找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12537|回复: 0

利用ModSecurity在Nginx上构建WAF

[复制链接]
发表于 2017-10-19 17:34:51 | 显示全部楼层 |阅读模式
ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。
/ q9 C8 t" g, h9 z, M: P5 @
8 ^1 Q# [. q. U0 H: _: E7 Z; |
4 |2 K- c; y4 K, o; U在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。# e0 o7 b- F# r

+ n0 }  V1 J0 A9 ~8 C* |! t0 _" Z3 D: n+ M1 l% e6 c; C
什么是ModSecurity; v8 c5 K6 i, H# b
ModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。
- ?/ }+ V9 A/ `7 d$ J/ {9 Y5 P* J  E
: k; D- @- |* D  c* g# K& j- h+ S. u1 I
ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。
$ m, t8 v0 {6 b7 ~; I" A# w& l
: E) ^1 x0 Z* k! M% }/ Z* W1 A( q- \! h9 t! \
ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。. e& o" x6 |! Q  M% i/ T) r
$ B$ c' B. ?1 Q. q9 t5 @  n
  h# m! r( {3 o9 n. ^
官网: https://www.modsecurity.org/
4 U" s: V6 y2 ?/ m
( F# J# p! w3 Y  e
  [- s* X2 Y( m6 |/ f* R5 y什么是OWASP CRS
$ \9 s& t1 @8 d1 H; iOWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。
; m" a  V: N2 A! ~+ b
+ Q/ Q: T8 `+ @# p
8 k" B1 s; s( @7 _. MModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。+ Y% b8 \8 o2 {

/ M5 Y4 i: W! v8 r1 q0 n% I! b! ]$ Q9 [' ^4 ?
HTTP Protection(HTTP防御)
3 p' X3 N7 P4 t$ ZHTTP协议和本地定义使用的detectsviolations策略。" D6 }4 [$ Z7 |  c0 z

$ o; a+ Y! ^5 u7 L
* b7 j7 C% w7 [+ d4 T  HReal-time Blacklist Lookups(实时黑名单查询)% f' ~) w! p- d' X- F8 o( r
利用第三方IP名单。. L! }% _( p% S$ t. i) Q# I
% O  n& c- F+ l% w' e

* x4 T3 Q( r% w( Z6 d7 Q* v: IHTTP Denial of Service Protections(HTTP的拒绝服务保护)
% h* P, A9 E$ D, D9 M6 u# u防御HTTP的洪水攻击和HTTP Dos攻击。5 Y, Y1 P5 j" F0 x' Q. l2 E+ Z
+ ?% _& ], V; e7 g! S- D% @

. M; }, R. q" c( d( b: iCommon Web Attacks Protection(常见的Web攻击防护)8 D9 j$ F% d+ J1 N
检测常见的Web应用程序的安全攻击。
8 Q( K: ?2 _$ l# a7 p$ ^3 V; ]9 j( |7 }) K6 c2 u* U, Q
# n8 a3 e% B, g6 z, I
Automation Detection(自动化检测)
& C5 s: K- R4 @# ~9 n+ j检测机器人,爬虫,扫描仪和其他表面恶意活动。
: S5 p( O/ k7 f2 \
0 N( q" I* o) s6 _
& [! ?5 z0 I# Y7 }# o" U8 X6 UIntegration with AV Scanning for File Uploads(文件上传防病毒扫描)
; r; ^" z) F3 y# m" ^检测通过Web应用程序上传的恶意文件。
% l  |8 b/ p' q3 G% S' S+ F. U
$ \* Y/ v) M/ N" m& X, [
* w' i+ k: q0 h& I8 H8 [4 ?; ^Tracking Sensitive Data(跟踪敏感数据)9 k. T: ~# G' T( ^
信用卡通道的使用,并阻止泄漏。6 M, D9 A. a: Q0 \+ G6 M: T' i" L

0 O; d1 U& [6 [5 X- [8 T0 \  e* q8 _7 R5 _7 Q; N
Trojan Protection(木马防护)
8 k4 i& W9 `- E1 M2 X' H检测访问木马。
4 U3 x& p, j8 F, l) O$ ?3 K
* B! N1 g! {2 e/ w' N1 J: Q) `/ Y! Y9 @5 L. g8 B
Identification of Application Defects(应用程序缺陷的鉴定)
+ [6 t! s: [" a0 V" }+ H6 C1 @- x检测应用程序的错误配置警报。5 H. S/ M( W+ J+ i

6 [; ^$ N; {! X9 T  \' C+ g7 e, X1 I( c
Error Detection and Hiding(错误检测和隐藏)
1 H! T, C- r! ~) o检测伪装服务器发送错误消息。
# G& Q0 R+ _9 g- T. L) T3 e8 M4 t3 }' i4 H' q( t

9 M/ [5 W( N( d+ a; {) ^0 b安装ModSecurity  ^4 w6 b2 I* [+ Y, Z" z
软件基础环境准备% D9 _5 [0 R& }. y" C
下载对应软件包& D- t. X3 q- o* Y0 a& D0 Q; H; E/ j
$ cd /root3 F% m6 Z# {8 K; [2 c- ~. }
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
) b1 x. B8 d' U+ f! ^0 h$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz
1 f6 s/ r2 ?2 c" Q5 E安装Nginx和ModSecurity依赖包4 c# t% t3 V+ b& V' N2 Q6 X
Centos/RHEL
6 P- q( H/ Y% R! E# e3 O- T" C3 S6 u- Y* l
/ A& |* w( c; [9 w; A
$ yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel8 w) X" m( V+ w6 r
Ubuntu/Debian
$ k! J& Z; A$ h& p: M7 D
# f9 u' f6 }5 d1 X! ?0 J# a) T! A( z+ z, W' |9 O
$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git  libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev
' \) o  T& D4 `; [. I3 r- [5 ?编译安装ModSecurity' A: e+ k8 Q  m) ~8 `6 I
Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。
5 W9 O. S5 N0 D0 w: a7 }5 o6 w5 v$ d4 J  h. e' e# u

8 z+ D, L# E# B- b4 P7 k方法一:编译为Nginx静态模块
* D1 t* y3 f9 Z* G1 E
3 n6 a, e+ ^6 f% A! H3 }$ U& ~8 R; B6 ~/ n, L
编译为独立模块(modsecurity-2.9.1)8 c( a6 `. K' V7 _: l
$ tar xzvf modsecurity-2.9.1.tar.gz( n$ W, v8 `) k; w0 R) \
$ cd modsecurity-2.9.1/
7 i8 C8 s1 c2 [9 u& R$ ./autogen.sh
! B+ g8 O; a6 W+ X$ ./configure --enable-standalone-module --disable-mlogc: l) X3 y& Y8 X5 f
$ make( T+ l. ^7 m# w' r
编译安装Nginx并添加ModSecurity模块
5 ?! Q  r7 r0 m3 y1 W$ tar xzvf nginx-1.9.2.tar.gz. V* c, [) t% T/ }. |; A0 u
$ cd nginx-1.9.2' {9 v2 q" E( F3 H/ A; T+ }
$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/7 x! g7 c4 @+ `4 u7 n  m
$ make && make install1 Z$ @7 R# b! G$ ^
方法二:编译通过ModSecurity-Nginx Connector加载的动态模块
2 J: G  D. t$ j) ^: U7 x5 ]8 ~6 \% O' J

; U/ Z8 O) B: X" B1 p' J2 H) t编译LibModSecurity(modsecurity-3.0): V& Y3 M7 ~  }* s. J
$ cd /root* c! ~7 V. I4 j) m+ l; j* N  T
$ git clone https://github.com/SpiderLabs/ModSecurity
8 ]" P0 Z7 ^! d* H, H6 m$ z" ?$ cd ModSecurity
& Y$ D( b% b5 G( G( m. C+ t( h" |$ git checkout -b v3/master origin/v3/master
! G8 r+ G* Y) e  V' L; m$ sh build.sh) q: D+ m; s3 C
$ git submodule init/ d8 I& \6 c' E7 D+ w: D  Q' ?
$ git submodule update
: A$ ?3 z+ c. {* p$ ./configure! v, Z) t! f! y4 N# i! y
$ make1 ?( b! j8 W/ u1 ~" C9 R8 d0 F2 s
$ make install
# H, k* \0 V* K$ V; ?1 fLibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。
: I  I4 ]& |3 i) \; b- `0 w* k3 ~( P$ w& p
3 @7 w5 M7 i+ H3 T4 a
$ ls /usr/local/modsecurity/lib  ~2 R4 z; V; E( `
libmodsecurity.a  libmodsecurity.la  libmodsecurity.so  libmodsecurity.so.3  libmodsecurity.so.3.0.0
% A6 C2 ~0 p; w, n- h7 x编译安装Nginx并添加ModSecurity-Nginx Connector模块. H& O' a& y: O, M- Q
使用ModSecurity-Nginx模块来连接LibModSecurity/ z0 a  J+ K' l) \# ~  S! D. i
# `4 @$ \9 B0 f2 b. ]  V( D

  S4 M" l5 K- r+ W" O$ l$ cd /root
, U2 D1 V8 p5 g) X: p1 u$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx) x: Z4 ?6 |9 q# {6 R# o& [
$ tar xzvf nginx-1.9.2.tar.gz: }" R& D8 {4 F, Y: d
$ cd nginx-1.9.2
/ L# C' u1 D' i: F, W' P0 j0 \0 {$ ./configure --add-module=/root/modsecurity-nginx0 k# k& N( }* ^/ A7 H+ C
$ make
1 q3 ?1 y; M( G5 t7 v$ make && make install
: `, f& {* ?7 P! h添加OWASP规则
& j$ J5 v% I) Y: U! |8 g+ F! o0 r: JModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。
0 I1 `$ A4 Y) m, }
6 J1 O0 [/ h3 ?4 b' i$ x: u, _) O- D. w% e% S
下载OWASP规则并生成配置文件
  s: ^" U7 k8 _8 `% n1 t& |$ U$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git
! y$ s' z$ l0 M  i* Z7 L. v7 x) K$ cp -rf owasp-modsecurity-crs  /usr/local/nginx/conf/
" F  Y5 t% b' u) e$ cd /usr/local/nginx/conf/owasp-modsecurity-crs8 `3 U- Q5 O# C7 H
$ cp crs-setup.conf.example  crs-setup.conf
2 ~8 ^6 d; k6 v配置OWASP规则6 y' d) ?. d. g, p
编辑crs-setup.conf文件( W$ j, g3 |! J+ e+ a5 l

/ u* }' k) g" L  y+ q7 I  c% D3 J8 b* q1 O- s
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf
1 B7 k1 Z1 f1 a7 z% T4 \$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf
+ q8 t0 y9 x; h, N" I8 Y* g# G; O$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf& y: O" R* _) X
$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf) `* b8 K$ B' I
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。0 U: c) V( _" Y, i
/ b/ g* w+ q: D5 f1 N6 M

# p6 p! x/ C# t- c9 r! K8 e# C& Y启用ModSecurity模块和CRS规则
! _/ r3 l# R, b* Y2 T复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。/ {) M! b; e+ i0 f

5 O: f1 g# E* F8 L3 j  C/ p
! o( P$ `+ t& j( p+ V3 b1 fmodsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。
, Q2 W' N1 g, A
, [4 k9 ~& ], k3 g: X) H, {5 t0 r8 h; x$ |4 s
$ cd /root/modsecurity-2.9.1/
; @4 {. q0 S* l. U: `$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf  
& p8 K; b1 k1 S, C$ cp unicode.mapping  /usr/local/nginx/conf/& j7 }0 I3 k  u
将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。% _, K  B. b3 v* D5 c3 T: W
+ M8 i. w% p3 M. @" P% \
3 i+ N* F# i. [7 W2 S7 L" r# [- I6 s
$ vim /usr/local/nginx/conf/modsecurity.conf
/ q3 [9 _# Y8 s8 Z# P( j8 @SecRuleEngine On* ^9 S: _6 b' A1 v" d) W2 Q! N
ModSecurity中几个常用配置说明:
" x) G" S2 l: B* W7 x% @2 y1 N2 X* O( H( H" \( m& p( e! [

0 Y4 n/ C. Q) }9 p  ~1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。/ {$ {8 k4 H. ^& y. G
$ a. E! n+ t/ S- p* \! I
5 L3 U# ?( L; Y  W+ e. Z: ^
2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。/ m6 _7 e) l# q: i  T1 A

( u$ }, ~0 c/ {; v$ M: S, |, z- j$ v
( V, Z% }! \/ R. n9 c& D! [/ q3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。9 E( k' v& H* R: `! ^
% g4 G" E7 @/ n/ V) O

# t" U- O. u! B, m  V2 E% w4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。
2 p7 C$ d  ?# e, R+ [; J1 c8 [* q1 A. x
; {# _# p; U  s) F. T( n3 X' S$ e
在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。: D1 m( Y7 o. ?3 c) ?* l0 f5 ?3 B& A

" C% F( f# A( F# h4 W6 Z) E1 r9 ?! c% W7 W) p' B9 O
3.x版本CRS
2 _! q. v  l2 ]3 j! H- X# M; C' M$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
2 g3 f4 ^9 z: G6 X7 o/ d; h# 生成例外排除请求的配置文件
0 ~( x8 h5 T2 ?# G$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf9 {- \5 N8 ~" N2 {, ?2 Y7 u! F
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf- [: k9 \5 T  k/ N$ ?5 g& x/ ?3 ^8 t
$ cp rules/*.data /usr/local/nginx/conf- Y6 t$ Z& d* `5 f
为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。
# e) M+ B8 @* |* o* F$ N  D
* j  z; G; a# v$ k  X1 I0 A  W4 a. {; ], ]9 v! S! F8 w# h+ M
$ vim /usr/local/nginx/conf/modsec_includes.conf
5 k& r) P6 D$ V$ u" @0 B  R$ ^6 T4 _( b) k
[Bash shell] 纯文本查看 复制代码
include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
  [8 P& h5 `! h5 e- S5 e: T, T8 H( u

; U3 V9 V! z* X3 x注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。
3 Q6 k, d' w! v% i# f9 ^1 N0 }# @! R  Q& j8 |5 `: |

( K( ^! P7 C. Q2 T! A, @# Q+ I! b/ l配置Nginx支持Modsecurity
) l- z! T2 S5 C/ I$ g启用Modsecurity
! ?- m7 _$ L# h6 J1 b使用静态模块加载的配置方法, J- i. h9 A+ M4 k: G' r5 z
在需要启用Modsecurity的主机的location下面加入下面两行即可:+ Z3 D% Q; x' n9 o4 O

" ^* {; V( }9 N' _  ]' e( V% f' b0 W4 ]
ModSecurityEnabled on;  I9 i$ p+ f) L$ B) P" E
ModSecurityConfig modsec_includes.conf;
# c$ ?! v9 d, Y& d修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。* y# |+ R: s' i* ]7 ]$ {  ^

2 c8 \/ a3 H" R) w; `8 s1 _6 Y; c8 C/ l7 w- I7 x
$ vim /usr/local/nginx/conf/nginx.conf8 Q3 W6 D# {6 |; L7 r# C& U

" |' b1 i& z" ]. @& _9 \, x
3 M3 [, C, e, ]1 C3 x. Pserver {
' C- }; l' H) e$ t* {0 N3 M1 L  listen       80;
: @+ d7 ~# c4 R) G1 f# T( @0 ]  server_name  example.com;
3 S9 W4 W3 z- p9 i5 V8 N' C6 G5 N# G
1 G4 G- |+ Q( h, |
4 K% c; G# P( `; k: {  location / {
2 d, u8 }; H4 r, B/ O, k    ModSecurityEnabled on;! p+ u' V1 u1 C: w2 ^: O
    ModSecurityConfig modsec_includes.conf;
5 Z5 H. k" b" P8 K* f# j+ X2 g6 T    root   html;, R6 }  G, N6 e2 L7 x
    index  index.html index.htm;4 c1 S) D' a# ?+ r; \$ y
  }2 w! s4 s& v) c+ q  B+ d
}+ |  q6 ]7 A2 A4 N: }
使用动态模块加载的配置方法% x* R! l+ D# T2 S9 t  k
在需要启用Modsecurity的主机的location下面加入下面两行即可:" x- e5 r3 l) {% _5 y7 T

  E5 ^: E0 l2 N6 \! t; }9 P' |, v! Q: A8 V
modsecurity on;2 b8 o3 s( Z% [
modsecurity_rules_file modsec_includes.conf;* ?2 l" w) w9 S8 @! Y
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。0 Z! b; }* W3 T
+ X2 U3 d7 H4 [% O2 e

9 Y3 ~" y  [; l$ e. U' p: b$ vim /usr/local/nginx/conf/nginx.conf
# \4 ]  o, r) F! }/ a1 P1 d/ o0 o: J* C" U, S" J9 ]+ q
: S. i' A) X+ ?3 \3 c: z. z
server {
4 A  y& B0 B: |- ?) q! r" L9 Z  listen  80;5 o& s$ y- u- |! i- {0 @5 T
  server_name localhost mike.hi-linux.com;. n/ i7 D- d' Y/ k. r( @
  access_log /var/log/nginx/yourdomain.log;
9 p/ _% G0 a; z/ ^% B7 \9 k3 f# k* \/ K& T+ Z
/ P0 N* D7 g2 ~3 V% W
  location / {
# {. Q! n9 e# v8 E6 d
, x  ]# a5 S3 b- l! [: S: n+ B! J! q& L4 R* [
  modsecurity on;
9 W! j) R3 N1 d5 Q( e* r8 b: W  modsecurity_rules_file modsec_includes.conf;
( u% C( N! f* X9 l2 P  root   html;1 w- o& Z* A! o- h; C
  index  index.html index.htm;
/ e3 }% P# ~8 [}1 g8 a+ x1 V. T. K
}
: H$ \/ a& @8 b验证Nginx配置文件
0 D! }3 \4 o6 w) V9 G# \3 X$ /usr/local/nginx/sbin/nginx -t
' h$ X, S- ^9 U3 M, X; \nginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok5 ^) @, E2 D! a
nginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful0 {/ w6 K  c. B
启动Nginx
0 S3 f" F' c3 y6 {0 q% U$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
) Z0 e  d2 P) E4 u& S2 E6 b
, y# j8 D& u% b; E" S

测试Modsecurity

ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。

在浏览器中访问默认首页,会看到Nginx默认的欢迎页:

[/url]

这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页:

[url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png]

接下来,我们在前面正常参数的基础上再加上  ,整个请求变成:

[/url]

就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。

[url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png]

查看Modsecurity日志

[url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url]

所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。

$ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.log

Modsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。


$ W. _' R5 z; j  R7 B6 \

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-9 17:19 , Processed in 0.077245 second(s), 22 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表