2. 在Web Server 7.0上,向obj.conf文件中添加以下规则覆盖包含有Digest字符串的Authorization头:
<If defined $headers{'authorization'} and $headers{'authorization'} =~ "(?i)digest">
NameTrans fn="set-variable" $headers{'authorization'} = "refuse"
</If>
厂商补丁:
Sun
---
Sun已经为此发布了一个安全公告(Sun-Alert-6916389)以及相应补丁:
Sun-Alert-6916389:Multiple security vulnerabilities in the HTTP TRACE, WebDAV and Digest Authentication Methods in the Sun Java System Web Server and Sun Java System Web Proxy Server
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-66-275850-1