
Gixy-Next v0.6.0
Gixy-Next: NGINX 구성 보안 스캐너 및 성능 검사기
Gixy-Next: 보안 감사를 위한 NGINX 구성 보안 스캐너
개요
Gixy-Next (Gixy)는 오픈소스 NGINX 구성 보안 스캐너이자 하드닝 도구로, nginx.conf를 정적으로 분석하여 보안 설정 오류, 하드닝 격차, 그리고 흔한 성능 함정을 프로덕션에 도달하기 전에 탐지합니다. Yandex의 Gixy를 활발히 유지보수하는 포크입니다. Gixy-Next의 소스 코드는 GitHub에서 확인할 수 있습니다.
Gixy-Next는 이 페이지에서 브라우저로도 실행할 수 있습니다. 다운로드가 필요 없으며, 웹사이트에서 (WebAssembly를 사용하여 로컬에서) 구성을 스캔할 수 있습니다.
빠른 시작
Gixy-Next (gixy 또는 gixy-next CLI)는 PyPI에 배포되어 있습니다. pip 또는 uv로 설치할 수 있습니다:
# pip
pip3 install gixy-next
# uv
uv pip install gixy-next
그런 다음 실행할 수 있습니다:
# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf
NGINX 구성을 단일 덤프 파일로 내보낼 수도 있습니다 (nginx -T 라이브 구성 덤프 참조):
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -
웹 기반 스캐너
Gixy-Next를 로컬에 다운로드하여 실행하는 대신, 이 웹페이지를 사용하여 웹 브라우저에서 (WebAssembly를 사용하여 로컬에서) 구성을 스캔할 수 있습니다.
Docker로 스캔
Gixy-Next는 Docker Hub 또는 GitHub Registry에서 Docker 이미지로 사용할 수 있습니다.
로컬 구성 파일을 컨테이너에 마운트하여 스캔합니다:
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf
NGINX 라이브 구성 덤프를 스캔합니다:
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf
stdin에서 스캔합니다:
# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -
할 수 있는 일
Gixy-Next는 nginx.conf 및 포함된 구성 파일 전반에서 광범위한 NGINX 보안 및 성능 설정 오류를 탐지할 수 있습니다. 다음 플러그인이 지원됩니다:
- [add_header_content_type] add_header를 통한 Content-Type 설정
- [add_header_multiline] 여러 줄 응답 헤더
- [add_header_redefinition] "add_header" 지시문에 의한 응답 헤더 재정의
- [alias_traversal] 잘못 구성된 alias를 통한 경로 순회
- [allow_without_deny] deny 없이 지정된 allow
- [default_server_flag] default_server 플래그 누락
- [error_log_off]
error_log가off로 설정됨 - [hash_without_default] hash 블록에 default 누락
- [host_spoofing] 요청의 Host 헤더 위조
- [http2_misdirected_request] HTTP/2 misdirected-request 보호 조치 누락
- [http_splitting] HTTP 응답 분할
- [if_is_evil] location 컨텍스트에서 사용될 때 if는 악마
- [invalid_regex] 잘못된 정규식 캡처 그룹
- [low_keepalive_requests] 낮은
keepalive_requests - [missing_worker_processes]
worker_processes누락 - [mixed_case_variable] 대소문자 혼용 변수 참조
- [origins] referer/origin 헤더 검증 문제
- [overlapping_captures] rewrite redirect/args 컨텍스트에서 겹치는 캡처
- [proxy_buffering_off]
proxy_buffering비활성화 - [proxy_pass_normalized]
proxy_pass경로 정규화 문제 - [proxy_set_header_redefinition] "proxy_set_header" 지시문에 의한 프록시 요청 헤더 재정의
- [quic_bpf_reuseport] 리로드 후 QUIC 연결이 조용히 끊김
- [regex_redos] 정규식 서비스 거부 (ReDoS)
- [resolver_external] 외부 DNS 네임서버 사용
- [return_bypasses_allow_deny] return 지시문이 allow/deny 제한을 우회함
- [ssl_ecdh_curve] 포스트 양자 그룹이 구형 OpenSSL에서 NGINX 시작을 막음
- [ssl_stapling_letsencrypt] Let's Encrypt 인증서에 대해 OCSP 스테이플링이 아무 효과 없음
- [ssl_stapling_without_resolver] resolver 없이 OCSP 스테이플링이 조용히 실패함
- [ssrf] 서버 측 요청 위조
- [stale_dns_cache] proxy_pass에서 사용되는 오래된/만료된 캐시 DNS 레코드
- [status_page_exposed] status_page가 외부에 노출되지 않도록 보장
- [try_files_is_evil_too] open_file_cache 없이는
try_files지시문이 악마 - [unanchored_regex] 앵커되지 않은 정규식
- [unnamed_groups] rewrite 쿼리 문자열의 이름 없는 캡처 그룹
- [valid_referers] valid_referers의 none/blocked
- [version_disclosure] server_tokens에 안전하지 않은 값 사용
- [worker_rlimit_nofile_vs_connections]
worker_rlimit_nofile은worker_connections의 최소 두 배여야 함
탐지되지 않는 항목이 있나요? 누락된 내용과 함께 GitHub에 이슈를 열어주세요!
사용법 (플래그)
gixy는 기본적으로 시스템의 NGINX 구성을 /etc/nginx/nginx.conf에서 읽습니다. gixy에 경로를 전달하여 위치를 지정할 수도 있습니다:
# Analyze the configuration in /opt/nginx.conf
gixy /opt/nginx.conf
--tests로 특정 검사 하위 집합만 실행할 수 있습니다:
# Only run these checks
gixy --tests http_splitting,ssrf,version_disclosure
또는 --skips로 몇 가지 시끄러운 검사를 건너뛸 수 있습니다:
# Run everything except these checks
gixy --skips low_keepalive_requests,worker_rlimit_nofile_vs_connections
특정 심각도 이상의 문제만 보고하려면 누적되는 -l 플래그를 사용합니다:
# -l for LOW severity issues and higher, -ll for MEDIUM and higher, and -lll for only HIGH severity issues
gixy -ll
기본적으로 gixy의 출력은 ANSI 색상이 적용되며, 호환되는 터미널에서 가장 잘 보입니다. --format (-f) 플래그에 text 값을 사용하면 색상 없는 출력을 얻을 수 있습니다:
$ gixy -f text
==================== Results ===================
Problem: [http_splitting] Possible HTTP-Splitting vulnerability.
Description: Using variables that can contain "\n" may lead to http injection.
Additional info: https://gixy.io/plugins/http_splitting/
Reason: At least variable "$action" can contain "\n"
Pseudo config:
include /etc/nginx/sites/default.conf;
server {
location ~ /v1/((?<action>[^.]*)\.json)?$ {
add_header X-Action $action;
}
}
==================== Summary ===================
Total issues:
Informational: 0
Low: 0
Medium: 0
High: 1
-f json을 사용하면 재현 가능한 기계 판독 가능 JSON 출력을 얻을 수도 있습니다:
