Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Gixy-Next — Gixy-Next:NGINX 配置安全扫描器与性能检查器 | Kitploit
工具/GitHubGitHub/megamansec/gixy-next
静态分析漏洞扫描器配置审计Web安全云安全DevSecOps硬件安全错误配置
GitHubmegamansec/gixy-next

Gixy-Next

Gixy-Next:NGINX 配置安全扫描器与性能检查器

查看仓库
18442616天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

Gixy-Next:用于安全审计的 NGINX 配置安全扫描器

概述

Gixy-Next Mascot Logo

Gixy-Next(Gixy)是一款开源的 NGINX 配置安全扫描器和加固工具,可对您的 nginx.conf 进行静态分析,在配置进入生产环境之前检测安全配置错误、加固缺口以及常见的性能陷阱。它是 Yandex 的 Gixy 的一个积极维护的分支。Gixy-Next 的源代码可在 GitHub 上获取。

Gixy-Next 也可以在浏览器中在此页面运行。无需下载;您可以在网站上扫描您的配置(在本地,使用 WebAssembly)。

快速开始

Gixy-Next(gixy 或 gixy-next CLI)发布在 PyPI 上。您可以使用 pip 或 uv 安装它:

# pip
pip3 install gixy-next
# uv
uv pip install gixy-next

然后您可以运行它:

# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf

您也可以将 NGINX 配置导出为单个转储文件(参见 nginx -T Live Configuration Dump):

# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -

基于 Web 的扫描器

无需在本地下载并运行 Gixy-Next,您可以使用此网页并从您的 Web 浏览器中扫描配置(在本地,使用 WebAssembly)。

使用 Docker 扫描

Gixy-Next 以 Docker 镜像形式提供,可从 Docker Hub 或 GitHub Registry 获取。

通过将本地配置文件挂载到容器中来扫描它:

# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf

扫描 NGINX 实时配置转储:

# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf

从 stdin 扫描:

# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -

它能做什么

Gixy-Next 可以检测 nginx.conf 及包含的配置文件中广泛的 NGINX 安全和性能配置错误。支持以下插件:

  • [add_header_content_type] Setting Content-Type via add_header
  • [add_header_multiline] Multiline response headers
  • [add_header_redefinition] Redefining of response headers by "add_header" directive
  • [alias_traversal] Path traversal via misconfigured alias
  • [allow_without_deny] Allow specified without deny
  • [default_server_flag] Missing default_server flag
  • [error_log_off] error_log set to off
  • [hash_without_default] Missing default in hash blocks
  • [host_spoofing] Request's Host header forgery
  • [http2_misdirected_request] Missing HTTP/2 misdirected-request safeguard
  • [http_splitting] HTTP Response Splitting
  • [if_is_evil] If is evil when used in location context
  • [invalid_regex] Invalid regex capture groups
  • [low_keepalive_requests] Low keepalive_requests
  • [missing_worker_processes] Missing worker_processes
  • [mixed_case_variable] Mixed-case variable references
  • [origins] Problems with referer/origin header validation
  • [overlapping_captures] Overlapping captures in rewrite redirect/args context
  • [proxy_buffering_off] Disabling proxy_buffering
  • [proxy_pass_normalized] proxy_pass path normalization issues
  • [proxy_set_header_redefinition] Redefining of proxied request headers by "proxy_set_header" directive
  • [quic_bpf_reuseport] QUIC connections silently dropped after reload
  • [regex_redos] Regular expression denial of service (ReDoS)
  • [resolver_external] Using external DNS nameservers
  • [return_bypasses_allow_deny] Return directive bypasses allow/deny restrictions
  • [ssl_ecdh_curve] Post-quantum groups stop NGINX from starting on older OpenSSL
  • [ssl_stapling_letsencrypt] OCSP stapling does nothing for a Let's Encrypt certificate
  • [ssl_stapling_without_resolver] OCSP stapling silently fails without a resolver
  • [ssrf] Server Side Request Forgery
  • [stale_dns_cache] Outdated/stale cached DNS records used in proxy_pass
  • [status_page_exposed] Ensures that status_page is not exposed to the world
  • [try_files_is_evil_too] try_files directive is evil without open_file_cache
  • [unanchored_regex] Unanchored regular expressions
  • [unnamed_groups] Unnamed capture groups in rewrite query string
  • [valid_referers] none/blocked in valid_referers
  • [version_disclosure] Using insecure values for server_tokens
  • [worker_rlimit_nofile_vs_connections] worker_rlimit_nofile must be at least twice worker_connections

有未检测到的问题?请在 GitHub 上提交一个 issue,说明缺少什么!

用法(标志)

gixy 默认从 /etc/nginx/nginx.conf 读取系统的 NGINX 配置。您也可以通过将其传递给 gixy 来指定位置:

# Analyze the configuration in /opt/nginx.conf
gixy /opt/nginx.conf

您可以使用 --tests 运行一个聚焦的检查子集:

# Only run these checks
gixy --tests http_splitting,ssrf,version_disclosure

或者使用 --skips 跳过一些嘈杂的检查:

# Run everything except these checks
gixy --skips low_keepalive_requests,worker_rlimit_nofile_vs_connections

要仅报告某一严重级别或更高级别的问题,请使用可叠加的 -l 标志:

# -l for LOW severity issues and higher, -ll for MEDIUM and higher, and -lll for only HIGH severity issues
gixy -ll

默认情况下,gixy 的输出是 ANSI 着色的;最好在兼容的终端中查看。您可以使用 --format(-f)标志并指定 text 值来获得无着色输出:

$ gixy -f text

==================== Results ===================
下载工具