From f3a6461eaa62588ec8364f1b85cdf6acacc37cb8 Mon Sep 17 00:00:00 2001 From: Dave <12233528+kawaiipantsu@users.noreply.github.com> Date: Tue, 21 Feb 2023 01:13:52 +0100 Subject: [PATCH] Fixing uri max size Changing URI max size from 1024 to 1280 bytes --- docker/nginx/dist/conf/tpotweb.conf | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/docker/nginx/dist/conf/tpotweb.conf b/docker/nginx/dist/conf/tpotweb.conf index 68065cba..384fe6ea 100644 --- a/docker/nginx/dist/conf/tpotweb.conf +++ b/docker/nginx/dist/conf/tpotweb.conf @@ -46,7 +46,11 @@ server { client_body_buffer_size 128k; client_header_buffer_size 1k; client_max_body_size 2M; - large_client_header_buffers 2 1k; + + ### Changed from OWASP defaults + ### To suit Kibana (long ajax uris) breaking 1024 + ### Still keeping it very true to 1k + large_client_header_buffers 2 1280; ### Mitigate Slow HHTP DoS Attack ### Timeouts definition ##