虚拟主机域名注册-常见问题虚拟主机问题 → 虚拟主机问题


网站低危漏洞通过伪静态功能处理方法
作者:

Windows主机

Windows主机需要在wwwroot目录下的web.config里面添加以下规则:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.web>
        <httpCookies httpOnlyCookies="true"  requireSSL="true"  />
    </system.web>
    <system.webServer>
        <security>
            <requestFiltering>
                <verbs allowUnlisted="true">
                    <add verb="OPTIONS" allowed="false"/>
                    <add verb="TRACE" allowed="false"/>
                </verbs>
            </requestFiltering>
       </security>
       <httpProtocol>
           <customHeaders>
               <!--检测到目标X-Content-Type-Options响应头缺失-->
               <add name="X-Content-Type-Options" value="nosniff" />
               <!--检测到目标X-XSS-Protection响应头缺失-->
               <add name="X-XSS-Protection" value="1;mode=block" />
               <!--检测到目标Content-Security-Policy响应头缺失 /-->
               <add name="Content-Security-Policy" value="default-src 'self' 'unsafe-inline' ; img-src 'self' data:" />
               <!--检测到目标Strict-Transport-Security响应头缺失-->
               <add name="Strict-Transport-Security" value="max-age=31536000" />
               <!--检测到目标Referrer-Policy响应头缺失-->
               <add name="Referrer-Policy" value="origin-when-cross-origin" />
               <!--检测到目标X-Permitted-Cross-Domain-Policies响应头缺失-->
               <add name="X-Permitted-Cross-Domain-Policies" value="master-only" />
               <!--检测到目标X-Download-Options响应头缺失-->
               <add name="X-Download-Options" value="noopen" />
               <!--点击劫持:X-Frame-Options未配置-->
               <add name="X-Frame-Options" value="SAMEORIGIN" />
           </customHeaders>
       </httpProtocol>
        <rewrite>       
        <outboundRules>
            <rule name="Add HttpOnly" preCondition="No HttpOnly">
                <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" />
                <action type="Rewrite" value="{R:0}; HttpOnly" />
                <conditions>
                </conditions>
            </rule>
            <preConditions>
                <preCondition name="No HttpOnly">
                    <add input="{RESPONSE_Set_Cookie}" pattern="." />
                    <add input="{RESPONSE_Set_Cookie}" pattern="; HttpOnly" negate="true" />
                </preCondition>
            </preConditions>
        </outboundRules>
        </rewrite>
    </system.webServer>
</configuration>

 

请注意规则必须要添加节点,如果添加错误会导致网站无法打开。

 

  • Linux主机

wwwroot目录下的.htaccess中添加以下规则:

 

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.web>
        <httpCookies httpOnlyCookies="true"  requireSSL="true"  />
    </system.web>
    <system.webServer>
        <security>
            <requestFiltering>
                <verbs allowUnlisted="true">
                    <add verb="OPTIONS" allowed="false"/>
                    <add verb="TRACE" allowed="false"/>
                </verbs>
            </requestFiltering>
       </security>
       <httpProtocol>
           <customHeaders>
               <!--检测到目标X-Content-Type-Options响应头缺失-->
               <add name="X-Content-Type-Options" value="nosniff" />
               <!--检测到目标X-XSS-Protection响应头缺失-->
               <add name="X-XSS-Protection" value="1;mode=block" />
               <!--检测到目标Content-Security-Policy响应头缺失 /-->
               <add name="Content-Security-Policy" value="default-src 'self' 'unsafe-inline' ; img-src 'self' data:" />
               <!--检测到目标Strict-Transport-Security响应头缺失-->
               <add name="Strict-Transport-Security" value="max-age=31536000" />
               <!--检测到目标Referrer-Policy响应头缺失-->
               <add name="Referrer-Policy" value="origin-when-cross-origin" />
               <!--检测到目标X-Permitted-Cross-Domain-Policies响应头缺失-->
               <add name="X-Permitted-Cross-Domain-Policies" value="master-only" />
               <!--检测到目标X-Download-Options响应头缺失-->
               <add name="X-Download-Options" value="noopen" />
               <!--点击劫持:X-Frame-Options未配置-->
               <add name="X-Frame-Options" value="SAMEORIGIN" />
           </customHeaders>
       </httpProtocol>
        <rewrite>       
        <outboundRules>
            <rule name="Add HttpOnly" preCondition="No HttpOnly">
                <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" />
                <action type="Rewrite" value="{R:0}; HttpOnly" />
                <conditions>
                </conditions>
            </rule>
            <preConditions>
                <preCondition name="No HttpOnly">
                    <add input="{RESPONSE_Set_Cookie}" pattern="." />
                    <add input="{RESPONSE_Set_Cookie}" pattern="; HttpOnly" negate="true" />
                </preCondition>
            </preConditions>
        </outboundRules>
        </rewrite>
    </system.webServer>
</configuration>


# .htaccess只能管的了静态文件,php动态程序是要php代码中设置。

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.web>
        <httpCookies httpOnlyCookies="true"  requireSSL="true"  />
    </system.web>
    <system.webServer>
        <security>
            <requestFiltering>
                <verbs allowUnlisted="true">
                    <add verb="OPTIONS" allowed="false"/>
                    <add verb="TRACE" allowed="false"/>
                </verbs>
            </requestFiltering>
       </security>
       <httpProtocol>
           <customHeaders>
               <!--检测到目标X-Content-Type-Options响应头缺失-->
               <add name="X-Content-Type-Options" value="nosniff" />
               <!--检测到目标X-XSS-Protection响应头缺失-->
               <add name="X-XSS-Protection" value="1;mode=block" />
               <!--检测到目标Content-Security-Policy响应头缺失 /-->
               <add name="Content-Security-Policy" value="default-src 'self' 'unsafe-inline' ; img-src 'self' data:" />
               <!--检测到目标Strict-Transport-Security响应头缺失-->
               <add name="Strict-Transport-Security" value="max-age=31536000" />
               <!--检测到目标Referrer-Policy响应头缺失-->
               <add name="Referrer-Policy" value="origin-when-cross-origin" />
               <!--检测到目标X-Permitted-Cross-Domain-Policies响应头缺失-->
               <add name="X-Permitted-Cross-Domain-Policies" value="master-only" />
               <!--检测到目标X-Download-Options响应头缺失-->
               <add name="X-Download-Options" value="noopen" />
               <!--点击劫持:X-Frame-Options未配置-->
               <add name="X-Frame-Options" value="SAMEORIGIN" />
           </customHeaders>
       </httpProtocol>
        <rewrite>       
        <outboundRules>
            <rule name="Add HttpOnly" preCondition="No HttpOnly">
                <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" />
                <action type="Rewrite" value="{R:0}; HttpOnly" />
                <conditions>
                </conditions>
            </rule>
            <preConditions>
                <preCondition name="No HttpOnly">
                    <add input="{RESPONSE_Set_Cookie}" pattern="." />
                    <add input="{RESPONSE_Set_Cookie}" pattern="; HttpOnly" negate="true" />
                </preCondition>
            </preConditions>
        </outboundRules>
        </rewrite>
    </system.webServer>
</configuration>

NGINX规则 添加到站点配置文件server里

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.web>
        <httpCookies httpOnlyCookies="true"  requireSSL="true"  />
    </system.web>
    <system.webServer>
        <security>
            <requestFiltering>
                <verbs allowUnlisted="true">
                    <add verb="OPTIONS" allowed="false"/>
                    <add verb="TRACE" allowed="false"/>
                </verbs>
            </requestFiltering>
       </security>
       <httpProtocol>
           <customHeaders>
               <!--检测到目标X-Content-Type-Options响应头缺失-->
               <add name="X-Content-Type-Options" value="nosniff" />
               <!--检测到目标X-XSS-Protection响应头缺失-->
               <add name="X-XSS-Protection" value="1;mode=block" />
               <!--检测到目标Content-Security-Policy响应头缺失 /-->
               <add name="Content-Security-Policy" value="default-src 'self' 'unsafe-inline' ; img-src 'self' data:" />
               <!--检测到目标Strict-Transport-Security响应头缺失-->
               <add name="Strict-Transport-Security" value="max-age=31536000" />
               <!--检测到目标Referrer-Policy响应头缺失-->
               <add name="Referrer-Policy" value="origin-when-cross-origin" />
               <!--检测到目标X-Permitted-Cross-Domain-Policies响应头缺失-->
               <add name="X-Permitted-Cross-Domain-Policies" value="master-only" />
               <!--检测到目标X-Download-Options响应头缺失-->
               <add name="X-Download-Options" value="noopen" />
               <!--点击劫持:X-Frame-Options未配置-->
               <add name="X-Frame-Options" value="SAMEORIGIN" />
           </customHeaders>
       </httpProtocol>
        <rewrite>       
        <outboundRules>
            <rule name="Add HttpOnly" preCondition="No HttpOnly">
                <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" />
                <action type="Rewrite" value="{R:0}; HttpOnly" />
                <conditions>
                </conditions>
            </rule>
            <preConditions>
                <preCondition name="No HttpOnly">
                    <add input="{RESPONSE_Set_Cookie}" pattern="." />
                    <add input="{RESPONSE_Set_Cookie}" pattern="; HttpOnly" negate="true" />
                </preCondition>
            </preConditions>
        </outboundRules>
        </rewrite>
    </system.webServer>
</configuration>


注意:无论windows还是Linux主机,添加规则即可生效不需要做其他设置。




来源:
阅读:15
日期:2026-04-22

【 双击滚屏 】 【 推荐朋友 】 【 收藏 】 【 打印 】 【 关闭 】 【 字体: 】 
上一篇:网站被系统入侵监控扫描到木马以后如何恢复网站
下一篇:网站域名被墙了如何判断解决
  >> 相关文章
 
点我咨询