lizongbo at 618119.com 工作,生活,Android,前端,Linode,Ubuntu,nginx,java,apache,tomcat,Resin,mina,Hessian,XMPP,RPC

2010年11月29日

使用CRLFFilter过滤HTTP应答头信息名称和值的非法字符防止CRLF注入攻击

Filed under: Java,Web — 标签:, , , , — lizongbo @ 10:02

使用CRLFFilter过滤http应答中头信息名称和值的非法字符,防止CRLF注入攻击
经过测试Resin的response.addHeader方法也没做header名字和值的检查,因此如果webapp代码写法不当的话,将导致CRLF注入攻击,

例如一个页面从url参数中获取地址燃尽进行跳转,如果url地址存在“%0d%0a”编码表示的CRLF而未被检测过滤(.net.URL解析不会出错,必须用java.net.URI才行),将产生安漏洞。

通过下面的代码可以重现这个Xss漏洞攻击。
jsp代码:
<%
response.addHeader(“X-Locationaaa: http://mqq.im/\r\nX-tesh”,”aaa”);
response.addHeader(“X-Locationbbb: 汉字/\r\nX-teshbbb”,”aaa”);

//下面的goUrl可以从URL的参数中获取,如果url地址存在“%0d%0a”编码表示的CRLF而未被检测过滤(java.net.URL解析不会出错,必须用java.net.URI才行),将产生漏洞。

String goUrl=”http://lizongbo.com/\r\nX-Location: http://618119.com/”;
//goUrl=java.net.URLEncoder.encode(goUrl, “UTF-8”);
response.sendError(403,goUrl);
%>

在Firefox中访问jsp,使用Live HTTP headers 可以看到生成的实际head如下:

HTTP/1.1 403 http://lizongbo.com/
X-Location: http://618119.com/
Server: Resin/4.0.10
X-Locationaaa: http://mqq.im/
X-tesh: aaa
X-Locationbbb: 汉字
X-teshbbb: aaa
Content-Type: text/html; charset=utf-8
Content-Length: 216
Date: Tue, 09 Nov 2010 02:37:48 GMT

因此封装过滤器代码如下:
[code]
package com.lizongbo.web.;

import java.io.IOException;

import javax.servlet.Filter;
import javax.servlet.FilterChain;
import javax.servlet.FilterConfig;
import javax.servlet.ServletException;
import javax.servlet.ServletRequest;
import javax.servlet.ServletResponse;
import javax.servlet.http.HttpServletResponse;

public class CRLFFilter implements Filter {

@Override
public void destroy() {

}

@Override
public void doFilter(ServletRequest req, ServletResponse res,
FilterChain chain) throws IOException, ServletException {
HttpServletResponse response = new CRLFFilterResponseWrapper(
(HttpServletResponse) res);
chain.doFilter(req, response);
}

@Override
public void init(FilterConfig config) throws ServletException {

}

}

[/code]

[code]
package com.lizongbo.web.filter;

import java.io.IOException;
import java.util.Arrays;

import javax.servlet.http.HttpServletResponse;
import javax.servlet.http.HttpServletResponseWrapper;

public class CRLFFilterResponseWrapper extends HttpServletResponseWrapper {
/**
* http name 不允许出现的字符
*/
private static final char[] headerName_tspecials = new char[] { ‘(‘, ‘)’,
‘<‘, ‘>’, ‘@’, ‘,’, ‘;’, ‘:’, ‘\\’, ‘\”‘, ‘/’, ‘[‘, ‘]’, ‘?’, ‘=’,
‘{‘, ‘}’ };
static {
Arrays.sort(headerName_tspecials);
}

HttpServletResponse response = null;

public CRLFFilterResponseWrapper(HttpServletResponse response)
throws IOException {
super(response);
this.response = response;
}

@Override
public void addHeader(String name, String value) {
super.addHeader(filterHeaderName(name), filterHeaderValue(value));
}

@Override
public void sendError(int sc, String msg) throws IOException {
super.sendError(sc, filterHeaderValue(msg));
}

@Override
public void sendRedirect(String location) throws IOException {
super.sendRedirect(filterHeaderValue(location));
}

@Override
public void setHeader(String name, String value) {
super.setHeader(filterHeaderName(name), filterHeaderValue(value));
}

@Override
public void setStatus(int sc, String sm) {
super.setStatus(sc, filterHeaderValue(sm));
}

@Override
public void addDateHeader(String name, long date) {
super.addDateHeader(filterHeaderName(name), date);
}

@Override
public void addIntHeader(String name, int value) {
super.addIntHeader(filterHeaderName(name), value);
}

@Override
public void setDateHeader(String name, long date) {
super.setDateHeader(filterHeaderName(name), date);
}

@Override
public void setIntHeader(String name, int value) {
super.setIntHeader(filterHeaderName(name), value);
}
@Override
public void setContentType(String contentType) {
super.setContentType(filterHeaderValue(contentType));
}

/**
*过滤头信息名字中的非法字符,避免CRLF注入攻击

Many HTTP/1.1 header field values consist of words separated by LWS<br/>
or special characters. These special characters MUST be in a quoted<br/>
string to be used within a parameter value.<br/>

token          = 1*<any CHAR except CTLs or tspecials><br/>

tspecials      = “(” | “)” | “<” | “>” | “@”<br/>
| “,” | “;” | “:” | “\” | <“><br/>
| “/” | “[” | “]” | “?” | “=”<br/>
| “{” | “}” | SP | HT <br/>
CTL            = <any US-ASCII control character<br/>
(octets 0 – 31) and DEL (127)><br/>
SP             = <US-ASCII SP, space (32)><br/>
HT             = <US-ASCII HT, horizontal-tab (9)><br/>

* @param name
* @return
*/
private static String filterHeaderName(String name) {
if (name == null || name.length() < 1) {
return “null”;
}
StringBuilder sb = new StringBuilder(name.length());
for (int i = 0; i < name.length(); i++) {
char c = name.charAt(i);
if (c > 32 && c < 127
&& Arrays.binarySearch(headerName_tspecials, c) < 0) {
sb.append(c);
}
}
return sb.toString();
}

/**
*过滤头信息值中的非法字符,避免CRLF注入攻击

* field-value = *( field-content | LWS )<br/>
*
* field-content = <the OCTETs making up the field-value<br/>
* and consisting of either *TEXT or combinations<br/>
* of token, tspecials, and quoted-string><br/>
*
* @param value
* @return
*/
private static String filterHeaderValue(String value) {
if (value == null || value.length() < 1) {
return “null”;
}
StringBuilder sb = new StringBuilder(value.length());
for (int i = 0; i < value.length(); i++) {
char c = value.charAt(i);
if (c >= 32 && c < 127) {
sb.append(c);
}
}
return sb.toString();
}

public static void main(String[] args) {
String headName = “aaaa aaa\r\n bbb “;
String headvalue = “cccccccccc\r\n ddd”;
System.out.println(headName + “==” + filterHeaderName(headName));
System.out.println(headvalue + “==” + filterHeaderValue(headvalue));
}
}
[/code]

参考链接:

http://www.ietf.org/rfc/rfc2068.txt
http://www.acunetix.com/websitesecurity/crlf-injection.htm
http://comic.sjtu.edu.cn/bbs/view.asp?TID=4118

没有评论 »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment

Powered by WordPress