Sign inSign up

detoxd/nginx

By detoxd

•Updated 6 months ago

Image
0

1.7K

detoxd/nginx repository overview

⁠NGINX - Detoxd Hardened Image

⁠Overview

NGINX is a high-performance HTTP server, reverse proxy, and load balancer created by Igor Sysoev in 2004. Originally designed to solve the C10K problem (handling 10,000+ concurrent connections), NGINX has become one of the most widely deployed web servers in the world.

⁠Common Use Cases

  • Web Server - Serving static content with exceptional performance
  • Reverse Proxy - Forwarding requests to backend application servers
  • Load Balancer - Distributing traffic across multiple servers
  • API Gateway - Managing and routing API traffic
  • SSL/TLS Termination - Handling encryption at the edge
  • Caching - Improving response times with content caching

⁠Security Concerns

NGINX, like any web-facing software, can be vulnerable to:

  • Server Information Disclosure - Default configurations expose version information
  • Buffer Overflow Vulnerabilities - Memory corruption bugs in parsing
  • HTTP Request Smuggling - Inconsistent request handling
  • Denial of Service - Resource exhaustion attacks
  • Path Traversal - Misconfigured location blocks

⁠What Detoxd Does

⁠Security Headers
  • Disables server tokens (server_tokens off;) to hide version information
  • Adds X-Content-Type-Options: nosniff to prevent MIME sniffing
  • Adds X-Frame-Options: DENY to prevent clickjacking
  • Adds X-XSS-Protection: 1; mode=block for XSS protection
⁠System Hardening
  • Updates all Alpine/Debian packages to latest versions
  • Removes setuid/setgid bits from all binaries
  • Removes unnecessary tools (curl, wget, etc.)
  • Removes default HTML pages
  • Cleans package caches
⁠Best Practices Applied
  • Non-root user available for running nginx
  • Minimal attack surface
  • Security-focused configuration
# Add to your nginx.conf
http {
    # Rate limiting
    limit_req_zone $binary_remote_addr zone=one:10m rate=10r/s;
    
    # SSL hardening
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_prefer_server_ciphers on;
    ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256;
    
    # Hide version
    server_tokens off;
    
    # Security headers
    add_header X-Content-Type-Options "nosniff" always;
    add_header X-Frame-Options "DENY" always;
    add_header Content-Security-Policy "default-src 'self'" always;
    add_header Referrer-Policy "strict-origin-when-cross-origin" always;
}

⁠References

Tag summary

Content type

Image

Digest

sha256:962f68e85…

Size

24.9 MB

Last updated

6 months ago

docker pull detoxd/nginx:1.29.7-alpine3.23-detox.1