http {
...
# 隐藏版本信息
server_tokens off;
...
}
···
location / {
...
# 隐藏powered-by
proxy_hide_header X-Powered-By;
...
}
···
add_header 内容安全策略“default-src 'self'; img-src '自我' *.alicdn.com; 对象-src'无';script-src 'self' *.alicdn.com; style-src 'self ' *.alicdn.com;frame-ancestors 'self';base-uri 'self';form-action 'self'";
add_header X-Content-Type-Options nosniff;
add_header 严格传输安全“max-age=31536000;includeSubDomains”;
add_header X-Frame-Options SAMEORIGIN;
add_header 访问控制允许来源 *;
add_header Access-Control-Allow-Origin *.xx.com;
add_header X-XSS-保护“1;模式=阻止”;
add_header Set-Cookie "Path=/; HttpOnly; 安全";
proxy_cookie_path / "/; httponly; secure; SameSite=None";
设置$cors“”;
if ($http_origin ~* (.*\.atpool.com)) {
设置 $cors $http_origin;
add_header
访问控制允许来源 $cors;
add_header 访问控制允许方法“GET、POST、OPTIONS、DELETE、PUT”;
add_header Access-Control-Allow-Credentials true;
add_header 访问控制允许标头 *;
if ($request_method = "选项") {
返回 204;
}
服务器{
听80;
服务器名称 test.xx.com;
# 证书设置
ssl_certificate cert/xx.com.pem;
ssl_certificate_key cert/xx.com.key;
ssl_session_timeout 5m;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE -RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
# 只启用TLS1.2以上
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers 开启;
# 安全相关设置
add_header Content-Security-Policy "default-src 'self' *.xx.com data: 'unsafe-inline';";
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" 始终;
add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-保护“1;模式=阻止”;
add_header Set-Cookie "Path=/; HttpOnly; 安全";
add_header 缓存控制 max-age=86400;
# 跨域设置
set $cors "";
if ($http_origin ~* (.*\.xx.com)) {
设置 $cors $http_origin;
add_header
访问控制允许来源 $cors;
add_header 访问控制允许方法“GET、POST、OPTIONS、DELETE、PUT”;
add_header Access-Control-Allow-Credentials true;
add_header 访问控制允许标头 *;
if ($request_method = "选项") {
返回 204;
}
位置/{
gzip 打开;
gzip_comp_level 6;
gzip_min_length 1k;
gzip_buffers 4 16k;
gzip_types 文本/普通应用程序/x-javascript 文本/css 应用程序/xml 应用程序/javascript 应用程序/json 应用程序/vnd.ms-fontobject 字体/ttf 字体/opentype 字体/x-woff 图像/svg+xml;
proxy_pass http://127.0.0.1:8000;
proxy_hide_header X-Powered-By;# 隐藏由 proxy_cookie_path 提供支持的
/ "/; httponly; secure; SameSite=None";
proxy_set_header X-真实IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header 主机 $http_host;
proxy_redirect 默认值;
}
}
服务器 {
监听 80;
服务器名称 test.xx.com;
# 证书设置
ssl_certificate cert/xx.com.pem;
ssl_certificate_key cert/xx.com.key;
ssl_session_timeout 5m;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE -RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
# 只启用TLS1.2以上
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers 开启;
# 安全相关设置
add_header Content-Security-Policy "default-src 'self' *.xx.com data:
'不安全内联';"; add_header 严格传输安全 "max-age=31536000; 始终包含子域”;
add_header X-Frame-Options SAMEORIGIN;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-保护“1;模式=阻止”;
add_header Set-Cookie "Path=/; HttpOnly; 安全";
add_header 缓存控制 max-age=86400;
# 跨域设置
set $cors "";
if ($http_origin ~* (.*\.xx.com)) {
设置 $cors $http_origin;
add_header
访问控制允许来源 $cors;
add_header 访问控制允许方法“GET、POST、OPTIONS、DELETE、PUT”;
add_header Access-Control-Allow-Credentials true;
add_header 访问控制允许标头 *;
if ($request_method = "选项") {
返回 204;
}
位置/{
gzip 打开;
gzip_comp_level 6;
gzip_min_length 1k;
gzip_buffers 4 16k;
gzip_types 文本/普通应用程序/x-javascript 文本/css 应用程序/xml 应用程序/javascript 应用程序/json 应用程序/vnd.ms-fontobject 字体/ttf 字体/opentype 字体/x-woff 图像/svg+xml;
proxy_pass http://127.0.0.1:8000;
proxy_hide_header X-Powered-By;# 隐藏由 proxy_cookie_path 提供支持的
/ "/; httponly; secure; SameSite=None";
proxy_set_header X-真实IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header 主机 $http_host;
proxy_redirect默认值;
}
}
欢迎光临 黑帽联盟 (https://bbs.cnblackhat.com/) | Powered by Discuz! X2.5 |