Skip to content

New Rules Proposal: Detect usage of RemoteIPHeader directive in an apache configuration.#3748

Open
righettod wants to merge 1 commit intosemgrep:developfrom
righettod:apache-remoteipheader
Open

New Rules Proposal: Detect usage of RemoteIPHeader directive in an apache configuration.#3748
righettod wants to merge 1 commit intosemgrep:developfrom
righettod:apache-remoteipheader

Conversation

@righettod
Copy link
Contributor

Hello,

This generic rule for apache is intended to detect when the directive RemoteIPHeader is used. The goal is for inform about the potential risks of unexpected DNS queries if the value of the header is not checked via for example a rewrite rule.

I tested the rule against the sample code using the online rule editor:

image

Thank you very much for your feedback ๐Ÿ˜‰

@righettod
Copy link
Contributor Author

Hi,
Any news about this PR?
Thanks for your feedback ๐Ÿ˜‰

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant