改进SQL注入检测

This commit is contained in:
刘祥超
2022-03-19 15:41:25 +08:00
parent b6f4e5ce13
commit a3bd4b1b0a

View File

@@ -376,7 +376,7 @@ func HTTPFirewallTemplate() *HTTPFirewallPolicy {
IsOn: true,
Param: "${requestAll}",
Operator: HTTPFirewallRuleOperatorMatch,
Value: `(updatexml|extractvalue|ascii|ord|char|chr|count|concat|rand|floor|substr|length|len|user|database|benchmark|analyse)\s*\(`,
Value: `\b(updatexml|extractvalue|ascii|ord|char|chr|count|concat|rand|floor|substr|length|len|user|database|benchmark|analyse)\s*\(.*\)`,
IsCaseInsensitive: true,
})