ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。
; e/ o8 D, T8 Z; q3 R% j
: s3 N% X- @# e. {, ?( T: c$ H7 {* j3 V5 v' z
在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。
% ?9 l7 M2 H' u% `$ g+ j# R: k7 y
) H0 |$ r0 O! b! [( Y& R# H' d! h: @) F
什么是ModSecurity4 ]1 J7 I6 A/ Y) v: P) E
ModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。
' q# F5 {, T3 |- G4 j, j) O$ ?8 W( J, M; p! O
j N6 C# z. ^- U( P" T
ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。+ ~2 u3 b( M0 \8 \
/ I! p7 b% P% ^; S
( q0 P4 V% p9 JModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。
( p, S( t1 E9 y& y9 A' y
* T n }" L5 p" o9 ?' K: B5 g, N
5 A! G, X* r0 ~" l) Q6 Y: r官网: https://www.modsecurity.org/9 Y: Z6 Y, Y! M# ^
9 \! f; n( O( ~- B1 @' d
9 C& M6 M" C+ ?% e* ^什么是OWASP CRS
" B. r& l" `+ _: W* b q0 W GOWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。
2 h5 z# f) j7 {. V, _
?, I& I& Q" ~0 w6 j
& D' w4 _2 a2 [ModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。3 ^+ {8 q8 n Q8 F( p) g, ?
4 x! u* n2 J( a3 D# p. c. D+ A; b( o4 \# {+ X
HTTP Protection(HTTP防御)
) y6 x" I3 l, l8 E: WHTTP协议和本地定义使用的detectsviolations策略。8 T# @- t% b7 ^$ {% ^, I* G3 a, h
6 a- \/ M, Z4 {; l3 Z
) q" H D3 {- a
Real-time Blacklist Lookups(实时黑名单查询)
( U( }5 [9 J M* X- q! W1 @利用第三方IP名单。
! _7 W- U/ h/ n/ P& w
# ?% V1 A D8 [" a- p+ J: K6 h
$ j! C6 }0 [/ B, [5 u- jHTTP Denial of Service Protections(HTTP的拒绝服务保护)0 C% s- b9 E) l1 w& Z# [4 k
防御HTTP的洪水攻击和HTTP Dos攻击。
: Q5 ]$ Q$ d% a
/ n& h8 W. w2 T3 Y
1 {/ x7 S1 a# kCommon Web Attacks Protection(常见的Web攻击防护)% v' y$ }* E/ \7 S9 ?) c0 W1 j
检测常见的Web应用程序的安全攻击。4 _3 l. b% b: |6 s' d% ]; t* j
- p& ~1 Z1 [1 ^
! ]: s0 F) C- q8 d" cAutomation Detection(自动化检测)# S* [4 k7 b0 z, }2 |# m3 b
检测机器人,爬虫,扫描仪和其他表面恶意活动。. i7 t, G2 ~" ?' D8 O% y
2 q; F' q' x3 e# Q) ?* J, K% N# s$ o; x/ q# [5 B
Integration with AV Scanning for File Uploads(文件上传防病毒扫描)
1 S( n5 O3 d; m6 {+ O" [1 A检测通过Web应用程序上传的恶意文件。6 E& Z) l6 U, @, L. ~9 u" D; G
@- N3 d# p5 U: M% k1 h6 {" w' q8 |6 }) [/ ]/ U
Tracking Sensitive Data(跟踪敏感数据)7 u& n7 I$ J+ J/ W* H8 Q; p0 a
信用卡通道的使用,并阻止泄漏。: G0 _0 @: W# N1 Y2 \0 E P, M
4 B' a% s3 Z, j* T; w7 d9 g/ d4 f" g/ @+ K) c( `$ y
Trojan Protection(木马防护), b# b& Z3 O, m. P- j: W8 f
检测访问木马。1 W7 T/ }( f* C$ F& M; x+ w
; v# j- s9 m- n; g; y! C g( f, e
) d' m: w' Y1 e% b
Identification of Application Defects(应用程序缺陷的鉴定)! h& c, V" L( k" H
检测应用程序的错误配置警报。
& Y3 T8 W% i6 C9 h0 H( O3 N9 Z5 A3 M6 l
" O ~, h! _8 L' ?5 {& w. B: @
Error Detection and Hiding(错误检测和隐藏)" m4 \8 s7 n1 D$ K; F2 {$ @
检测伪装服务器发送错误消息。! f, ~* t d% }0 o6 O/ s, o. i8 C
, l$ b& j% x0 ]4 D5 ?# a# z f+ s) i: C5 [3 u" _* z: ]/ x- x+ B
安装ModSecurity& Q% \; [% X3 K# D0 }
软件基础环境准备
, E( l: Z7 s3 X7 f9 o, b- }下载对应软件包
% h1 ?2 I' k7 e$ cd /root/ R w1 t' x- } K' p) N
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'" Y' N1 `0 B# g5 A, r
$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz
0 {$ g/ q: R% j* m) e安装Nginx和ModSecurity依赖包
2 L- a. s& ]1 s; C& X# zCentos/RHEL
: P* x1 @3 n0 B: D# o7 m8 c8 e: ^9 N
H# G7 F, Z2 G$ C! c6 o' X: C% a: G) q
$ yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel/ v) L) j- z5 \! A( w; ~% r$ x5 B
Ubuntu/Debian5 K" B: K: h. K5 [# f
% X8 o& \, C$ k" a {) B
+ {# w( s: L) A+ Y% m5 w- r
$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev
- T4 @2 U1 r6 T# I N8 _: h编译安装ModSecurity3 z8 u! r$ S7 r
Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。
* ], ~/ J1 F% Z* R/ L0 Z
0 Z; j: a* H- T+ W6 z2 t8 L, f& L# ]- Q9 U% G% D
方法一:编译为Nginx静态模块9 d, r+ L. b1 L/ \# ?! V8 \6 M! V
, O4 \2 S; O9 n `/ I
% e3 J+ u' v* h4 K1 L# r4 m1 I编译为独立模块(modsecurity-2.9.1)2 z( Z/ h: s; u" V) h0 e6 X' i
$ tar xzvf modsecurity-2.9.1.tar.gz
* B6 l( O9 i* L/ }+ ^5 X7 L$ cd modsecurity-2.9.1/' ]; I# A5 O! g5 L# {, V
$ ./autogen.sh
' o7 p& Y* ]' _3 }9 j' t( N+ g$ ./configure --enable-standalone-module --disable-mlogc
5 I( o* {* {6 F; h2 W$ make
' b6 z1 y2 W8 c" p, Q编译安装Nginx并添加ModSecurity模块0 Q+ x) R3 [' q/ q; U/ y0 D
$ tar xzvf nginx-1.9.2.tar.gz
7 ]3 P4 Y/ c/ x' \$ cd nginx-1.9.2
7 _% w9 Q. s. ]- Y7 J$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/
0 Z5 n, t# g9 c. a( ~$ make && make install
8 x2 ` Y& _ K9 u2 B5 [; j方法二:编译通过ModSecurity-Nginx Connector加载的动态模块
: i% a# v, x4 z& b! p% O
* E& b! B( }+ F5 H$ l; s0 Y% q! o1 q1 {5 G0 f# K7 K2 k! H
编译LibModSecurity(modsecurity-3.0)
4 |/ g9 H6 K- I& D; N& \ d$ cd /root
' K& b% Q6 }" B; W% `0 r( B" ^5 P$ git clone https://github.com/SpiderLabs/ModSecurity# @ h O; X0 n4 o" v
$ cd ModSecurity
7 L1 K6 @' x( w$ git checkout -b v3/master origin/v3/master$ p) Z0 U3 L) e0 B! Y# v2 P$ x
$ sh build.sh- o; ]& `+ ]# o5 U
$ git submodule init& p& I" e. g. z' e
$ git submodule update$ \* P) w. [6 G$ H8 j
$ ./configure
2 o8 G+ I3 v$ d$ make
3 ?* T6 }! Y5 W: m- z$ make install4 p5 D/ x0 c2 Z$ v6 w) c& a5 J
LibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。
. J5 O7 I5 H- G. W! t6 H
/ W0 W$ p, y8 l) ^6 ~! d& B0 _+ Z/ R, m3 e k
$ ls /usr/local/modsecurity/lib: X% R& o! H6 s! X( P
libmodsecurity.a libmodsecurity.la libmodsecurity.so libmodsecurity.so.3 libmodsecurity.so.3.0.0$ W! Q1 `) v3 g. p; \9 @6 E
编译安装Nginx并添加ModSecurity-Nginx Connector模块
* _0 s, R _7 O5 I7 C5 L. g7 F使用ModSecurity-Nginx模块来连接LibModSecurity
1 W$ A% ]% }$ G% g+ }# E- q/ G" D
, |) L+ O4 e: g
' }1 l7 j$ N8 o+ o# B; A$ cd /root
. c! q3 A7 n) [5 O' k$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx) P9 S. S T# w5 l
$ tar xzvf nginx-1.9.2.tar.gz* ?# h6 u1 a8 \+ _7 l+ `* C
$ cd nginx-1.9.24 F4 f& Y0 H) V H7 o
$ ./configure --add-module=/root/modsecurity-nginx
1 p3 i% |0 H( m& b$ Y4 s$ make
# r' J* J8 X3 o$ make && make install
- T- E: Q5 r: c0 _添加OWASP规则. @0 Y& q2 p1 n- M1 ~$ {7 r* r E
ModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。" V2 j! K* Z0 S4 @5 i
7 j0 f; ^2 J# ]' ^6 W% }
4 z3 Q; b8 {5 L0 @% R0 E下载OWASP规则并生成配置文件
+ U- R( N; G1 r0 _) [2 M7 h% s$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git* M! Y4 k2 z+ k# h
$ cp -rf owasp-modsecurity-crs /usr/local/nginx/conf/3 h3 }6 q! Y8 W, G3 _2 n# G
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
6 r+ T) P1 Q( r. @$ cp crs-setup.conf.example crs-setup.conf8 x3 u: y7 y5 ?, z( @/ ?
配置OWASP规则3 H+ l" k8 f) H6 w; A
编辑crs-setup.conf文件4 @) R; e! c9 ^
* {4 _3 ^& n6 \: [/ v5 V$ c% E/ ~! o, @) e4 s# H
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf* T/ _3 b6 z" `4 P
$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf4 q) a4 y& A* l/ t
$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf: D9 D& a& i$ X8 X f5 J+ J+ i: M' n
$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf
9 C# P- F. m8 ]2 d5 i默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。
& e" S7 [+ H I6 D4 j+ H, Q* d: _2 S6 \1 K- }
% s h+ C9 h6 E1 _0 q启用ModSecurity模块和CRS规则
0 O6 z' \* z" H0 @2 L& R6 B复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
: a& t3 y: j- |& o
6 d) J, E) `2 _' a2 S+ t. T+ S$ n, n
modsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。: ` w! w2 {" }# ^: e O
7 z6 P( V8 G1 B- H: W: g( d2 y8 a( z: \4 ]- E
$ cd /root/modsecurity-2.9.1/3 L& M, v% X5 O1 U9 S8 ?
$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf
( j; p" X1 v6 E" h/ d$ cp unicode.mapping /usr/local/nginx/conf/
, K# A. r7 R. `, h) N+ w; U4 u将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。
3 f! X1 d9 G/ x. D# s" i/ Z( k( H- a& D1 Y3 Q
: `) D3 B- K8 k% z7 _
$ vim /usr/local/nginx/conf/modsecurity.conf
C4 \- l* m% hSecRuleEngine On
. x$ s1 {) c3 d" u: v& AModSecurity中几个常用配置说明:+ W/ o4 w9 D1 x- Z, r. w
# d3 `8 v- t9 |, `. ]% {8 A1 w- L. |
1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。" L$ x- Y* S7 a6 }) }
/ m- }/ j+ w/ u' e7 S2 a
) U& D5 q: o/ ~ V2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。
9 k6 ^% s1 Z J2 p0 v. m p: G& P6 }9 E- ^) }; P$ E6 X+ \
1 K7 c: W# B; ?4 N) a
3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。* i- M2 @5 v/ B: P# O; N
+ a# z% W+ v2 E7 B7 V+ V
$ b+ P( W& y' I8 Q4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。- o9 f' V8 \0 R4 ]
+ \9 b$ N) C) W$ a) ~
; u$ W4 G& w1 E z* F在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。
, f, W$ _* F4 U6 b: I$ G0 A; @( A0 T# H2 j# r
/ K# m4 @" I- u& h3 n0 ~) a
3.x版本CRS/ k' @7 p- K5 @4 `% S
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs0 [" r+ b5 Z7 Y+ P5 d
# 生成例外排除请求的配置文件
5 U# j% Y& \; B$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf: z- {/ m3 c; m. F
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf. |# ^- P4 Q2 W; u9 U1 O
$ cp rules/*.data /usr/local/nginx/conf
8 N3 p& `) x, h( i# x为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。
; F# x) \+ J) D9 M) d! }8 B/ y1 [8 g/ v
) h( t! k5 q& r: u$ L- o m0 B
$ vim /usr/local/nginx/conf/modsec_includes.conf5 O, |8 h3 _6 q$ p
2 w" q1 O- z* G6 B9 m# Q[Bash shell] 纯文本查看 复制代码 include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf 0 P2 [: \( V2 x4 |7 X- ]; ]
4 T4 a: m4 k8 f, r1 u' N8 s
注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。
% ?8 k* c% L# ~( x& P7 m5 R' n9 r n6 b& [; v
: v! ]! ]" u% h8 M3 R+ W配置Nginx支持Modsecurity
7 ^! _5 q8 v+ d! |* |* N启用Modsecurity
. B: p E. E8 g使用静态模块加载的配置方法" d; k% r+ T# K" d* Q7 p
在需要启用Modsecurity的主机的location下面加入下面两行即可:
) i! z" m7 q* ?8 M% a6 Y" z! J, i8 A8 h/ g' _( d# b$ H# D' U
8 {( W1 g% Q. m) aModSecurityEnabled on;5 I R$ t, f$ ~" e3 M" h4 b
ModSecurityConfig modsec_includes.conf;
4 ?- V5 d+ H% w修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
" B+ z" j5 M9 N+ a6 U$ [: V; M( c" l- F: c
S' o, [# R/ I/ v- R6 [# _) U( U
$ vim /usr/local/nginx/conf/nginx.conf1 s: J; ~! o9 ?& e
- E) `/ a' x9 O) V, d
- u- N h9 q% ] O: t) y/ Q+ Gserver {* X& J& ~" G8 q. W0 f( n
listen 80;6 s4 i' K0 I' V+ o& p- z
server_name example.com;" y" O% t5 Z. T O2 p& Q* W
) U$ W4 g' t9 Q; y( ~
0 k4 t: H$ A0 A5 u5 j ~: E$ |2 R
location / {5 A' z4 E* j8 l
ModSecurityEnabled on;! O! X( D! P0 \
ModSecurityConfig modsec_includes.conf;
: r: P& c @; e* I% D8 I: N root html;5 C. q. o0 P9 }, M
index index.html index.htm;
; T! z3 Z+ f3 I& P }
" I) g% S5 S1 N+ ]& x) R2 \}: |+ ?3 h# a: S# T) j, l
使用动态模块加载的配置方法
; E9 t3 c! w$ E在需要启用Modsecurity的主机的location下面加入下面两行即可:
6 g7 D; z$ X1 |3 m8 p, i
1 E+ @7 Z7 f" l j( g ~* k2 D& P f. w. r+ r& F
modsecurity on;3 V9 i# y0 V/ H% g; J9 r- Q
modsecurity_rules_file modsec_includes.conf;
: U/ f j1 k" B* ~1 \* y( a) S修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。& o2 e w& X% H1 N$ ~: n
- x" |5 ]' A& G0 P. D9 U/ g+ r- F O t( q1 l B6 ]5 z
$ vim /usr/local/nginx/conf/nginx.conf! k) E' o* Z# i4 k% y4 A" g/ l
. c6 }1 m) Y7 s, L
5 L0 H7 l9 ~+ }* s$ A8 `* d; Qserver {
! l9 ^2 f) w' y' Z z& [ listen 80;! {! r4 w8 o2 N
server_name localhost mike.hi-linux.com;
" J( y) t3 Q3 H; {& H access_log /var/log/nginx/yourdomain.log;
8 H7 r% h# L& L/ |: t2 f, [5 L
2 O# D" L' C4 A4 w6 `" b4 z% V- ]2 g
location / {6 |, V! x" C' {
* O- u3 s) p4 y9 e" g- I' z3 J
9 z2 u# S6 A9 X) r' t$ [5 t modsecurity on;1 _. c+ r' g O% n4 l
modsecurity_rules_file modsec_includes.conf;2 r1 s4 j/ q8 Q. z3 f2 P* G
root html;
, \3 t0 ]) a1 t6 o1 b6 H. h6 d index index.html index.htm;2 `* ^3 ]5 L8 r; h9 f
}
, {2 z% ?7 {5 M, O}
3 P8 @. }- M8 z验证Nginx配置文件. n! T. m* N; U9 o4 G# j
$ /usr/local/nginx/sbin/nginx -t' k" u& j: J% g4 n( b& m
nginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok
% l9 ?" [5 l" p2 enginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful
) ?6 h3 D& t3 W启动Nginx
) T4 c8 p& ~7 c7 ?# T; U$ n$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf. L/ n) w* j/ ?( F' Q9 E5 Y
$ f2 T- `3 D( t测试Modsecurity ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。 在浏览器中访问默认首页,会看到Nginx默认的欢迎页: [/url] 这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页: [url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png] 接下来,我们在前面正常参数的基础上再加上 ,整个请求变成: [/url] 就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。 [url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png] 查看Modsecurity日志 [url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url] 所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。 $ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.logModsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。
B" M7 J: X8 A1 |$ P4 R$ {* B |