From a8c0a0464e45e3133ecad873a17360efc078df9e Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sun, 23 Aug 2026 17:07:14 -1000 Subject: Refuse unknown and spoofed hostnames in nginx.conf --- custom/servers/nginx.conf | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) (limited to 'custom/servers') diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf index f26598c..cf1e49f 100644 --- a/custom/servers/nginx.conf +++ b/custom/servers/nginx.conf @@ -80,6 +80,37 @@ http { gzip_types text/css text/javascript text/plain application/atom+xml; + # Requests carrying a Host header this config does not serve, a raw IP or + # an invented name from a scanning bot, land in these two blocks and are + # dropped without a response. cgit keys its page cache on the Host header + # so clone URLs stay honest, which means every invented hostname reaching + # it would mint a cache entry of its own and evict a real page to make + # room. Refusing strangers here keeps the cache to the names the site + # actually answers to. 444 is nginx shorthand for closing the connection + # without replying. + server { + listen 80 default_server; + listen [::]:80 default_server; + server_name _; + return 444; + } + + server { + listen 443 ssl default_server; + listen [::]:443 ssl default_server; + server_name _; + # Refuse the TLS handshake itself when the SNI name is unknown, which + # also spares this block from needing a certificate. Requires nginx + # 1.19.4 or newer. On older builds point ssl_certificate at any cert, + # a self-signed one included, and rely on the return below. + ssl_reject_handshake on; + # A client can still handshake against a real name and then send some + # other Host header. Those requests route here after the handshake, + # past the rejection above, so close them too. + return 444; + } + + # Bounce plain HTTP up to HTTPS. Delete this whole server block if you # serve plain HTTP only. server { -- cgit v2.8.0