github baidu/openrasp v0.30
Version 0.30

latest releases: v1.3.7, v1.3.6, v1.3.5...
6 years ago

中文说明

Breaking changes

  • Java agent
    • Debug level option debug_level now renamed to debug.level

New features

API changes

  • Add stack parameter for both directory and ssrf hook points

Algorithm improvements

  • SQLi detections
    • Block UNION NULL queries
    • Block blind injection releated functions, e.g ordchr
  • Java - Anti deserialize exploits
    • Block command execution via YsoSerial payloads
  • PHP - china chopper detection
    • Block suspicious file manager, command execution via stack validation algorithm
    • Block simple webshells that directly evaluate user inputs
  • PHP - block unusual callbacks
    • Please refer to openrasp.callable_blacklists for more details

Don't miss a new openrasp release

NewReleases is sending notifications on new releases.