Skip to content
KitploitKITPLOIT
FerramentasBlog
Log in
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

FeedsContatoPrivacidade© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Gixy-Next — Gixy-Next: Scanner de Segurança de Configuração NGINX & Verificador de Desempenho | Kitploit
Ferramentas/GitHubGitHub/megamansec/gixy-next
Análise EstáticaScanners de VulnerabilidadesAuditoria de ConfiguraçãoSegurança WebSegurança na NuvemDevSecOpsSegurança de HardwareConfiguração Incorreta
GitHubmegamansec/gixy-next

Gixy-Next

Gixy-Next: Scanner de Segurança de Configuração NGINX & Verificador de Desempenho

Ver Repositório
184429há 17 diasRevisado pelo Kitploit
Site

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Gixy-Next: Scanner de Segurança para Configurações NGINX para Auditorias de Segurança

Visão Geral

Gixy-Next Mascot Logo

Gixy-Next (Gixy) é um scanner de segurança e ferramenta de hardening para configurações NGINX de código aberto que analisa estaticamente seu nginx.conf para detectar configurações incorretas de segurança, lacunas de hardening e armadilhas de desempenho comuns antes que cheguem à produção. É um fork ativamente mantido do Gixy do Yandex. O código-fonte do Gixy-Next está disponível no GitHub.

O Gixy-Next também pode ser executado no navegador nesta página. Não é necessário download; você pode escanear suas configurações no site (localmente, usando WebAssembly).

Início rápido

O Gixy-Next (a CLI gixy ou gixy-next) é distribuído no PyPI. Você pode instalá-lo com pip ou uv:

# pip
pip3 install gixy-next
# uv
uv pip install gixy-next

Você pode então executá-lo:

# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf

Você também pode exportar sua configuração NGINX para um único arquivo de dump (veja nginx -T Live Configuration Dump):

# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -

Scanner baseado na web

Em vez de baixar e executar o Gixy-Next localmente, você pode usar esta página web e escanear uma configuração diretamente do seu navegador (localmente, usando WebAssembly).

Escanear com Docker

O Gixy-Next está disponível como imagem Docker no Docker Hub ou no GitHub Registry.

Escanear um arquivo de configuração local montando-o no contêiner:

# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf

Escanear um dump de configuração NGINX em execução:

# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf

Escanear a partir de stdin:

# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -

O que ele pode fazer

O Gixy-Next pode detectar uma ampla variedade de configurações incorretas de segurança e desempenho do NGINX em nginx.conf e arquivos de configuração incluídos. Os seguintes plugins são suportados:

  • [add_header_content_type] Setting Content-Type via add_header
  • [add_header_multiline] Multiline response headers
  • [add_header_redefinition] Redefining of response headers by "add_header" directive
  • [alias_traversal] Path traversal via misconfigured alias
  • [allow_without_deny] Allow specified without deny
  • [default_server_flag] Missing default_server flag
  • [error_log_off] error_log set to off
  • [hash_without_default] Missing default in hash blocks
  • [host_spoofing] Request's Host header forgery
  • [http2_misdirected_request] Missing HTTP/2 misdirected-request safeguard
  • [http_splitting] HTTP Response Splitting
  • [if_is_evil] If is evil when used in location context
  • [invalid_regex] Invalid regex capture groups
  • [low_keepalive_requests] Low keepalive_requests
  • [missing_worker_processes] Missing worker_processes
  • [mixed_case_variable] Mixed-case variable references
  • [origins] Problems with referer/origin header validation
  • [overlapping_captures] Overlapping captures in rewrite redirect/args context
  • [proxy_buffering_off] Disabling proxy_buffering
  • [proxy_pass_normalized] proxy_pass path normalization issues
  • [proxy_set_header_redefinition] Redefining of proxied request headers by "proxy_set_header" directive
  • [quic_bpf_reuseport] QUIC connections silently dropped after reload
  • [regex_redos] Regular expression denial of service (ReDoS)
  • [resolver_external] Using external DNS nameservers
  • [return_bypasses_allow_deny] Return directive bypasses allow/deny restrictions
  • [ssl_ecdh_curve] Post-quantum groups stop NGINX from starting on older OpenSSL
  • [ssl_stapling_letsencrypt] OCSP stapling does nothing for a Let's Encrypt certificate
  • [ssl_stapling_without_resolver] OCSP stapling silently fails without a resolver
  • [ssrf] Server Side Request Forgery
  • [stale_dns_cache] Outdated/stale cached DNS records used in proxy_pass
  • [status_page_exposed] Ensures that status_page is not exposed to the world
  • [try_files_is_evil_too] try_files directive is evil without open_file_cache
  • [unanchored_regex] Unanchored regular expressions
  • [unnamed_groups] Unnamed capture groups in rewrite query string
  • [valid_referers] none/blocked in valid_referers
  • [version_disclosure] Using insecure values for server_tokens
  • [worker_rlimit_nofile_vs_connections] worker_rlimit_nofile must be at least twice worker_connections

Algo não detectado? Por favor, abra uma issue no GitHub informando o que está faltando!

Uso (flags)

Baixar ferramenta