggle navigation
Go to a project
Project
Repository
Issues
0
Merge Requests
0
Pipelines
Wiki
Snippets
Settings
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Commit
85721e9b
authored
Jan 14, 2021
by
Joneq
Browse files
Options
_('Browse Files')
Download
Email Patches
Plain Diff
增加对referer的访问白名单
parent
3cafd654
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
8 additions
and
3 deletions
redirect.lua
waf.lua
redirect.lua
View file @
85721e9b
...
...
@@ -17,7 +17,7 @@ function _ReM.checkgoogle(red)
end
--新增如果refer不在对应的设置里面,才计算302重定向次数 get_headers里面就是浏览器的请求头小写
if
red
:
sismember
(
'ichunt_waf_white_referer'
,
ngx
.
req
.
get_headers
()[
'referer'
])
~
=
0
then
if
red
:
sismember
(
'ichunt_waf_white_referer'
,
ngx
.
req
.
get_headers
()[
'referer'
])
=
=
0
then
--获取多少时间内同一个ip可以几次302,超过就加入黑名单
threezerotwo_second
,
err
=
red
:
get
(
'threezerotwo_second'
)
...
...
waf.lua
View file @
85721e9b
...
...
@@ -60,10 +60,15 @@ if config.redis_auth ~= "" and ok then
end
if
ngx
.
req
.
get_headers
()[
'referer'
]
==
nil
then
ngx
.
req
.
get_headers
()[
'referer'
]
=
""
local
referer
=
""
if
ngx
.
req
.
get_headers
()[
'referer'
]
~=
nil
then
referer
=
ngx
.
req
.
get_headers
()[
'referer'
]
end
ngx
.
say
(
referer
)
ngx
.
say
(
red
:
sismember
(
'ichunt_waf_white_referer'
,
referer
))
ngx
.
say
(
red
:
sismember
(
'ichunt_waf_white_referer'
,
referer
)
==
0
)
ngx
.
exit
(
ngx
.
HTTP_FORBIDDEN
)
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment