https://depthfirst.com/nginx-rift
Uncategorized
4
Posts
4
Posters
0
Views
-
https://depthfirst.com/nginx-rift
Anyone running nginx? Noone does that right?
-
https://depthfirst.com/nginx-rift
Anyone running nginx? Noone does that right?
@mcfly the vulnerable rewrite looks suspicious even without the flaw

-
https://depthfirst.com/nginx-rift
Anyone running nginx? Noone does that right?
> The bug is reachable only when an unnamed PCRE capture is paired with a replacement string that contains a question mark, followed by a rewrite, if, or set directive in the same scope.
… Gesundheit?
-
https://depthfirst.com/nginx-rift
Anyone running nginx? Noone does that right?
@mcfly if anyone is I’ve made a plugin for gixy-next to check for the rewrite directives that might be an issue.
-
R relay@relay.publicsquare.global shared this topic