Blame view

buildroot/buildroot-2016.08.1/package/nginx-naxsi/Config.in 1.04 KB
6b13f685e   김민수   BSP 최초 추가
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
  config BR2_PACKAGE_NGINX_NAXSI
  	bool "nginx-naxsi"
  	help
  	  NAXSI means Nginx Anti XSS & SQL Injection.
  
  	  Technically, it is a third party nginx module, available as
  	  a package for many UNIX-like platforms. This module, by
  	  default, reads a small subset of simple (and readable) rules
  	  containing 99% of known patterns involved in website
  	  vulnerabilities. For example, <, | or drop are not supposed
  	  to be part of a URI.
  
  	  Being very simple, those patterns may match legitimate
  	  queries, it is the Naxsi's administrator duty to add
  	  specific rules that will whitelist legitimate
  	  behaviours. The administrator can either add whitelists
  	  manually by analyzing nginx's error log, or (recommended)
  	  start the project with an intensive auto-learning phase that
  	  will automatically generate whitelisting rules regarding a
  	  website's behaviour.
  
  	  In short, Naxsi behaves like a DROP-by-default firewall, the
  	  only task is to add required ACCEPT rules for the target
  	  website to work properly.
  
  	  https://github.com/nbs-system/naxsi