tomcat下配置web.xml修復不安全的請求方法漏洞。

1、黑名單方式:

<security-constraint>
<web-resource-collection>
                <web-resource-name>fortune</web-resource-name>
                <url-pattern>/*</url-pattern>
                <http-method>PUT</http-method>
                <http-method>DELETE</http-method>
                <http-method>HEAD</http-method>
                <http-method>OPTIONS</http-method>
                <http-method>TRACE</http-method>
</web-resource-collection>
<auth-constraint></auth-constraint>
</security-constraint>
<login-config>
                <auth-method>BASIC</auth-method>
</login-config>

2、白名單請求方式:

禁用除了GET、POST之外的所有方法。

<security-constraint>
<web-resource-collection>
                <web-resource-name>fortune</web-resource-name>
                <url-pattern>/*</url-pattern>
                <http-method-omission>GET</http-method-omission>
                <http-method-omission>POST</http-method-omission>
</web-resource-collection>
<auth-constraint></auth-constraint>
</security-constraint>
<login-config>
                <auth-method>BASIC</auth-method>
</login-config>

 

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章