Gixy-Next(Gixy)是一款开源的 NGINX 配置安全扫描器和加固工具,可对您的 nginx.conf 进行静态分析,在配置进入生产环境之前检测安全配置错误、加固缺口以及常见的性能陷阱。它是 Yandex 的 Gixy 的一个积极维护的分支。Gixy-Next 的源代码可在 GitHub 上获取。
Gixy-Next 也可以在浏览器中在此页面运行。无需下载;您可以在网站上扫描您的配置(在本地,使用 WebAssembly)。
Gixy-Next(gixy 或 gixy-next CLI)发布在 PyPI 上。您可以使用 pip 或 uv 安装它:
# pip
pip3 install gixy-next
# uv
uv pip install gixy-next
然后您可以运行它:
# gixy defaults to reading /etc/nginx/nginx.conf
gixy
# But you can also specify a path to the configuration
gixy /opt/nginx.conf
您也可以将 NGINX 配置导出为单个转储文件(参见 nginx -T Live Configuration Dump):
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Scan the dump elsewhere (or via stdin):
gixy ./nginx-dump.conf
# or
cat ./nginx-dump.conf | gixy -
无需在本地下载并运行 Gixy-Next,您可以使用此网页并从您的 Web 浏览器中扫描配置(在本地,使用 WebAssembly)。
Gixy-Next 以 Docker 镜像形式提供,可从 Docker Hub 或 GitHub Registry 获取。
通过将本地配置文件挂载到容器中来扫描它:
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" ghcr.io/megamansec/gixy-next /nginx.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx.conf:/nginx.conf:ro" megamansec/gixy-next /nginx.conf
扫描 NGINX 实时配置转储:
# Dumps the full NGINX configuration into a single file (including all includes)
nginx -T > ./nginx-dump.conf
# Use Github Registry
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" ghcr.io/megamansec/gixy-next /nginx-dump.conf
# Or Docker Hub
docker run --pull=always --rm -v "$PWD/nginx-dump.conf:/nginx-dump.conf:ro" megamansec/gixy-next /nginx-dump.conf
从 stdin 扫描:
# Use Github Registry
nginx -T | docker run --pull=always --rm -i ghcr.io/megamansec/gixy-next gixy-next -
# Or Docker Hub
nginx -T | docker run --pull=always --rm -i megamansec/gixy-next gixy-next -
Gixy-Next 可以检测 nginx.conf 及包含的配置文件中广泛的 NGINX 安全和性能配置错误。支持以下插件:
error_log set to offkeepalive_requestsworker_processesproxy_bufferingproxy_pass path normalization issuestry_files directive is evil without open_file_cacheworker_rlimit_nofile must be at least twice worker_connections有未检测到的问题?请在 GitHub 上提交一个 issue,说明缺少什么!
gixy 默认从 /etc/nginx/nginx.conf 读取系统的 NGINX 配置。您也可以通过将其传递给 gixy 来指定位置:
# Analyze the configuration in /opt/nginx.conf
gixy /opt/nginx.conf
您可以使用 --tests 运行一个聚焦的检查子集:
# Only run these checks
gixy --tests http_splitting,ssrf,version_disclosure
或者使用 --skips 跳过一些嘈杂的检查:
# Run everything except these checks
gixy --skips low_keepalive_requests,worker_rlimit_nofile_vs_connections
要仅报告某一严重级别或更高级别的问题,请使用可叠加的 -l 标志:
# -l for LOW severity issues and higher, -ll for MEDIUM and higher, and -lll for only HIGH severity issues
gixy -ll
默认情况下,gixy 的输出是 ANSI 着色的;最好在兼容的终端中查看。您可以使用 --format(-f)标志并指定 text 值来获得无着色输出:
$ gixy -f text
==================== Results ===================