找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12468|回复: 0

利用ModSecurity在Nginx上构建WAF

[复制链接]
发表于 2017-10-19 17:34:51 | 显示全部楼层 |阅读模式
ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。2 G9 m" l% X" ?4 I

( U+ [& d$ k8 |" L2 d, O9 ^8 j9 l3 J5 O
- U2 E5 a( y: h5 z$ K在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。
( t" t5 Q6 E* S! N$ K. D4 _4 ^. ^7 C1 ?- E# b$ ^. U$ y% L9 y6 o8 ^9 ~
' d7 g7 e2 M1 U! C  c
什么是ModSecurity5 W! h# O- r2 u
ModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。
: m. ^6 N3 Z; }2 ~7 u' S' `, K8 v2 g$ y8 t% P  N
8 \2 L! x  m* I3 L
ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。
- N4 r# M( h* `! R" D; l0 {; }4 f6 ~5 {3 [) H# b

+ Y/ h) o3 W0 n; y) W/ \( d" c1 c6 y( }ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。3 |4 \8 y& G. N& N' e& T

9 d4 ^/ i$ O+ H1 a  R, c" i* F" j. u8 o, P& P
官网: https://www.modsecurity.org/
0 |" N% q% O4 R/ f/ |1 }$ z* B+ [7 p4 Y
6 r& A# V6 @  S& @) f
什么是OWASP CRS
! T* O3 C" \; _- G( p6 bOWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。
+ r, X; a. E4 M
' H, |: B' q8 J/ c2 y: h4 T7 K- k+ V4 G0 O
ModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。
6 U; O) ]' u- M+ U$ X
9 G- a  I% L' {# _
9 x1 e7 Y" i  P* ^0 k' qHTTP Protection(HTTP防御)3 I7 _5 W+ B6 n( R+ L
HTTP协议和本地定义使用的detectsviolations策略。
0 E. q9 K9 b3 a6 m* d8 z) Z) y7 n6 J6 w
: m4 Q8 m8 t1 @% I# q
Real-time Blacklist Lookups(实时黑名单查询)8 p: A+ B. P9 n  T+ E( a' ]
利用第三方IP名单。
% V% ^( C: a. l- h  ~3 Y
! G5 L- ^6 N( c# A& W) T: p
8 Y$ E5 I" O3 g; `# @HTTP Denial of Service Protections(HTTP的拒绝服务保护)
9 k9 U3 ^* m! T防御HTTP的洪水攻击和HTTP Dos攻击。, A% \0 U7 [$ J$ h
  O# H# ^' s) H

' c8 D  F  d$ p4 R( O. a5 iCommon Web Attacks Protection(常见的Web攻击防护)
4 t2 T# G; L1 z检测常见的Web应用程序的安全攻击。( z% q8 I' b6 Y$ Y9 [! e
5 z8 C( C3 C" v

3 s0 w. l7 |  S  b  tAutomation Detection(自动化检测). |; }+ j( B& m0 T# x
检测机器人,爬虫,扫描仪和其他表面恶意活动。
* n3 X) j9 o+ ^  C5 U! V" w0 |# Z1 G. A7 L& p" F
! a- h1 m" c+ w$ F2 p7 y, L( Z( b
Integration with AV Scanning for File Uploads(文件上传防病毒扫描)
. X" V, z% B$ h8 a" |  [检测通过Web应用程序上传的恶意文件。
7 K* Q# z; w& n+ q0 X2 ?' F5 L
9 q( s. r/ C/ T- ?9 b
8 {& e3 c# ?0 u- W/ J; N; s7 }Tracking Sensitive Data(跟踪敏感数据)
1 t( }8 J0 p/ p4 A, ~/ g信用卡通道的使用,并阻止泄漏。+ q! r% N7 k- m( b9 V% E' H

' P% h  x7 ?& Y) t1 r
9 `, r0 {# r! y0 H% r2 G; ITrojan Protection(木马防护)
. p. |- Q# C: i9 q检测访问木马。( ^0 ^% q$ J+ X7 l! ~
6 E- ]5 v9 f) j: I1 b, S
$ l* `7 L1 d2 }  P( l
Identification of Application Defects(应用程序缺陷的鉴定)" G+ u' ~% t/ ]$ w
检测应用程序的错误配置警报。
0 C& H$ G2 B  H8 x6 l8 x7 p. p) R+ C7 t+ N- L4 \8 W! R

. Y4 ]4 r% i- G6 n4 x% uError Detection and Hiding(错误检测和隐藏)
8 }9 m- {- @5 q* E0 z检测伪装服务器发送错误消息。
3 l( Y- [: J$ b4 A4 ^1 I: B$ Z/ q9 T5 g5 K  g0 U( A

6 F- c, V/ P+ {7 j安装ModSecurity" L# k; W" P+ p* L
软件基础环境准备2 C$ T5 {. Y; @) S, u% k% Y4 n
下载对应软件包
1 K4 S$ `& u! C4 J2 H# D$ cd /root  J4 z' z% L, y; F: {
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
6 g/ T# L- Q8 `5 F& ~! P( y6 B$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz/ _8 u+ J+ l' T* I: C1 n7 Z* X
安装Nginx和ModSecurity依赖包
! W! f! C  @- b) u: X8 V4 F% u' W# MCentos/RHEL% B8 M/ `/ x2 p  v, E! l

8 ^, X3 g4 u* d3 L8 s& C
- e2 L/ Y, N: m8 r$ yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel
9 Q# O+ X% `% {! p. QUbuntu/Debian
2 q+ `6 l( q: p$ A% s2 j* k, V9 L9 z1 Y- j2 D& X0 L. F1 E

. _% `8 c3 m0 ~7 G$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git  libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev" z4 ?2 ^' d2 T/ e- t% s
编译安装ModSecurity7 t0 j4 p# W9 G0 Y
Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。
; d6 q5 j! Z$ d8 P
5 g1 z6 [6 m( I' V3 p) l2 s5 V, b' V( p+ ?  p6 V. q  Z
方法一:编译为Nginx静态模块
# _9 k; P. }) @% ^& K2 D! G3 G
" G. z, E) H$ i/ B2 u  M3 j( |4 M% e* a& m& C  l" L9 @& d3 S
编译为独立模块(modsecurity-2.9.1)
9 E8 z. t, K' S. J6 F$ tar xzvf modsecurity-2.9.1.tar.gz
. n% x! g' C" X) [* c$ cd modsecurity-2.9.1/
9 b1 ^5 A, ~, r+ ?$ ./autogen.sh
' W# U2 L8 e) }4 ~1 L* t$ ./configure --enable-standalone-module --disable-mlogc
: e; M+ Y" n. D/ P5 \$ make
3 ?1 A+ \0 k6 z编译安装Nginx并添加ModSecurity模块
2 t" F" o" `" z* \  Z- N$ tar xzvf nginx-1.9.2.tar.gz
4 @8 ?, b( o. E! X- X5 R' E6 R3 D$ cd nginx-1.9.2
" ^5 p3 }4 C8 Q3 H# ]$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/
- E5 f6 E: z" G$ make && make install
3 d6 K# E* c/ V, }: w方法二:编译通过ModSecurity-Nginx Connector加载的动态模块4 i3 n' q9 {! z6 G2 B

, j) I; J7 z* W* P; z% |
  G7 d! w3 L) s编译LibModSecurity(modsecurity-3.0)
* e7 @4 D6 P! ^9 \7 O! }$ cd /root
: z, ~- d8 [1 X6 K$ M8 Q$ git clone https://github.com/SpiderLabs/ModSecurity
0 _" y. e4 h. b' B1 o( r+ i# A$ o$ cd ModSecurity
1 z$ i/ s, {; \1 I5 ]$ git checkout -b v3/master origin/v3/master2 m0 ~3 C+ n4 n7 A
$ sh build.sh
- O! K! t9 t: u/ B6 Y. [9 {$ D9 ]6 B$ git submodule init! p3 N4 c! m# N) B7 N
$ git submodule update
7 W1 `" W' t3 r4 L$ ./configure
. e. E( P) y& j7 Z$ make
; R: E) D; f# L5 n1 u$ make install2 ^- H9 |5 A; Z
LibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。
# d+ D0 |, r  f/ y/ F# r+ j8 {2 ]5 @( z$ l% r

. I% t. Z) A" w# X- `) ~. P: o$ ls /usr/local/modsecurity/lib
2 Q$ L, O4 H  {! A# b, r# Zlibmodsecurity.a  libmodsecurity.la  libmodsecurity.so  libmodsecurity.so.3  libmodsecurity.so.3.0.0
$ u8 ~7 E7 W6 [, m4 j编译安装Nginx并添加ModSecurity-Nginx Connector模块/ k7 V# _# F$ p, a* q4 `
使用ModSecurity-Nginx模块来连接LibModSecurity
0 S) u) T0 v1 r9 l9 r" E2 x7 [7 P

* e- i7 C% {' m  d* x9 X+ `$ cd /root
6 h5 `0 l/ b9 a) U2 S$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx# P; Z: }3 l( X: C4 _+ H, Y
$ tar xzvf nginx-1.9.2.tar.gz" ^$ ?7 w8 q* W5 H
$ cd nginx-1.9.2
9 O( P$ k& N4 n' e9 `% ?/ ~  j1 [! X$ ./configure --add-module=/root/modsecurity-nginx) U4 }! b. e+ Q# F3 [5 p& x* y, M
$ make) t* A9 {) w7 m" w
$ make && make install
& H+ b* \, E0 L9 d' U添加OWASP规则
1 E8 W2 @: P. @2 y) O7 tModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。4 w2 V2 U) ^3 F' n  Q  v, S1 @

# W, R3 |! L8 z$ X
9 A0 r$ U0 d$ x% _下载OWASP规则并生成配置文件
; P9 Q6 n0 W+ b% ?  E- K9 s$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git
# e$ h' Z/ m  o. @/ d) M9 O$ cp -rf owasp-modsecurity-crs  /usr/local/nginx/conf/3 D" l2 [+ p! f
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
4 b& N  W) A6 o, I$ cp crs-setup.conf.example  crs-setup.conf
! t5 P; C  }3 U5 K- @6 p9 I" [配置OWASP规则3 F7 S3 w7 w7 L% y* N
编辑crs-setup.conf文件% n7 r) I0 M8 Z2 t$ Q# g! [. \

- J  k8 W$ F9 Y7 k6 [+ }1 W) k# r5 \$ D1 X. |- q4 S
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf' D) b- I' j9 s# z
$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf; f) e. E9 ?! K' }
$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf
* _% @9 |2 c6 v) X" W8 L% I9 l$ w$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf2 e# t" X1 g4 p7 R8 Y
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。+ s1 r3 ?7 @/ B( j# H
& i3 Z! k6 M6 U% r

) H; w5 }& c0 [! |# K3 h启用ModSecurity模块和CRS规则- x- L: w& ?( O
复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
9 z2 f; G7 h. ~7 @! Y( d* E8 k: V0 v( z
4 T( e5 P4 ?6 n
modsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。, t. u- f6 G6 y7 l3 S

8 ]$ K3 V2 n* B; v2 _# u# a- g
' a& b3 `5 A# T7 ~( X8 q$ cd /root/modsecurity-2.9.1/% d9 v" b8 c4 A) z# K
$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf  
  K* X* j( ^1 V9 K+ Y* [" ~- F$ cp unicode.mapping  /usr/local/nginx/conf/7 v' {% N& A, r' i4 D* j
将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。; w4 D( C6 w# G0 x6 I

; t6 M0 L; v9 j9 E$ Z
& W* r3 q0 _7 y6 ~- ]& T$ vim /usr/local/nginx/conf/modsecurity.conf
/ V: x* M; P! {$ U# X$ h$ ESecRuleEngine On8 ^8 G7 R2 A) o! |  @
ModSecurity中几个常用配置说明:
/ O. j5 _7 J. o8 @2 B' y' `* C" I8 w# E2 t& z

+ R/ |- S; a/ V) g* [! |5 L1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。
% e) G, K& I# ?& L/ S5 c' ?; d, f* t  T- N
* V# o" |& q! o/ w0 }) I
2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。" R2 v# _) n$ |  H4 A& k

1 v2 x  L# c; D4 c/ G- ]' h
% N# J! u; v& d3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。
& B" n# A) u( Y; x( T' J* C# `6 }# o4 G: l. f
4 X" V7 r, I5 u) M& R5 R% t) C
4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。
( S4 ~: g0 Z; Y" s
& t" f2 ^/ ~# n. u* d0 L1 ^$ C) x8 i
% R; Q  m3 @0 L" c" L& _, o' [在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。
+ E1 e6 J. e' ~, t! z  O& b4 H+ R4 k, Q% |) w0 H- j
0 T8 k; X, J, y4 e! V0 k
3.x版本CRS
  r  {& P7 B7 \. z/ {5 l& w$ q$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
2 I1 y0 ~6 R6 m2 `* Y8 j- F# 生成例外排除请求的配置文件
$ x4 w$ @$ a0 G! b# v& k$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
' H: ?8 x, F$ Z' Z/ `6 l$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf+ x% n6 s4 W" X5 q1 _
$ cp rules/*.data /usr/local/nginx/conf# b4 e9 ], T) W1 j
为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。
; P( U8 `( a6 ^/ {, a3 p+ K+ }& d( w7 O( W" [

8 f# Z8 g; L9 i# g# X. v- r( k$ vim /usr/local/nginx/conf/modsec_includes.conf
/ F9 r' I2 f: t7 [3 m6 S- `* B' F' I0 I9 B
[Bash shell] 纯文本查看 复制代码
include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
8 @6 F# E+ C; J! S
, r; s. j; i+ P- X
注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。1 @4 f2 z: b+ y, I5 i

7 Z& b4 j0 C$ W/ g. m
: Z) h# O2 S% W6 }配置Nginx支持Modsecurity0 C& \9 i  `" O% a& g; O/ k
启用Modsecurity1 c8 K/ O5 e% M( Q) W! t# |# g
使用静态模块加载的配置方法
' h5 l$ m& l' H& F4 P& L8 n在需要启用Modsecurity的主机的location下面加入下面两行即可:  ~+ U* L- E/ M, x( z# x$ m

' V; s# r/ i" M" s* b! e: r2 ?/ l) ~  z2 e* n
ModSecurityEnabled on;
1 ~7 c# ]. B& n: l) }9 rModSecurityConfig modsec_includes.conf;
2 X. w! U- ^# A! J7 c修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。! g1 G+ t! Z: d3 k

$ ?1 Z+ \- c/ F( a& a
  v% F2 h" J. r9 X9 r$ vim /usr/local/nginx/conf/nginx.conf
' l7 q" {- ?2 w) x6 d$ I
' O8 ?9 s5 p9 G- g' j1 Q& `$ E: P/ Y: _; B( a
server {) v' ?+ Y* K: ]7 K! V! ]: n2 Y$ v
  listen       80;1 S- X7 K! ]( \+ X
  server_name  example.com;3 s# N3 ]( l+ [$ m
0 {4 C$ a! O9 A# V8 u7 z; e" Q
( T& `4 _) Y2 m9 k3 D
  location / {7 X8 ?5 u; T$ @) k
    ModSecurityEnabled on;: R- M8 G+ T. |6 r) z/ l5 q
    ModSecurityConfig modsec_includes.conf;) J% i2 d0 d2 j1 f! l
    root   html;
( q  V% u2 ~4 [( u    index  index.html index.htm;
$ x+ l8 j. |9 i# ]7 p0 o; d3 V; {  }
6 E; l6 n# k0 n) `}/ K0 N  ?" P! j" e1 D
使用动态模块加载的配置方法
4 K$ I* {, S' ~( q( l  C, d在需要启用Modsecurity的主机的location下面加入下面两行即可:
6 C; ~/ B& C+ O- h) ?
3 S% k. D. ], o% O" h/ f2 C! ^) Z3 W5 _7 j
modsecurity on;* [$ r# [8 N' D. o* m& w
modsecurity_rules_file modsec_includes.conf;
- b; W7 i2 k; Q6 F1 D修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
7 A( P+ ]( {; G6 Y
: h" M3 e7 B" {) M2 |- A2 h5 ^$ a( D! t/ q
$ vim /usr/local/nginx/conf/nginx.conf
$ d: `: x/ K" d8 I
. I( B6 t, m8 s" H" {6 p6 u  p$ S4 [; Q* n: f
server {
/ k. R/ \/ z) I1 V3 i  listen  80;
2 X" l) x+ s9 f8 G. \7 J8 o  server_name localhost mike.hi-linux.com;
7 U% H8 }, `+ i$ {6 Y2 K) `% u  access_log /var/log/nginx/yourdomain.log;
0 y4 ]! _8 |8 e
5 Y0 D  W/ w# H( d+ k7 w0 v& W
9 v$ r; C5 @/ C  location / {
+ ]& l* h+ v/ D8 a; ]* e9 P  d0 l, l. g9 R9 ]
" V3 [9 q; c* z- j7 a6 F
  modsecurity on;
) Z. D" Z% U5 a- B* ^2 X, u6 ~2 R  modsecurity_rules_file modsec_includes.conf;
( F3 l- c& s* v9 L/ o  root   html;
/ d( x3 u6 S( D- v' l( r  index  index.html index.htm;0 }) j4 U) y0 Y8 K) S  a7 F
}# @' `9 d# L7 H- z* j9 _' U
}& ?* B8 `7 i5 o7 Q8 K3 E- N7 p. v
验证Nginx配置文件% F. c  Z! j! u4 w% d/ \) g
$ /usr/local/nginx/sbin/nginx -t
# H( }! n8 H$ T# U0 e8 `: K. Knginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok
3 \* K0 z$ }9 y& E( e& R& J$ s# Znginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful
: @. h. d( T  k, O8 l启动Nginx
  N  P/ x+ ~$ E' ]( X$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
2 C9 Q" C" M# y+ I3 }$ P' y, g$ H. k6 d' @* j( y/ R

测试Modsecurity

ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。

在浏览器中访问默认首页,会看到Nginx默认的欢迎页:

[/url]

这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页:

[url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png]

接下来,我们在前面正常参数的基础上再加上  ,整个请求变成:

[/url]

就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。

[url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png]

查看Modsecurity日志

[url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url]

所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。

$ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.log

Modsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。

; i: P  _9 M6 I) h- W

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-30 06:25 , Processed in 0.087223 second(s), 22 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表