Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
lua-resty-limit-traffic — Biblioteca Lua para limitar y controlar el tráfico en OpenResty/ngx_lua | Kitploit
Herramientas/GitHubGitHub/openresty/lua-resty-limit-traffic
Herramientas DefensivasUtilidades de Propósito GeneralSeguridad Web
GitHubopenresty/lua-resty-limit-traffic

lua-resty-limit-traffic

Biblioteca Lua para limitar y controlar el tráfico en OpenResty/ngx_lua

Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
852157hace 1 mesRevisado por Kitploit

Nombre

lua-resty-limit-traffic - Biblioteca Lua para limitar y controlar el tráfico en OpenResty/ngx_lua

Tabla de contenidos

  • Nombre
  • Estado
  • Sinopsis
  • Descripción
  • Instalación
  • Comunidad
    • Lista de correo en inglés
    • Lista de correo en chino
  • Errores y parches
  • Autor
  • Derechos de autor y licencia
  • Ver también

Estado

Esta biblioteca ya es utilizable aunque sigue siendo altamente experimental.

La API de Lua todavía está en evolución y puede cambiar en un futuro próximo sin previo aviso.

Sinopsis

root@kitploit:~
# demonstrate the usage of the resty.limit.req module (alone!)
http {
    lua_shared_dict my_limit_req_store 100m;

    server {
        location / {
            access_by_lua_block {
                -- well, we could put the require() and new() calls in our own Lua
                -- modules to save overhead. here we put them below just for
                -- convenience.

                local limit_req = require "resty.limit.req"

                -- limit the requests under 200 req/sec with a burst of 100 req/sec,
                -- that is, we delay requests under 300 req/sec and above 200
                -- req/sec, and reject any requests exceeding 300 req/sec.
                local lim, err = limit_req.new("my_limit_req_store", 200, 100)
                if not lim then
                    ngx.log(ngx.ERR,
                            "failed to instantiate a resty.limit.req object: ", err)
                    return ngx.exit(500)
                end

                -- the following call must be per-request.
                -- here we use the remote (IP) address as the limiting key
                local key = ngx.var.binary_remote_addr
                local delay, err = lim:incoming(key, true)
                if not delay then
                    if err == "rejected" then
                        return ngx.exit(503)
                    end
                    ngx.log(ngx.ERR, "failed to limit req: ", err)
                    return ngx.exit(500)
                end

                if delay >= 0.001 then
                    -- the 2nd return value holds the number of excess requests
                    -- per second for the specified key. for example, number 31
                    -- means the current request rate is at 231 req/sec for the
                    -- specified key.
                    local excess = err

                    -- the request exceeding the 200 req/sec but below 300 req/sec,
                    -- so we intentionally delay it here a bit to conform to the
                    -- 200 req/sec rate.
                    ngx.sleep(delay)
                end
            }

            # content handler goes here. if it is content_by_lua, then you can
            # merge the Lua code above in access_by_lua into your content_by_lua's
            # Lua handler to save a little bit of CPU time.
        }
    }
}
root@kitploit:~
# demonstrate the usage of the resty.limit.conn module (alone!)
http {
    lua_shared_dict my_limit_conn_store 100m;

    server {
        location / {
            access_by_lua_block {
                -- well, we could put the require() and new() calls in our own Lua
                -- modules to save overhead. here we put them below just for
                -- convenience.

                local limit_conn = require "resty.limit.conn"

                -- limit the requests under 200 concurrent requests (normally just
                -- incoming connections unless protocols like SPDY is used) with
                -- a burst of 100 extra concurrent requests, that is, we delay
                -- requests under 300 concurrent connections and above 200
                -- connections, and reject any new requests exceeding 300
                -- connections.
                -- also, we assume a default request time of 0.5 sec, which can be
                -- dynamically adjusted by the leaving() call in log_by_lua below.
                local lim, err = limit_conn.new("my_limit_conn_store", 200, 100, 0.5)
                if not lim then
                    ngx.log(ngx.ERR,
                            "failed to instantiate a resty.limit.conn object: ", err)
                    return ngx.exit(500)
                end

                -- the following call must be per-request.
                -- here we use the remote (IP) address as the limiting key
                local key = ngx.var.binary_remote_addr
                local delay, err = lim:incoming(key, true)
                if not delay then
                    if err == "rejected" then
                        return ngx.exit(503)
                    end
                    ngx.log(ngx.ERR, "failed to limit req: ", err)
                    return ngx.exit(500)
                end

                if lim:is_committed() then
                    local ctx = ngx.ctx
                    ctx.limit_conn = lim
                    ctx.limit_conn_key = key
                    ctx.limit_conn_delay = delay
                end

                -- the 2nd return value holds the current concurrency level
                -- for the specified key.
                local conn = err

                if delay >= 0.001 then
                    -- the request exceeding the 200 connections ratio but below
                    -- 300 connections, so
                    -- we intentionally delay it here a bit to conform to the
                    -- 200 connection limit.
                    -- ngx.log(ngx.WARN, "delaying")
                    ngx.sleep(delay)
                end
            }

            # content handler goes here. if it is content_by_lua, then you can
            # merge the Lua code above in access_by_lua into your
            # content_by_lua's Lua handler to save a little bit of CPU time.

            log_by_lua_block {
                local ctx = ngx.ctx
                local lim = ctx.limit_conn
                if lim then
                    -- if you are using an upstream module in the content phase,
                    -- then you probably want to use $upstream_response_time
                    -- instead of ($request_time - ctx.limit_conn_delay) below.
                    local latency = tonumber(ngx.var.request_time) - ctx.limit_conn_delay
                    local key = ctx.limit_conn_key
                    assert(key)
                    local conn, err = lim:leaving(key, latency)
                    if not conn then
                        ngx.log(ngx.ERR,
                                "failed to record the connection leaving ",
                                "request: ", err)
                        return
                    end
                end
            }
        }
    }
}
root@kitploit:~
# demonstrate the usage of the resty.limit.traffic module
http {
    lua_shared_dict my_req_store 100m;
    lua_shared_dict my_conn_store 100m;

    server {
        location / {
            access_by_lua_block {
                local limit_conn = require "resty.limit.conn"
                local limit_req = require "resty.limit.req"
                local limit_traffic = require "resty.limit.traffic"

                local lim1, err = limit_req.new("my_req_store", 300, 200)
                assert(lim1, err)
                local lim2, err = limit_req.new("my_req_store", 200, 100)
                assert(lim2, err)
                local lim3, err = limit_conn.new("my_conn_store", 1000, 1000, 0.5)
                assert(lim3, err)

                local limiters = {lim1, lim2, lim3}

                local host = ngx.var.host
                local client = ngx.var.binary_remote_addr
                local keys = {host, client, client}

                local states = {}

                local delay, err = limit_traffic.combine(limiters, keys, states)
                if not delay then
                    if err == "rejected" then
                        return ngx.exit(503)
                    end
                    ngx.log(ngx.ERR, "failed to limit traffic: ", err)
                    return ngx.exit(500)
                end

                if lim3:is_committed() then
                    local ctx = ngx.ctx
                    ctx.limit_conn = lim3
                    ctx.limit_conn_key = keys[3]
                end

                print("sleeping ", delay, " sec, states: ",
                      table.concat(states, ", "))

                if delay >= 0.001 then
                    ngx.sleep(delay)
                end
            }

            # content handler goes here. if it is content_by_lua, then you can
            # merge the Lua code above in access_by_lua into your
            # content_by_lua's Lua handler to save a little bit of CPU time.

            log_by_lua_block {
                local ctx = ngx.ctx
                local lim = ctx.limit_conn
                if lim then
                    -- if you are using an upstream module in the content phase,
                    -- then you probably want to use $upstream_response_time
                    -- instead of $request_time below.
                    local latency = tonumber(ngx.var.request_time)
                    local key = ctx.limit_conn_key
                    assert(key)
                    local conn, err = lim:leaving(key, latency)
                    if not conn then
                        ngx.log(ngx.ERR,
                                "failed to record the connection leaving ",
                                "request: ", err)
                        return
                    end
                end
            }
        }
    }
}

Descripción

Esta biblioteca proporciona varios módulos Lua para ayudar a los usuarios de OpenResty/ngx_lua a controlar y limitar el tráfico, ya sea la tasa de solicitudes o la concurrencia de solicitudes (o ambos).

  • resty.limit.req proporciona limitación y ajuste de la tasa de solicitudes basados en el método del "cubo con fugas".
  • resty.limit.count proporciona limitación de tasa basada en una implementación de "ventana fija" desde OpenResty 1.13.6.1+.
  • resty.limit.conn proporciona limitación y ajuste del nivel de concurrencia de solicitudes basados en retrasos adicionales.
  • resty.limit.traffic proporciona un agregador para combinar múltiples instancias de las clases resty.limit.req, resty.limit.count o resty.limit.conn (o todas).

Consulte la documentación propia de estos módulos Lua para obtener más detalles.

Esta biblioteca proporciona alternativas más flexibles a los módulos estándar de NGINX ngx_limit_req y ngx_limit_conn. Por ejemplo, los limitadores basados en Lua proporcionados por esta biblioteca se pueden usar en cualquier contexto, como justo antes del procedimiento de negociación SSL descendente (como con ssl_certificate_by_lua) o justo antes de emitir solicitudes al backend.

Volver al índice

Instalación

Esta biblioteca está habilitada de forma predeterminada en OpenResty 1.11.2.2+.

Si tiene que instalar esta biblioteca manualmente, asegúrese de estar usando al menos OpenResty 1.11.2.1 o una compilación personalizada de nginx que incluya ngx_lua 0.10.6+. Además, debe configurar la directiva lua_package_path para agregar la ruta de su árbol de fuentes de lua-resty-limit-traffic a la ruta de búsqueda de módulos Lua de ngx_lua, como en

root@kitploit:~
# nginx.conf
http {
    lua_package_path "/path/to/lua-resty-limit-traffic/lib/?.lua;;";
    ...
}

y luego cargue uno de los módulos proporcionados por esta biblioteca en Lua. Por ejemplo,

root@kitploit:~
local limit_req = require "resty.limit.req"

Volver al índice

Comunidad

Volver al índice

Lista de correo en inglés

La lista de correo openresty-en es para hablantes de inglés.

Volver al índice

Lista de correo en chino

La lista de correo openresty es para hablantes de chino.

Volver al índice

Errores y parches

Por favor, informe errores o envíe parches mediante

  1. la creación de un ticket en el GitHub Issue Tracker,
  2. o publicando en la comunidad de OpenResty.

Volver al índice

Autor

Yichun "agentzh" Zhang (章亦春) [email protected], OpenResty Inc.

Volver al índice

Derechos de autor y licencia

Este módulo está licenciado bajo la licencia BSD.

Copyright (C) 2015-2019, by Yichun "agentzh" Zhang, OpenResty Inc.

Todos los derechos reservados.

La redistribución y el uso en formas de código fuente y binarias, con o sin modificación, están permitidos siempre que se cumplan las siguientes condiciones:

  • Las redistribuciones del código fuente deben conservar el aviso de copyright anterior, esta lista de condiciones y el siguiente descargo de responsabilidad.

  • Las redistribuciones en forma binaria deben reproducir el aviso de copyright anterior, esta lista de condiciones y el siguiente descargo de responsabilidad en la documentación y/o en otros materiales proporcionados con la distribución.

ESTE SOFTWARE SE PROPORCIONA "TAL CUAL", SIN GARANTÍAS EXPRESAS O IMPLÍCITAS DE NINGÚN TIPO, INCLUIDAS, PERO NO LIMITADAS A, LAS GARANTÍAS IMPLÍCITAS DE COMERCIABILIDAD E IDONEIDAD PARA UN FIN DETERMINADO. EN NINGÚN CASO LOS TITULARES DEL COPYRIGHT O LOS COLABORADORES SERÁN RESPONSABLES DE NINGÚN DAÑO DIRECTO, INDIRECTO, INCIDENTAL, ESPECIAL, EJEMPLAR O CONSECUENTE (INCLUIDOS, PERO NO LIMITADOS A, LA ADQUISICIÓN DE BIENES O SERVICIOS SUSTITUTOS; LA PÉRDIDA DE USO, DATOS O BENEFICIOS; O LA INTERRUPCIÓN DEL NEGOCIO), YA SEA POR CONTRATO, RESPONSABILIDAD ESTRICTA O AGRAVIO (INCLUIDA LA NEGLIGENCIA U OTRA CAUSA), QUE SURJA DE CUALQUIER MANERA DEL USO DE ESTE SOFTWARE, INCLUSO SI SE HA ADVERTIDO DE LA POSIBILIDAD DE TALES DAÑOS.

Volver al índice

Ver también

  • módulo resty.limit.req
  • módulo resty.limit.count
  • módulo resty.limit.conn
  • módulo resty.limit.traffic
  • el módulo ngx_lua: https://github.com/openresty/lua-nginx-module
  • OpenResty: https://openresty.org/

Volver al índice

Descargar herramienta