mirror of
https://github.com/zedeus/nitter
synced 2026-09-05 22:59:31 +00:00
Fix SSRF in /video proxy and API JSON injection
Validate the target host on the /video media route with isTwitterUrl() (mirroring /pic) and reject non-http(s) schemes, and stop the media proxy following redirects off the validated host. JSON-escape user-controlled GraphQL cursors and build id variables with packedjson so untrusted input can't break out of the query. Warn on startup when the insecure default hmacKey is in use. Fixes #1411
This commit is contained in:
parent
7b27c2c629
commit
44b2f096f6
7 changed files with 69 additions and 22 deletions
|
|
@ -34,6 +34,10 @@ stdout.flushFile
|
|||
updateDefaultPrefs(fullCfg)
|
||||
setCacheTimes(cfg)
|
||||
setHmacKey(cfg.hmacKey)
|
||||
if cfg.hmacKey.len == 0 or cfg.hmacKey == "secretkey":
|
||||
stderr.write "WARNING: insecure default 'hmacKey' in nitter.conf; " &
|
||||
"set a unique random value to stop media URL signatures being forgeable.\n"
|
||||
stderr.flushFile
|
||||
setProxyEncoding(cfg.base64Media)
|
||||
setMaxHttpConns(cfg.httpMaxConns)
|
||||
setHttpProxy(cfg.proxy, cfg.proxyAuth)
|
||||
|
|
|
|||
Loading…
Reference in a new issue