From b9869e0abd0f2dcff93655235f8d2298f9bca0b2 Mon Sep 17 00:00:00 2001 From: loveshell <82163261@qq.com> Date: Wed, 27 Mar 2013 10:38:23 +0800 Subject: [PATCH] =?UTF-8?q?=E6=81=A2=E5=A4=8D=E7=99=BE=E5=88=86=E5=8F=B7?= =?UTF-8?q?=E6=9B=BF=E6=8D=A2=EF=BC=8C=E5=A2=9E=E5=8A=A0=E7=BC=96=E7=A0=81?= =?UTF-8?q?=E5=89=8D=E7=9A=84=E7=99=BE=E5=88=86=E5=8F=B7=E6=9B=BF=E6=8D=A2?= =?UTF-8?q?=EF=BC=8C=E6=B3=A8=E9=87=8A=EF=BC=8C=E9=9C=80=E8=A6=81=E5=8F=AF?= =?UTF-8?q?=E8=87=AA=E8=A1=8C=E5=BC=80=E5=90=AF?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- waf.lua | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/waf.lua b/waf.lua index e328da5..7d7d611 100644 --- a/waf.lua +++ b/waf.lua @@ -3,10 +3,13 @@ if ngx.re.match(ngx.var.request_uri,whitelist,"isjo") then elseif ngx.req.get_body_data() and ngx.re.match(ngx.req.get_body_data(),[[^(?!Content-Disposition: form-data;(.*)filename="(.*).(php|jsp|phtml|asp|aspx|cgi)").*$]],"isjo") then return else - if ngx.re.match(ngx.unescape_uri(ngx.var.request_uri),regex.."|"..get,"isjo") then + if ngx.re.match(string.gsub(ngx.unescape_uri(ngx.var.request_uri),"\\%",""),regex.."|"..get,"isjo") then log('GET',ngx.unescape_uri(ngx.var.request_uri)) check() - elseif ngx.req.get_body_data() and ngx.re.match(ngx.unescape_uri(ngx.req.get_body_data()),regex,"isjo")then + -- elseif ngx.re.match(string.gsub(ngx.var.request_uri,"\\%",""),regex.."|"..get,"isjo") then +-- log('GET',ngx.var.request_uri) +-- check() + elseif ngx.req.get_body_data() and ngx.re.match(string.gsub(ngx.unescape_uri(ngx.req.get_body_data()),"\\%",""),regex,"isjo")then log('POST',ngx.unescape_uri(ngx.var.request_uri),ngx.unescape_uri(ngx.req.get_body_data())) check() -- elseif ngx.req.get_headers()["Cookie"] and ngx.re.match(ngx.unescape_uri(ngx.req.get_headers()["Cookie"]),regex,"isjo")then