ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。) J7 W1 R/ Z4 t
( Z- |8 x& l1 I4 R8 \: _- o; v
2 j8 @+ d( v- x+ w
在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。 w; J3 ~+ |2 I( F: c0 K4 _
2 C8 x4 J9 W- Q& r; X1 v |8 h# [7 n
# B% g0 K* b( r什么是ModSecurity) d: d/ c+ z* H; m5 |
ModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。- E( |; D& s5 b
3 V2 a: j. A- L' v
) r( A5 m% k( V1 RModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。
- ?' T8 v& v4 v1 N+ p5 o, g! t) s
% D8 u' b) b' @ S8 m
ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。; \ _6 B4 [: V& X2 M U0 z
5 ^- p4 u3 z/ G% e7 w8 T4 M$ }: K# g( b
官网: https://www.modsecurity.org/- a& }# B5 O+ q
5 _3 q+ d4 E; `* ?
1 Z+ U# M# l5 n; e7 \" c什么是OWASP CRS
: o: M2 ~$ O" \, T9 R- t- }OWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。- a- D7 U2 Z* S8 q3 W* |
+ D7 q/ p" i/ |( T
0 H5 v) H: r# T8 ]+ y2 ~ModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。
8 d, q' D% m# ? u- T6 E' R
+ s# [: G3 y& s- a M& K r
- E+ O+ q i& q1 DHTTP Protection(HTTP防御)
# T0 s$ n% Y8 T+ hHTTP协议和本地定义使用的detectsviolations策略。) a$ t' b- G9 D6 J
0 B. y$ X% T7 {( z! U; B& |+ y/ l* [: f: j9 v
Real-time Blacklist Lookups(实时黑名单查询)
( h. V& j) U# j( J9 N$ S利用第三方IP名单。# T- e; [7 L% ^- a1 n1 G: W: f3 P9 t
5 m0 t/ q( @% _
: v7 k' {$ D( b7 wHTTP Denial of Service Protections(HTTP的拒绝服务保护)* [ O" H r; _$ {$ c( p* F2 g
防御HTTP的洪水攻击和HTTP Dos攻击。
4 E$ a, W/ g8 Y3 }" u+ ]! k# f* l+ H$ b- ?$ D
, b5 i: d! R: H. W( y% ACommon Web Attacks Protection(常见的Web攻击防护); G2 b7 f/ D( Q0 U- F
检测常见的Web应用程序的安全攻击。
- }% d& ]) c6 m E- k- O4 W$ f9 D7 y+ Q$ M' d% s) H, {& `& q
( F1 s3 x" W9 q1 \
Automation Detection(自动化检测)
' h8 T; I5 N; X4 m8 \6 |( k' d- m检测机器人,爬虫,扫描仪和其他表面恶意活动。/ H+ E* ]* T `' m0 ]5 w
4 f, R; E' n4 c# Q( y+ i* g) t7 J0 W9 B$ |
Integration with AV Scanning for File Uploads(文件上传防病毒扫描)
2 n, a% ?% N* |1 `$ U" A" t检测通过Web应用程序上传的恶意文件。
* P8 T' z8 g2 j3 g4 Z
: e9 d3 n8 z8 s2 a7 o5 o& `1 t
/ V4 L3 N% s3 t0 `7 C* w3 pTracking Sensitive Data(跟踪敏感数据), R! Q( l; z0 u4 b
信用卡通道的使用,并阻止泄漏。
8 r7 N+ v3 g. Z# m
" w, w; j- k+ ?/ Z3 c4 V
# P' I0 |, k- t% N/ {Trojan Protection(木马防护)! Z* W# d4 L$ F. _) n5 p; t$ L
检测访问木马。
t2 @2 y [; M% U! Y) g7 W1 W4 Y s: q, _- [/ N
. ~: _8 G- {( r3 W4 OIdentification of Application Defects(应用程序缺陷的鉴定)8 G% I3 u! Y' [ m- X* N3 y1 ^* K
检测应用程序的错误配置警报。" E& ~4 u5 [* {/ g$ S( T
/ I4 a/ S* {' Y
) J: d2 _: o7 o) s1 U( j: PError Detection and Hiding(错误检测和隐藏)+ |, l* p, T9 @9 p
检测伪装服务器发送错误消息。" g$ K6 }! `( ~1 \& ~
8 T% t6 w9 h$ z* r. i: V
6 B6 H. F) c$ E0 E2 |! U
安装ModSecurity
6 S2 M& O9 S" M7 H软件基础环境准备( j3 S( b! H% R2 s' D. X4 Y
下载对应软件包
& R' k- ^8 X; C2 @$ cd /root0 K2 Y0 i6 Y9 {; }
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
^9 n) n+ Z3 K' ^3 Z$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz
& d% i) X- h) Y安装Nginx和ModSecurity依赖包7 H6 x! k# g0 H4 z
Centos/RHEL
8 y1 |, Q/ z0 z2 R
" k7 F) \+ G% w# V/ u+ M$ u. g5 l3 F/ e' _1 O7 ^
$ yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel4 M3 h ]3 h% I7 {# d
Ubuntu/Debian
9 B; J1 A: P& R
2 U c5 }2 P, `+ ]! |8 W6 @! d) ^* K+ E6 F
$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev
3 z# m* @' Z( |9 Z4 I编译安装ModSecurity* C9 h$ J. ?6 O. b/ D( _
Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。: Q0 j- _* B& `
; a5 e" S" u8 c
% C5 @) X. l. `* G) N: B. ~7 |
方法一:编译为Nginx静态模块, l6 w' K( C+ |' o$ Y# q! H
6 Y& S6 p) m8 v4 J, m2 n3 p4 j% {2 K q* S2 M9 o, y
编译为独立模块(modsecurity-2.9.1)9 d* u3 C9 S3 Q" O5 C: Y' U
$ tar xzvf modsecurity-2.9.1.tar.gz
P! a+ T' i: {: T3 F1 l% c i$ cd modsecurity-2.9.1/$ d @, D; k- {- y/ U5 W
$ ./autogen.sh6 G' D5 A" f" y9 F2 _, t( S
$ ./configure --enable-standalone-module --disable-mlogc
, u, y9 k* d, V3 a$ make K) j* S& S K7 k0 D/ F
编译安装Nginx并添加ModSecurity模块
" O5 i; h" p+ U U& \$ tar xzvf nginx-1.9.2.tar.gz
W! h q( p- E* H$ cd nginx-1.9.2
) A4 D. P4 O/ o& e$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/
. d6 |6 M& h: ^3 j* ^' d) x0 r$ make && make install
2 C7 q8 n# }: L& ]3 D/ A% j方法二:编译通过ModSecurity-Nginx Connector加载的动态模块) h$ b% r$ B; \. J& }( c
0 R& b* p. H( c/ l. v
* Z: C" O% o6 l; [; S0 W6 v编译LibModSecurity(modsecurity-3.0)
p1 w, P8 T' T1 ?4 X9 |$ cd /root3 W [6 ~7 a. S6 N q
$ git clone https://github.com/SpiderLabs/ModSecurity
3 p7 B0 Y3 |' v; f$ cd ModSecurity
; V( L$ m- V' o% B) i/ C+ u$ git checkout -b v3/master origin/v3/master/ k% B& X* w. X1 M% Y% b5 q, [ m: z
$ sh build.sh1 A' N5 n" @/ z: A5 N
$ git submodule init
) J0 X4 k8 h3 b$ |, I5 ~$ git submodule update6 H* |3 |6 ]; y: D9 I4 y
$ ./configure& Q# P' a( ^2 S! e" Z
$ make/ F i2 \$ o. @4 H! o5 Y- f
$ make install
1 A l/ E; A. uLibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。6 m8 J: N7 D: V$ g
( {8 m5 x6 M( B$ Z6 C
8 M4 [2 z2 @% A7 q$ ls /usr/local/modsecurity/lib( f, i/ Q6 v. U* c9 E c
libmodsecurity.a libmodsecurity.la libmodsecurity.so libmodsecurity.so.3 libmodsecurity.so.3.0.0' p5 X2 j- \5 }
编译安装Nginx并添加ModSecurity-Nginx Connector模块9 k" v. t% c- }
使用ModSecurity-Nginx模块来连接LibModSecurity% f; [8 p+ J9 i8 [, c" Q! g% U
{9 `+ j8 e/ `# m% z$ H( V% L! `: k1 W9 Q1 A+ i$ y
$ cd /root# K+ Y# l" x# T3 S; Z' \7 C
$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx
8 ]9 ], }& ?2 L9 T1 p, S$ tar xzvf nginx-1.9.2.tar.gz8 Z1 W) _# e$ n" q( E9 V% z
$ cd nginx-1.9.2
! g" @! N! a+ o& i7 i2 ~3 ?$ ./configure --add-module=/root/modsecurity-nginx
1 V3 m7 D6 X, p3 \! {$ make6 z7 ~+ s m& h3 ~7 T' E
$ make && make install' ~( w6 Z8 \% {" v- j
添加OWASP规则/ `( Y! M' S2 I! ?, `/ t* i
ModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。3 t5 ` ?9 g |& c$ F7 v0 ~
$ J" g+ n# m u9 s$ l# I
, m* I- X0 f# U! t8 y% ]下载OWASP规则并生成配置文件$ M) L! h6 E: n* l) H0 l& o
$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git+ L( w: \ W$ V' D5 K% l! |
$ cp -rf owasp-modsecurity-crs /usr/local/nginx/conf/. k/ S* x7 A# U# f9 o
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
1 B& l0 y! O" f* ~; V) {! B$ cp crs-setup.conf.example crs-setup.conf9 l2 [9 G% C& J% ]
配置OWASP规则
m: f' {! |1 r2 ^2 E0 K0 G! }- p1 p编辑crs-setup.conf文件1 _/ m- Z( h/ M$ A9 c$ ]. ?
8 s$ Y* N) X; L" y- D
1 n" d3 ^' x5 ~, x/ R/ Y( P- m
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf
9 J) I) o* D5 m$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf
^' |2 m2 B1 y9 q) e$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf
$ \ \+ b- B4 m5 i$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf
9 _$ k9 D7 c2 F7 T& P' r5 j默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。
8 p+ c# ~) U f6 }8 S" q) l4 |# n8 V5 }, I+ Z, |; H% |( t
6 G, E+ n+ K# g0 h& @启用ModSecurity模块和CRS规则
3 \0 G: `8 O7 @/ c复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。5 U$ K/ N; l( g0 I8 @
/ f: e4 n+ v) J, R# _ \ t/ T
- K# W% q& M. V) t# jmodsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。
! q9 b6 M0 B% \% }
# m6 M4 m- r w7 b& X# `* Q+ L5 l+ A! z) r8 |3 U
$ cd /root/modsecurity-2.9.1/
8 g" K* x& W8 `0 s. J$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf . n/ r& d' t4 p0 ~$ V
$ cp unicode.mapping /usr/local/nginx/conf/
- B8 g# ]+ B; X$ D/ u' s8 @, X/ C将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。
1 D8 u8 n+ Z; F/ W9 \9 { C
5 C3 [7 d" a* r$ m5 M
* K# h. _* \8 Z. y1 s$ vim /usr/local/nginx/conf/modsecurity.conf
; {2 a( R0 g ?4 dSecRuleEngine On1 t: u! V6 ?2 D$ |; |7 c7 p
ModSecurity中几个常用配置说明:
7 w3 R5 X( q* r$ g/ L* |2 H1 b& p, p' C& Q6 F, q# d% d- E* M# v
( J K3 {, w* B3 d! Z
1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。! X9 U6 c( }( b" b
. G+ m, ]& S+ K% S# a3 K
5 c3 F: L0 b$ R9 m0 {3 u+ Q2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。
$ M" h9 U/ W( ]8 R8 i. e
~' i* V1 v# d% S# w5 k+ |- ?
5 u b% W0 L; U/ ~( |* R8 p D+ y3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。- H( y. Q5 @$ J) l
8 S- C! x; w9 a+ @1 r8 J' Z5 R5 C, F: b
4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。% U7 d7 s0 Z2 a. P$ c3 P5 H* P
# Z8 p* }- h b q: j1 u# a, T
5 p/ C' {: J$ }8 P2 U4 O* G) O在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。! ?' g) i, \1 L' M
: p5 y k+ m1 V" L0 k4 c# R
" q! [9 W y ?4 Q- B4 {7 o% Q/ Q3.x版本CRS
$ K) J. f6 s5 g# w+ q& b$ cd /usr/local/nginx/conf/owasp-modsecurity-crs6 K' P* d6 C! ?$ |+ x
# 生成例外排除请求的配置文件
( H' a2 S3 S6 }$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
8 l) a: x' r* k/ N$ N" j* ^* ?9 I$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
- B! m0 j( l6 z" W: g$ cp rules/*.data /usr/local/nginx/conf2 R7 ~, p \. P
为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。& V: U$ g" E) n% l
6 J- l( k/ N$ I$ q$ L4 Q9 }
; y5 A, D P; {# v" Z$ vim /usr/local/nginx/conf/modsec_includes.conf
: D; _/ h+ p+ _( |0 B7 C/ _" e# T+ M
[Bash shell] 纯文本查看 复制代码 include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf ( G& N( e# \3 s4 I) A; |) `! T2 @0 x
; A& @0 G) X9 k
注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。
% b2 J) X: N3 X( A+ |( G
" P' f9 p/ l N( Q% I, q3 p$ N( i2 j! s
配置Nginx支持Modsecurity
) P9 B# U2 v" B% d$ c! @- n启用Modsecurity1 B# o1 P0 d* y& Q7 o9 ^
使用静态模块加载的配置方法2 h5 D7 p5 s$ f/ t
在需要启用Modsecurity的主机的location下面加入下面两行即可:5 H; m% V6 y. _6 d
6 N9 |! @+ K- ` ]( R
0 N4 u5 ?' ~3 ?# U4 T( u
ModSecurityEnabled on;4 h, U$ S) d! h9 Z, l
ModSecurityConfig modsec_includes.conf;* h9 X9 P$ |# p- b2 s; Q1 T
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。% h# J9 m( ?7 i$ m
- c( _( h& f( ^1 R$ X
8 j, [' r# O$ n( j/ f$ d$ U/ A3 O4 p$ vim /usr/local/nginx/conf/nginx.conf' L+ f1 u, Z0 {- q, W& D N
7 B, ~3 C$ S, W6 q
7 e. k% A# K. `3 r: Q' c& `: eserver {
2 W2 g+ p2 W/ G, M y listen 80;
/ o! ?2 P: M& z( z! V server_name example.com;% I: T! T4 X( y7 O7 H
0 o0 G$ D2 [8 V, s
1 e) @& t/ r$ [$ D$ C location / {
1 r" ^4 o s3 j8 Z2 D ModSecurityEnabled on;
* r9 m) Z( Z/ X+ M3 Z2 `4 g) _8 y ModSecurityConfig modsec_includes.conf;
: w ?! G; k$ r) K% v9 }+ c+ d: ] root html;7 _; L* W* Q. k2 t1 [1 B/ j
index index.html index.htm;' k$ z4 b( A! e) ^# R7 E
}
$ a/ j" ?) j( z9 L6 ^}+ N8 F, C+ p" I5 \/ X0 }
使用动态模块加载的配置方法
5 X( S( W4 w! Z" g: X, r在需要启用Modsecurity的主机的location下面加入下面两行即可:0 u, M7 o0 w0 k& `4 `: {
2 F7 E. W2 ~6 |
4 q+ V1 s' E" n' Omodsecurity on;
: z. ^+ Q3 _, x' [modsecurity_rules_file modsec_includes.conf;+ F2 j9 J. i k. u
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
) I$ d: h+ P- e5 E5 W# p/ z
H7 e* f( S$ k6 w5 M" O
4 ~0 ~" L: I, @. R$ vim /usr/local/nginx/conf/nginx.conf
+ X+ L6 k& K4 }5 q4 m
. B1 \ K0 \9 O' \. F$ B9 i; E4 o0 K* J) S
server {4 ~- I+ h$ s- K1 z+ {- q
listen 80;- j- U# y5 Q1 Y, B; l# }
server_name localhost mike.hi-linux.com;+ C! _6 n J* M
access_log /var/log/nginx/yourdomain.log;
$ P+ ~; T' ~" U! x! N @( S3 G6 @6 f+ H4 u) z5 ?% O
- Y& j# }! R7 j) Y( T, a. L
location / {
" y9 y6 B7 I8 o# W9 k( P/ @9 e7 G& Y% }) R; Q; T8 Q; t9 g# ~' O
+ P$ J2 i* A. B3 f' F. {1 U
modsecurity on;2 @- O# ]- b2 C
modsecurity_rules_file modsec_includes.conf;' `- H$ F2 w9 z4 b& C
root html;
# n# [4 z# \* p# j. s |& N1 A: n index index.html index.htm;' j4 ~! }0 `1 k6 {- Z( ?+ B
}
" C2 c. n, [2 ]}
* ~# c1 K, t+ ]9 z+ ?* B! c) a验证Nginx配置文件2 q% W5 X9 ?0 z
$ /usr/local/nginx/sbin/nginx -t! J3 _- b: f' I/ D) L8 d3 f
nginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok
. L% M/ q* j& }. d! |4 n- \nginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful
& A5 z: @' n- u; G5 e t1 ]启动Nginx
( M5 F7 n/ `! B" g) A$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
+ c% K ]8 x h/ F: S) b" U ]
2 h" g' g7 L+ h% I测试Modsecurity ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。 在浏览器中访问默认首页,会看到Nginx默认的欢迎页: [/url] 这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页: [url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png] 接下来,我们在前面正常参数的基础上再加上 ,整个请求变成: [/url] 就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。 [url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png] 查看Modsecurity日志 [url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url] 所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。 $ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.logModsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。 * S5 m1 ?& x3 N$ j$ Y
|