
Gixy-Next v0.7.1
Gixy-Next: Escáner de seguridad de configuración y verificador de rendimiento de NGINX
Gixy-Next: Escáner de seguridad de configuraciones NGINX para auditorías de seguridad
Descripción general
Gixy-Next (Gixy) es un escáner de seguridad y herramienta de hardening de configuraciones NGINX de código abierto que analiza estáticamente tu nginx.conf para detectar configuraciones erróneas de seguridad, carencias de hardening y errores de rendimiento comunes antes de que lleguen a producción. Es un fork mantenido activamente del Gixy de Yandex. El código fuente de Gixy-Next está disponible en GitHub.
Gixy-Next también se puede ejecutar en el navegador en esta página. No se necesita descargar nada; puedes escanear tus configuraciones en el sitio web (localmente, usando WebAssembly).
Inicio rápido
Gixy-Next (la CLI gixy o gixy-next) se distribuye en PyPI. Puedes instalarlo con pip o uv:
# pip
pip3 install gixy-next
# uv
uv pip install gixy-next
Luego puedes ejecutarlo:
# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf
También puedes exportar tu configuración de NGINX a un único archivo de volcado (consulta nginx -T Live Configuration Dump):
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -
Escáner basado en web
En lugar de descargar y ejecutar Gixy-Next localmente, puedes usar esta página web y escanear una configuración desde tu navegador web (localmente, usando WebAssembly).
Escanear con Docker
Gixy-Next está disponible como imagen de Docker desde Docker Hub o GitHub Registry.
Escanea un archivo de configuración local montándolo en el contenedor:
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf
Escanea un volcado de configuración en vivo de NGINX:
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf
Escanear desde stdin:
# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -
Qué puede hacer
Gixy-Next puede detectar una amplia gama de configuraciones erróneas de seguridad y rendimiento de NGINX en nginx.conf y en los archivos de configuración incluidos. Se admiten los siguientes plugins:
- [add_header_content_type] Setting Content-Type via add_header
- [add_header_multiline] Multiline response headers
- [add_header_redefinition] Redefining of response headers by "add_header" directive
- [alias_traversal] Path traversal via misconfigured alias
- [allow_without_deny] Allow specified without deny
- [default_server_flag] Missing default_server flag
- [error_log_off]
error_logset tooff - [hash_without_default] Missing default in hash blocks
- [host_spoofing] Request's Host header forgery
- [http2_misdirected_request] Missing HTTP/2 misdirected-request safeguard
- [http_splitting] HTTP Response Splitting
- [if_is_evil] If is evil when used in location context
- [invalid_regex] Invalid regex capture groups
- [low_keepalive_requests] Low
keepalive_requests - [missing_worker_processes] Missing
worker_processes - [mixed_case_variable] Mixed-case variable references
- [origins] Problems with referer/origin header validation
- [overlapping_captures] Overlapping captures in rewrite redirect/args context
- [proxy_buffering_off] Disabling
proxy_buffering - [proxy_pass_normalized]
proxy_passpath normalization issues - [proxy_set_header_redefinition] Redefining of proxied request headers by "proxy_set_header" directive
- [quic_bpf_reuseport] QUIC connections silently dropped after reload
- [regex_redos] Regular expression denial of service (ReDoS)
- [resolver_external] Using external DNS nameservers
- [return_bypasses_allow_deny] Return directive bypasses allow/deny restrictions
- [ssl_ecdh_curve] Post-quantum groups stop NGINX from starting on older OpenSSL
- [ssl_stapling_letsencrypt] OCSP stapling does nothing for a Let's Encrypt certificate
- [ssl_stapling_without_resolver] OCSP stapling silently fails without a resolver
- [ssrf] Server Side Request Forgery
- [stale_dns_cache] Outdated/stale cached DNS records used in proxy_pass
- [status_page_exposed] Ensures that status_page is not exposed to the world
- [try_files_is_evil_too]
try_filesdirective is evil without open_file_cache - [unanchored_regex] Unanchored regular expressions
- [unnamed_groups] Unnamed capture groups in rewrite query string
- [valid_referers] none/blocked in valid_referers
- [version_disclosure] Using insecure values for server_tokens
- [worker_rlimit_nofile_vs_connections]
worker_rlimit_nofilemust be at least twiceworker_connections
¿Algo no detectado? ¡Abre un issue en GitHub indicando qué falta!
