
Gixy-Next v0.7.1
Gixy-Next: NGINX कॉन्फ़िगरेशन सुरक्षा स्कैनर और प्रदर्शन जाँचकर्ता
Gixy-Next: सुरक्षा ऑडिट के लिए NGINX कॉन्फ़िगरेशन सुरक्षा स्कैनर
अवलोकन
Gixy-Next (Gixy) एक ओपन-सोर्स NGINX कॉन्फ़िगरेशन सुरक्षा स्कैनर और हार्डनिंग टूल है जो आपकी nginx.conf का स्थिर विश्लेषण करके सुरक्षा गलत कॉन्फ़िगरेशन, हार्डनिंग कमियों, और सामान्य प्रदर्शन समस्याओं का पता लगाता है — इससे पहले कि वे प्रोडक्शन तक पहुँचें। यह Yandex के Gixy का सक्रिय रूप से अनुरक्षित फोर्क है। Gixy-Next का सोर्स कोड GitHub पर उपलब्ध है।
Gixy-Next को ब्राउज़र में भी इस पेज पर चलाया जा सकता है। किसी डाउनलोड की आवश्यकता नहीं है; आप वेबसाइट पर अपनी कॉन्फ़िगरेशन स्कैन कर सकते हैं (स्थानीय रूप से, WebAssembly का उपयोग करके)।
त्वरित शुरुआत
Gixy-Next (gixy या gixy-next CLI) PyPI पर वितरित किया जाता है। आप इसे pip या uv के साथ इंस्टॉल कर सकते हैं:
# pip
pip3 install gixy-next
# uv
uv pip install gixy-next
फिर आप इसे चला सकते हैं:
# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf
आप अपनी NGINX कॉन्फ़िगरेशन को एक एकल डंप फ़ाइल में भी निर्यात कर सकते हैं (देखें nginx -T Live Configuration Dump):
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -
वेब-आधारित स्कैनर
Gixy-Next को स्थानीय रूप से डाउनलोड और चलाने के बजाय, आप इस वेबपेज का उपयोग कर सकते हैं और अपने वेब ब्राउज़र से कॉन्फ़िगरेशन स्कैन कर सकते हैं (स्थानीय रूप से, WebAssembly का उपयोग करके)।
Docker के साथ स्कैन करें
Gixy-Next Docker Hub या GitHub Registry से Docker इमेज के रूप में उपलब्ध है।
स्थानीय कॉन्फ़िग फ़ाइल को कंटेनर में माउंट करके स्कैन करें:
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf
NGINX लाइव कॉन्फ़िगरेशन डंप स्कैन करें:
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf
stdin से स्कैन करें:
# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -
यह क्या कर सकता है
Gixy-Next nginx.conf और शामिल कॉन्फ़िगरेशन फ़ाइलों में NGINX सुरक्षा और प्रदर्शन संबंधी गलत कॉन्फ़िगरेशन की एक विस्तृत श्रृंखला का पता लगा सकता है। निम्नलिखित प्लगइन समर्थित हैं:
- [add_header_content_type] Setting Content-Type via add_header
- [add_header_multiline] Multiline response headers
- [add_header_redefinition] Redefining of response headers by "add_header" directive
- [alias_traversal] Path traversal via misconfigured alias
- [allow_without_deny] Allow specified without deny
- [default_server_flag] Missing default_server flag
- [error_log_off]
error_logset tooff - [hash_without_default] Missing default in hash blocks
- [host_spoofing] Request's Host header forgery
- [http2_misdirected_request] Missing HTTP/2 misdirected-request safeguard
- [http_splitting] HTTP Response Splitting
- [if_is_evil] If is evil when used in location context
- [invalid_regex] Invalid regex capture groups
- [low_keepalive_requests] Low
keepalive_requests - [missing_worker_processes] Missing
worker_processes - [mixed_case_variable] Mixed-case variable references
- [origins] Problems with referer/origin header validation
- [overlapping_captures] Overlapping captures in rewrite redirect/args context
- [proxy_buffering_off] Disabling
proxy_buffering - [proxy_pass_normalized]
proxy_passpath normalization issues - [proxy_set_header_redefinition] Redefining of proxied request headers by "proxy_set_header" directive
- [quic_bpf_reuseport] QUIC connections silently dropped after reload
- [regex_redos] Regular expression denial of service (ReDoS)
- [resolver_external] Using external DNS nameservers
- [return_bypasses_allow_deny] Return directive bypasses allow/deny restrictions
- [ssl_ecdh_curve] Post-quantum groups stop NGINX from starting on older OpenSSL
- [ssl_stapling_letsencrypt] OCSP stapling does nothing for a Let's Encrypt certificate
- [ssl_stapling_without_resolver] OCSP stapling silently fails without a resolver
- [ssrf] Server Side Request Forgery
- [stale_dns_cache] Outdated/stale cached DNS records used in proxy_pass
- [status_page_exposed] Ensures that status_page is not exposed to the world
- [try_files_is_evil_too]
try_filesdirective is evil without open_file_cache - [unanchored_regex] Unanchored regular expressions
- [unnamed_groups] Unnamed capture groups in rewrite query string
- [valid_referers] none/blocked in valid_referers
- [version_disclosure] Using insecure values for server_tokens
- [worker_rlimit_nofile_vs_connections]
worker_rlimit_nofilemust be at least twiceworker_connections
कुछ पता नहीं चला? कृपया GitHub पर एक issue खोलें और बताएं कि क्या छूट रहा है!
उपयोग (फ्लैग)
gixy डिफ़ॉल्ट रूप से सिस्टम की NGINX कॉन्फ़िगरेशन को /etc/nginx/nginx.conf से पढ़ता है। आप इसे gixy को पास करके स्थान भी निर्दिष्ट कर सकते हैं:
