1
0
Fork 0
forked from svrjs/svrjs

Added validation of X-Forwarded-For header

This commit is contained in:
Dorian Niemiec 2023-09-03 14:40:41 +02:00
parent d8cf7913be
commit b1ab6e3e4a
3 changed files with 42 additions and 56 deletions

View file

@ -1,9 +1,9 @@
{ {
"users": [], "users": [],
"port": 80, "port": 5555,
"pubport": 80, "pubport": 80,
"page404": "404.html", "page404": "404.html",
"timestamp": 1693732189583, "timestamp": 1693743065822,
"blacklist": [], "blacklist": [],
"nonStandardCodes": [], "nonStandardCodes": [],
"enableCompression": true, "enableCompression": true,
@ -91,7 +91,7 @@
"/.*\\.img$/", "/.*\\.img$/",
"/.*\\.iso$/" "/.*\\.iso$/"
], ],
"enableIPSpoofing": false, "enableIPSpoofing": true,
"secure": false, "secure": false,
"sni": {}, "sni": {},
"disableNonEncryptedServer": false, "disableNonEncryptedServer": false,

58
svr.js
View file

@ -2838,14 +2838,19 @@ if (!cluster.isPrimary) {
} }
// Set up X-Forwarded-For // Set up X-Forwarded-For
var reqport = ""; var reqip = req.socket.remoteAddress;
var reqip = ""; var reqport = req.socket.remotePort;
var oldport = "";
var oldip = ""; var oldip = "";
if (req.headers["x-forwarded-for"] != undefined && enableIPSpoofing) { var oldport = "";
var isForwardedValid = true;
if(enableIPSpoofing) {
if (req.headers["x-forwarded-for"] != undefined) {
var preparedReqIP = req.headers["x-forwarded-for"].split(",")[0].replace(/ /g, "");
var preparedReqIPvalid = net.isIP(preparedReqIP);
if(preparedReqIPvalid) {
if (preparedReqIPvalid == 4 && req.socket.remoteAddress && req.socket.remoteAddress.indexOf(":") > -1) preparedReqIP = "::ffff:" + preparedReqIP;
reqip = preparedReqIP
reqport = null; reqport = null;
reqip = req.headers["x-forwarded-for"].split(",")[0].replace(/ /g, "");
if (reqip.indexOf(":") == -1) reqip = "::ffff:" + reqip;
try { try {
oldport = req.socket.remotePort; oldport = req.socket.remotePort;
oldip = req.socket.remoteAddress; oldip = req.socket.remoteAddress;
@ -2861,8 +2866,9 @@ if (!cluster.isPrimary) {
// Address setting failed // Address setting failed
} }
} else { } else {
reqip = req.socket.remoteAddress; isForwardedValid = false;
reqport = req.socket.remotePort; }
}
} }
reqcounter++; reqcounter++;
@ -3324,33 +3330,6 @@ if (!cluster.isPrimary) {
return; return;
} }
var reqport = "";
var reqip = "";
var oldport = "";
var oldip = "";
if (req.headers["x-forwarded-for"] != undefined && enableIPSpoofing) {
reqport = null;
reqip = req.headers["x-forwarded-for"].split(",")[0].replace(/ /g, "");
if (reqip.indexOf(":") == -1) reqip = "::ffff:" + reqip;
try {
oldport = req.socket.remotePort;
oldip = req.socket.remoteAddress;
req.socket.realRemotePort = reqport;
req.socket.realRemoteAddress = reqip;
req.socket.originalRemotePort = oldport;
req.socket.originalRemoteAddress = oldip;
res.socket.realRemotePort = reqport;
res.socket.realRemoteAddress = reqip;
res.socket.originalRemotePort = oldport;
res.socket.originalRemoteAddress = oldip;
} catch (err) {
// Nevermind...
}
} else {
reqip = req.socket.remoteAddress;
reqport = req.socket.remotePort;
}
// Function to check the level of a path relative to the web root // Function to check the level of a path relative to the web root
function checkPathLevel(path) { function checkPathLevel(path) {
// Split the path into an array of components based on "/" // Split the path into an array of components based on "/"
@ -4090,11 +4069,18 @@ if (!cluster.isPrimary) {
} }
} }
// Check for invalid X-Forwarded-For header
if(!isForwardedValid) {
serverconsole.errmessage("X-Forwarded-For header is invalid.");
callServerError(400);
return;
}
// Handle redirects to HTTPS // Handle redirects to HTTPS
if(secure && !fromMain && !disableNonEncryptedServer && !disableToHTTPSRedirect) { if(secure && !fromMain && !disableNonEncryptedServer && !disableToHTTPSRedirect) {
var hostx = req.headers.host; var hostx = req.headers.host;
if (hostx === undefined) { if (hostx === undefined) {
serverconsole.errmessage("Bad request!"); serverconsole.errmessage("Host header is missing.");
callServerError(400); callServerError(400);
return; return;
} }

View file

@ -1 +1 @@
53 55