找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12526|回复: 0

利用ModSecurity在Nginx上构建WAF

[复制链接]
发表于 2017-10-19 17:34:51 | 显示全部楼层 |阅读模式
ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。
/ z, l9 A# R1 C! i  B% h5 s' O% [4 x  G/ @6 k
5 v6 r3 o) d) S6 V: J0 U3 j$ Q* ~! N
在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。
+ S% J# K$ ^' n% J0 w2 A4 @2 ~% f+ s* U  c: |

+ m" B) q; G! P什么是ModSecurity$ j) @2 Y5 c; X8 {% H
ModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。' z0 R0 q# N; R6 u2 ?  k9 G. T
1 s5 p5 j0 T( O& v
) f. C; \8 T5 A+ f
ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。
6 V: K+ Z, {* |" M+ x3 J! Q" B
% y6 T+ W5 d# T6 _1 w0 l
ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。$ |6 F% R" G0 L) L; Q' L
8 _: N  E7 ?) P; I; w
$ k% e* `# Q9 U6 |
官网: https://www.modsecurity.org/
5 `& p, ~( W7 h; Y; t& \4 T: I
( d2 D* ~/ \: ^5 s/ b  L1 I% h$ k9 u9 ^3 |+ c5 d3 |1 ]
什么是OWASP CRS/ R/ o9 ?3 b3 f) }% x
OWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。
2 O- M* s0 l% F' n7 G+ P, t8 X( Z2 z" n: r+ {# p1 |9 y8 j  o

* S" k3 J9 S- IModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。
) c2 K, K' T" `0 `7 R. I, T+ }2 A2 |8 L* \! @' r5 Z( T, |$ v
1 @* W6 b% b4 q  b4 P6 H3 T, q% o6 M
HTTP Protection(HTTP防御)
$ m, O! a* [+ K! Q7 a0 W% r  CHTTP协议和本地定义使用的detectsviolations策略。' K2 v3 V4 p$ x6 ^7 r$ u
1 K- w+ T% g5 j0 ?

! g  b+ e. I$ W: B, a, kReal-time Blacklist Lookups(实时黑名单查询)
  _9 Y7 L  M6 u: U利用第三方IP名单。, M# b% ]8 S. D+ f
& G, D% V4 y7 F8 M/ h+ U$ M1 g' R. G
! ?; V- T# @/ J8 i
HTTP Denial of Service Protections(HTTP的拒绝服务保护)& A( h. W  O' T
防御HTTP的洪水攻击和HTTP Dos攻击。$ S1 \0 N# b7 T* I7 N
( X2 U! F2 M0 C( b

4 A( |8 Y' @4 yCommon Web Attacks Protection(常见的Web攻击防护)
- o& l8 w. Z. e5 F$ t0 s检测常见的Web应用程序的安全攻击。0 {1 q* l1 D% E! |. x1 M& F8 z' u& A

5 J& `' C5 R2 y  R) f* p% V6 ?: v) k4 V$ x- O! n
Automation Detection(自动化检测)# P! D* w- e, q  l* i
检测机器人,爬虫,扫描仪和其他表面恶意活动。1 G% w# k+ h7 T2 x6 }$ b

5 K! l  B1 O  a9 u
: e+ _5 G" `+ l( y% l+ E4 d7 b& D; LIntegration with AV Scanning for File Uploads(文件上传防病毒扫描)6 B* R) p; p- z5 b( v/ A' g9 _9 c
检测通过Web应用程序上传的恶意文件。
( B1 B1 n  k) p* Z! \; X
! u( ]9 R) r/ \7 m1 d+ i
6 M5 a1 P1 y  d1 g' D% h  rTracking Sensitive Data(跟踪敏感数据)2 @( C! f0 K4 M8 v4 N7 ^% }( T
信用卡通道的使用,并阻止泄漏。! i4 @6 }' U) o; O! q5 y8 l
1 G0 I( A# V# B# ~! o

3 p$ N! b+ C. ^% [5 u4 @* ~6 [Trojan Protection(木马防护)
# X4 Y1 Y5 r! H- ^# t# N. T* w' N检测访问木马。7 {/ {+ K- W" D: u' {/ V
5 ~2 s$ ?5 X2 N& E4 @/ J
$ K" U- l5 Y& l, o* X5 {; f
Identification of Application Defects(应用程序缺陷的鉴定)# S1 i& M' S+ L- O4 r  [; R$ k
检测应用程序的错误配置警报。
& @/ S  U; Z. K8 b# m8 l; t$ A# C' r; x

- N6 C1 ^5 g& f/ Q  _+ vError Detection and Hiding(错误检测和隐藏)1 N+ J* A+ D( W5 _
检测伪装服务器发送错误消息。- h) N" s# ^  D4 n7 i
/ C3 k1 \! ^, a. j9 M% ?" M! B

  C/ _% f- F) q' P- O$ D安装ModSecurity
- x" I  l: _2 z6 ?4 S, t软件基础环境准备6 p1 _* O* |8 x6 o
下载对应软件包
4 p1 z; m1 i) o! O5 V1 ]# T8 Y$ cd /root4 T, u- q7 H. {* A3 X* F4 H
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
" \: n) _) \# x' F$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz( d2 c" w# \2 Y# V4 \/ z( a
安装Nginx和ModSecurity依赖包
4 ?* ~2 s0 }* V* s. e3 b. }9 Z7 lCentos/RHEL
- K- K2 z; B  q+ U7 _" d- f3 Y- h4 r8 L  x3 Z# f

# X8 ]9 ?9 E: S: A$ yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel
) R) ?. t# X+ B- ]0 ]Ubuntu/Debian  b+ o* p8 D4 k  S
6 O! P2 T* w/ u8 Y, |, c
1 Q! a5 l4 i5 ^1 H2 S: D
$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git  libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev
* D0 t  ?4 X- A# D% n" Q: O编译安装ModSecurity7 [+ J6 p6 L; c3 S0 ]
Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。, x" t9 E. Z! m4 r% s

! h7 w# l. L. X& ^" r( S5 R) Z3 X/ o  d" G5 L. r0 v( I: l
方法一:编译为Nginx静态模块
" J! {, i6 n; C1 R& o! A2 d( U2 |8 R# j9 p7 o8 I# ?0 \( t5 w
  C, Y- |, w4 U% z8 b
编译为独立模块(modsecurity-2.9.1)
# b5 d; o& I2 S# |$ tar xzvf modsecurity-2.9.1.tar.gz! u2 Q- R7 C6 d' q8 P2 g
$ cd modsecurity-2.9.1/
0 R3 S! w0 o+ c* B" J$ ./autogen.sh8 E, |% u! M1 Y" m  Z; f9 m
$ ./configure --enable-standalone-module --disable-mlogc
+ y/ N4 \) D9 O8 C' U$ make
5 t4 y! n; c6 V/ o& u1 {) k编译安装Nginx并添加ModSecurity模块
: E! H7 H5 A' I8 l$ tar xzvf nginx-1.9.2.tar.gz
, I3 [1 @$ ^# c2 b$ cd nginx-1.9.2
$ q8 D, R! X$ W: g1 q$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/
6 `/ y# k1 m$ w) U$ make && make install
, e+ M+ t/ r7 c! Z" d方法二:编译通过ModSecurity-Nginx Connector加载的动态模块3 Q2 c2 _+ h- ~  H

$ g8 j. f" a+ K7 N. A$ e% ]5 B: q7 ?6 q* `0 Y9 A' |9 u
编译LibModSecurity(modsecurity-3.0)
  c/ Z/ j# W5 u- \7 A) m" z  c2 ?$ cd /root! g. l) d, ^  m, }" t! U' T
$ git clone https://github.com/SpiderLabs/ModSecurity
) x- d. U% N3 ?) U4 t$ cd ModSecurity
* _" x7 {9 p* T# A& n: }$ git checkout -b v3/master origin/v3/master
8 h( c- `: H/ G6 Y2 h$ sh build.sh
5 H* f+ [4 I4 k9 Y& `4 \; s$ git submodule init# b# F3 m  i% ]( S8 R
$ git submodule update
, j4 m3 c' w, Q' W$ ./configure
) A9 @/ O& \7 u- B- m9 w$ make( K& h+ O& O, s' x" u
$ make install6 ?6 s- m/ j4 J# S2 B( Z
LibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。
7 C3 Y6 V3 m% |" r0 I: K. I) r$ N/ O7 v

" L! K+ O) @5 ^) o$ ls /usr/local/modsecurity/lib
! W& i' V6 u! Q# mlibmodsecurity.a  libmodsecurity.la  libmodsecurity.so  libmodsecurity.so.3  libmodsecurity.so.3.0.0
* T3 C* m+ A% z4 B编译安装Nginx并添加ModSecurity-Nginx Connector模块
# [  o  T7 A6 p$ ^: l4 q+ e! K' T  Y- p使用ModSecurity-Nginx模块来连接LibModSecurity( H1 e' `. i' f5 O" V0 x- g9 ?3 a

; T8 F  _4 b0 q7 e& K( o  c5 R
2 ^; Q& @" m8 l: C: Q* y1 T: K9 N$ cd /root. J# p7 B1 F  H" V
$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx
# f% Q5 d& `' Q2 v7 a$ tar xzvf nginx-1.9.2.tar.gz1 ]* R! s3 @5 N* P8 ~
$ cd nginx-1.9.2/ E) [9 i# q8 s9 @
$ ./configure --add-module=/root/modsecurity-nginx" u! \  D/ b8 q( y% `
$ make/ y" n1 \0 R1 p) P$ `
$ make && make install- _6 Q! m! z7 h( Q9 o
添加OWASP规则* w" z7 h+ P- X7 V. }( n
ModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。
- E4 U; b9 X$ J8 I' x. m% H& [/ s8 L& Q& ]+ F$ ~+ k% I! B
# I- }  g* y7 ]
下载OWASP规则并生成配置文件
4 @) `# y. t' n$ Z8 _; o$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git/ M+ M6 U( z* B
$ cp -rf owasp-modsecurity-crs  /usr/local/nginx/conf/) Y/ s  ?9 B& x: r. \
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
, M) y' A; f9 |- N; G- Q& r$ cp crs-setup.conf.example  crs-setup.conf
: M1 b9 V+ D1 P( c; @; O8 z; |配置OWASP规则
" W! j) D4 |# ]: ]编辑crs-setup.conf文件1 v3 W  P5 b$ Q" ]

, y  [; F9 p" j1 a( L) k- Y% r
3 I* q$ L7 V+ L' b! @$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf! ?: h8 h, O) r. E
$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf! L4 f1 D* o6 C
$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf
9 K) F9 |! A3 |- q) ~9 I$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf3 D5 E9 \1 @9 s4 f8 D, S
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。/ M5 _, J: N6 s# P0 o

; X+ X' s9 f" K7 Z$ w- A0 n: W9 y$ v" c" u
启用ModSecurity模块和CRS规则4 ~, j' j1 U2 ~. W2 e! E
复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。* Y; U9 q! m. O' ]# r) C- k: k8 [4 B7 V9 q

) O! C3 C9 o# P' v
; Q$ A* U3 [. S; b# G# r) vmodsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。
* \4 R( a% `, k' n$ F8 T% Z+ C& i: ?

4 @% k$ d; z8 T* |$ cd /root/modsecurity-2.9.1/9 o! g6 v3 q/ t# I" R
$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf  
3 `1 c5 n7 b! L5 [$ cp unicode.mapping  /usr/local/nginx/conf/
( X- L; n9 M. l( C6 V4 T将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。: X) X  D; Y2 w& g& D% \4 K# d

+ J; y3 W; j; H6 M( V9 v& _
$ ]0 L$ f, a; J* ^' }5 x$ vim /usr/local/nginx/conf/modsecurity.conf4 L2 j9 I0 a7 \$ a" B  ^
SecRuleEngine On
, P7 l9 F: Z: Y4 p) [( N$ [- P3 GModSecurity中几个常用配置说明:
0 C) i; u% g7 E2 X2 T; u
. O% X5 F4 ~: t1 P3 R/ y. q9 }+ D% x
1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。
$ ~& U0 @! U+ P4 p6 n8 ^. d+ ^1 `8 ]

, K7 S) A! \( ]7 W2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。  e# [6 i, z" S1 l

8 [3 L; I& L+ H  x6 y5 o$ ^* M  ?8 g' x
3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。
3 g/ I: A0 t' }! F1 H& f, [, q2 f) Y, J: T5 {

( }/ O# P% L( o9 ^% R4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。9 g2 V) |7 X, [

& `( \& ]* F2 w( @7 l" I: S
% ~! N1 A) I5 z; n4 n在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。
' t9 d0 u2 b2 z4 y
  N* n1 I$ d$ h5 s, c- P) `6 T9 u( s( H% Z+ n- L9 u9 a# l
3.x版本CRS
, B/ W3 @% ~8 k3 n6 `* Z/ w$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
$ \" w, L9 T" D6 a) o  L6 h# 生成例外排除请求的配置文件- ~- W6 M( p9 D9 ~; U) ]+ p1 j/ S. x. c
$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf2 `% e6 u3 \2 t) w
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
! M, @( \* Q0 O+ n9 v$ cp rules/*.data /usr/local/nginx/conf4 J. G' E+ D/ R$ b
为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。
- T0 q8 |: D# F0 q2 y) V( H3 P2 b& q0 i; U3 @$ L2 ]# ^% A, O

# a' u! }3 W9 {' O( g- s  f" V$ vim /usr/local/nginx/conf/modsec_includes.conf9 z, }' @3 r5 J) A
; ~" W  {9 k3 A" `- Y8 P8 b
[Bash shell] 纯文本查看 复制代码
include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
+ R: f1 f5 h! _+ E! u& {% i

( W: U/ _, e+ Y8 N; `3 \注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。
5 S) f# w" d2 {- z! r
  _: o6 S$ ^) `9 f
9 p8 D# q+ K5 n配置Nginx支持Modsecurity: i( {- }1 P( ?; ^$ Y( D4 H2 ]' ?
启用Modsecurity
8 F) B  b- n( f: ~) w$ |使用静态模块加载的配置方法# c8 h/ M5 E4 {7 H4 h2 k% s" J6 q) P
在需要启用Modsecurity的主机的location下面加入下面两行即可:7 }0 m% F1 f; I0 L
" G; y2 V. g) f5 j

+ X# @* y8 Q7 [ModSecurityEnabled on;
! g. y' n8 Y+ `ModSecurityConfig modsec_includes.conf;
$ D1 V/ v' I0 ~) P) ~" G1 G修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。/ Q; c/ ]2 s0 O  m. l: }9 M+ s

1 Y  b3 ?2 s- n. g8 |9 h. @7 A. Y4 q5 i) P( c# B
$ vim /usr/local/nginx/conf/nginx.conf
; p/ B) j! y' U+ g! M, }
7 n! s6 t6 b5 E2 O1 u3 l# s2 W7 R+ D) y( l! q& u" w
server {+ ]8 o6 t; j: X, [/ t# o$ v
  listen       80;6 k* f; L' |5 Y& B# h" v
  server_name  example.com;- J: }' n! i1 }: [$ T1 U* j
8 k6 d9 C% U! q" y7 Y
2 k+ W3 t5 K1 r, S
  location / {
/ d# y7 H3 S$ f" d7 m9 B    ModSecurityEnabled on;
* j1 l" ]8 x9 m% H7 H6 G( p3 d    ModSecurityConfig modsec_includes.conf;
$ _. N. }2 Q$ E* z0 {    root   html;2 g* c$ M/ Y! z0 E& U
    index  index.html index.htm;
1 P7 f* h! _  o5 V3 _& f- G  }3 Z! ]6 G9 L7 M; j+ `* R7 K! I! x
}9 Z1 O2 h4 L: g8 D9 n% i  k0 n
使用动态模块加载的配置方法# x0 K' O4 c: M  w; B# c% h/ C' c3 o
在需要启用Modsecurity的主机的location下面加入下面两行即可:
8 q1 j; ^6 i' U0 j; a2 ?
# h' I" O) z) ]% y
: \5 @3 g! o+ h) Hmodsecurity on;
0 _2 i" m; i) P4 {: omodsecurity_rules_file modsec_includes.conf;; j. E$ o( [8 _6 k
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。$ I2 [: h; A7 I/ x- t3 {

" `% L& @" ]- s" W! e. D4 ^4 b1 H: W6 E- W! R3 |; y& P8 Y1 v& l
$ vim /usr/local/nginx/conf/nginx.conf
# c7 x2 q# p0 J, o8 k0 G
, @+ S$ x5 K, k
+ R" }: b% u0 @& K' x3 Y/ b$ Sserver {7 E( j; D- \( G. H) W
  listen  80;
( G- D9 O1 F$ c2 B2 N3 i  server_name localhost mike.hi-linux.com;
% c" [  A* r$ S# S  b& D  access_log /var/log/nginx/yourdomain.log;
. V- F# K. U( Y7 K! ~% a1 Q
+ r6 U0 V8 n$ m6 h. W% i$ D
( y7 D, M7 k4 m/ H& e2 a! ~, D/ b  location / {
. F6 m+ E; ]" P0 R3 [, Q* S; x9 a, |4 l; ?/ P( P" E% C3 |

5 ^' y% W/ O+ r  modsecurity on;; J  G! i! c9 g1 {) S# q* H
  modsecurity_rules_file modsec_includes.conf;9 I+ c$ h  ]5 F# ?
  root   html;
  B+ O; h1 M% x! O  index  index.html index.htm;" j  g+ N2 N0 K  o' z7 c
}
6 j4 |/ W, }" H* a7 u1 u}
3 B3 d! t9 T8 A5 D验证Nginx配置文件; k0 X9 b7 `/ V" ~3 K1 M: E2 T
$ /usr/local/nginx/sbin/nginx -t
* m1 }% `+ z$ N0 a9 @nginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok& i3 w( }4 a( K& F' R" ~; P
nginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful; d# A2 y$ F* d
启动Nginx( V. z/ Z$ k9 f2 _# ^
$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf" s, J, E5 c0 \1 q  J

! l; r8 C: J$ b; O" n

测试Modsecurity

ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。

在浏览器中访问默认首页,会看到Nginx默认的欢迎页:

[/url]

这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页:

[url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png]

接下来,我们在前面正常参数的基础上再加上  ,整个请求变成:

[/url]

就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。

[url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png]

查看Modsecurity日志

[url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url]

所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。

$ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.log

Modsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。

2 N; v2 E( F8 d' c

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-8 17:11 , Processed in 0.085803 second(s), 22 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表