3 ms·
I cannot find any any information on how this data is sanitized. /safe/path/$hostname.key $hostname = ../../etc/some/secret /safe/path/../../etc/some/
by clon 8y ago
I cannot find any any information on how this data is sanitized.
/safe/path/$hostname.key
$hostname = ../../etc/some/secret
/safe/path/../../etc/some/secret.key
- vegardx 8y agoThat wouldn't be a valid hostname or Host-header, see https://tools.ietf.org/html/rfc952 https://tools.ietf.org/html/rfc952
- an_account_name 8y agoHost headers are transmitted after the ssl handshake.
- duncaen 8y agoSNI?
- an_account_name 8y agoI read through the codebase and can't assert that couldn't happen... wasn't sure if the ngx_http_ssl_certificate callback could be executed after a point where any of the client-controlled variables from [1] are defined. [1] - https://nginx.org/en/docs/http/ngx_http_ssl_module.html#variables https://nginx.org/en/docs/http/ngx_http_ssl_module.html#vari...