diff options
| author | Xe Iaso <me@xeiaso.net> | 2025-03-21 17:20:17 -0400 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2025-03-21 17:20:17 -0400 |
| commit | 5f7942faca06e844996cbaa0c342fc39d9bc121d (patch) | |
| tree | 23d4af3daaad2e7a25ddaaa77fc016b1a6e940cd | |
| parent | 869e46a4cc80a63d62e73d384b066b305049c935 (diff) | |
| download | anubis-5f7942faca06e844996cbaa0c342fc39d9bc121d.tar.xz anubis-5f7942faca06e844996cbaa0c342fc39d9bc121d.zip | |
cmd/anubis: delete example RSS reader rule (#67)v1.14.2
The example/default bot policy document had a rule to allow RSS readers
through based on paths that end with ".rss", ".xml", ".atom", or
".json". Frameworks like Rails will treat these specially, meaning that
going to /things/12345-whateverhaha.json could bypass Anubis.
I checked the history of this rule and it was present in the original
example policy file in Xe/x. This rule is likely a mistake and it has
been removed. I think it was for making my blog still work with RSS
readers.
Thanks to Graham Sutherland for reporting this over email.
Signed-off-by: Xe Iaso <me@xeiaso.net>
| -rw-r--r-- | VERSION | 2 | ||||
| -rw-r--r-- | cmd/anubis/botPolicies.json | 5 | ||||
| -rw-r--r-- | docs/docs/CHANGELOG.md | 6 |
3 files changed, 7 insertions, 6 deletions
@@ -1 +1 @@ -1.14.1
\ No newline at end of file +1.14.2 diff --git a/cmd/anubis/botPolicies.json b/cmd/anubis/botPolicies.json index 2785d87..aad2e9e 100644 --- a/cmd/anubis/botPolicies.json +++ b/cmd/anubis/botPolicies.json @@ -364,11 +364,6 @@ "action": "ALLOW" }, { - "name": "rss-readers", - "path_regex": ".*\\.(rss|xml|atom|json)$", - "action": "ALLOW" - }, - { "name": "lightpanda", "user_agent_regex": "^Lightpanda/.*$", "action": "DENY" diff --git a/docs/docs/CHANGELOG.md b/docs/docs/CHANGELOG.md index 56190b3..8c59f7d 100644 --- a/docs/docs/CHANGELOG.md +++ b/docs/docs/CHANGELOG.md @@ -11,6 +11,12 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## v1.14.2 + +Livia sas Junius: Echo 2 + +- Remove default RSS reader rule as it may allow for a targeted attack against rails apps + [#67](https://github.com/TecharoHQ/anubis/pull/67) - Whitelist MojeekBot in botPolicies [#47](https://github.com/TecharoHQ/anubis/issues/47) ## v1.14.1 |
