ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。
# G+ _: N" `6 X- }* f0 O
. P9 P4 \6 L% w' s; }1 ~& v0 l- l* d. }+ |0 }9 V
在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。( x' u& ]+ `9 M2 L/ A; N
/ x/ O) Y' Q% v7 \, I! A- V% ?
- T2 p0 G$ k8 m什么是ModSecurity
. m G6 r0 A+ z8 H- Z- iModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。, F/ G& S3 _: c, y. L
! P# ?$ u2 s+ {, P$ l* e! K5 M$ D
; a; ~! r5 Q2 R b% F6 JModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。3 B2 V! [) g0 j! b% w+ Q( O
8 q1 e* }5 y# m4 W( Y0 `, \) i0 r5 q; [
ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。
* b0 {/ Q4 c0 H9 u1 x6 u) ]) j+ ^7 {( x. U# Z
$ w# ^/ ~8 e2 P官网: https://www.modsecurity.org/% V- p7 A# c% l3 j1 W. t
: w; F Z4 i0 u* _1 _2 i' u4 E- Z4 ?" {. n
什么是OWASP CRS
' q& J! m$ t2 E/ @! GOWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。
+ E% P$ k D* C7 m9 o% j6 J$ E0 p" G
& S; K/ J$ M4 v' @; K: ~1 v
ModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。8 h% [1 a" z& {9 B, n$ Q
. Q- _1 {$ B9 b+ o
* X. i) S: G9 yHTTP Protection(HTTP防御)
; R# u5 ]/ K) fHTTP协议和本地定义使用的detectsviolations策略。
H4 A8 K; M: D/ b* ?! ~. c8 P+ |1 J" x1 N
* Y5 G1 }$ w0 l- L v* h
Real-time Blacklist Lookups(实时黑名单查询)
0 Z3 J& \6 W/ k利用第三方IP名单。6 \; z( i8 M7 ]" S
% A% z8 q! u9 y) x
! w; _0 E' _, P1 ]' b. qHTTP Denial of Service Protections(HTTP的拒绝服务保护)
0 w7 i$ `! C- j. y$ _防御HTTP的洪水攻击和HTTP Dos攻击。- [+ @" m2 ^% y. @: P3 e- a
$ ]# I( m' s9 J' X
! ?' v }" B; \0 K
Common Web Attacks Protection(常见的Web攻击防护)% W2 L8 e0 [. R( j. _: e" N
检测常见的Web应用程序的安全攻击。" S( e* R* I& N! t3 [
/ G6 Y5 ^$ a1 z- X; V \' S; k" I: o3 p
Automation Detection(自动化检测)
" {7 P& M/ X1 {6 h) B检测机器人,爬虫,扫描仪和其他表面恶意活动。
1 a+ o* G' i! K5 x: ^# X. _. {2 s# Z- y- H; C
: w( C; V- e! k) }Integration with AV Scanning for File Uploads(文件上传防病毒扫描)
& p' ]% \7 k! u- y检测通过Web应用程序上传的恶意文件。+ a0 l, y1 {+ V9 f" B/ `7 |
- J% i3 x; B& n) S7 B- E
/ j7 a w+ ]0 s, T2 _& BTracking Sensitive Data(跟踪敏感数据)) a$ n) ]9 ]3 W5 R4 J2 t% B
信用卡通道的使用,并阻止泄漏。
\ G$ q4 G$ E3 K* S
& [/ l/ |! I' U) u1 i- t1 }, g& r9 S* e
Trojan Protection(木马防护)
* P1 t0 _; ?* k) i0 u检测访问木马。 L/ Y+ d, R7 ~: m0 E
$ W) t! d/ H& y B: B3 A" R% Y/ g7 D1 _! ]9 e, C0 p4 U& v
Identification of Application Defects(应用程序缺陷的鉴定)
) q0 v, J% m% Q' K6 D2 F0 n8 E检测应用程序的错误配置警报。
! l3 ~8 |9 i9 ^& o; ?4 h d' s2 [$ {% J' }( A! Y2 v
' L& I* G1 I( P, n6 o7 N8 q( `. fError Detection and Hiding(错误检测和隐藏)
1 c0 o. i) g- }3 C$ i: W2 z5 k检测伪装服务器发送错误消息。
5 P4 o+ [- n; N4 `( c5 x2 y* H" r! a$ b
3 H! y4 y% K: U: v
安装ModSecurity
% S/ x4 T, F0 G软件基础环境准备
$ W# s7 C( Q3 b下载对应软件包8 h9 C. \2 b) m( F7 V9 t
$ cd /root2 B l* ?9 |9 p3 {, J$ E
$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
3 W0 O" d% i6 K, u$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz% D& w7 h# D/ D( z; }
安装Nginx和ModSecurity依赖包& s( T3 Y( k$ B4 c. C* @' ^! j
Centos/RHEL6 T( ?' n: I- }9 s
" @( T4 T- \$ j9 |. b6 G# d( [$ V2 h. i! o A8 W
$ yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel) t, H# @" C, i+ I0 Z1 k! W
Ubuntu/Debian$ e8 d( b3 t, y2 }6 U, C* Q
( f6 K* n! v+ O/ [/ p& u' `
: m% B# v. \, {' V7 r$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev
' F# v) y' Z, D8 O3 f. b编译安装ModSecurity+ c' s. A; i, d5 s9 W
Nginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。
! j( X5 s- i) i t! w" R/ ~( H& I ] t6 z4 p
' d' S" _) a: b* t8 C. K方法一:编译为Nginx静态模块% M( q- j1 w8 P% M8 Y
, O6 ? {' g3 k$ w0 ]+ r0 N# n5 L$ e% V3 z; p* a
编译为独立模块(modsecurity-2.9.1)6 A! ~0 `* g/ i) d
$ tar xzvf modsecurity-2.9.1.tar.gz
- A( d( C! c: @) P/ y$ s5 P) U5 T$ cd modsecurity-2.9.1/
$ x9 p; ~' `" I3 u% V$ ./autogen.sh7 ~: [# ]; z" J4 s1 U
$ ./configure --enable-standalone-module --disable-mlogc
1 P* G* D* k# q. ^: L+ ^4 q$ make! j4 J5 ?: K% B
编译安装Nginx并添加ModSecurity模块3 C% S& h7 _" X. r/ [% `7 ~
$ tar xzvf nginx-1.9.2.tar.gz
0 {: d2 B+ B* c4 w1 x$ cd nginx-1.9.2
: N& K! C% f5 l$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/9 K2 x% q. B7 z5 G) {
$ make && make install
) M! ^5 s* S( `- D1 s方法二:编译通过ModSecurity-Nginx Connector加载的动态模块1 E# C9 R0 a7 f: d
' d( l Z8 X G. d |0 N& Y8 L4 P2 O% |& c3 ~$ |
编译LibModSecurity(modsecurity-3.0)5 n% Q7 \1 W0 F8 g. R9 R; y
$ cd /root4 [) N; w" o! J% l2 m" y3 O
$ git clone https://github.com/SpiderLabs/ModSecurity
8 }( |; U' a) Z2 K: C, V: ^$ cd ModSecurity
- F9 B. ^6 C! k# a+ r$ git checkout -b v3/master origin/v3/master, L2 S' v& g; a# ~
$ sh build.sh
+ \3 {; C" Q/ h8 j N3 ]6 G! ~+ p5 q$ git submodule init
; N; a! U- f8 T" f4 |$ git submodule update! h4 I% A# E* D% x
$ ./configure
2 N/ L/ O. l! {$ make
9 w" G8 g6 j9 p! w$ u W. h$ make install
& I$ U- `. W% @5 l+ L/ bLibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。
) [* u6 |. B. T6 K: ~7 A( w5 C
; F, J( K2 f2 Q; t. t5 S% o5 D+ B: p. p
$ ls /usr/local/modsecurity/lib
- J$ y% _5 I) |) ^/ Mlibmodsecurity.a libmodsecurity.la libmodsecurity.so libmodsecurity.so.3 libmodsecurity.so.3.0.07 s) o- d( L# x( `( p/ o5 m8 C3 o( U, F
编译安装Nginx并添加ModSecurity-Nginx Connector模块3 [$ s X* f" e4 J" k9 [9 m
使用ModSecurity-Nginx模块来连接LibModSecurity4 A- s) u) }; J# d0 H- P+ a' V; i0 L0 H
# k+ L7 ~6 O, G5 m* n$ E1 ^
# [+ ~5 d) ?2 r9 c" k4 V: j' y$ cd /root3 l1 F/ X% P, x2 p: \
$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx3 M- C2 q ^: t+ y1 D6 K4 a$ e
$ tar xzvf nginx-1.9.2.tar.gz* O* V8 k3 o3 m1 X6 c& F, `7 E
$ cd nginx-1.9.2
) c4 k. N$ H, X' T J5 C$ ./configure --add-module=/root/modsecurity-nginx
7 x- }( T) a$ H6 V1 G$ make
$ Q4 H0 L$ H6 ], N) R$ make && make install
5 B: L# G) G% t5 P& ?* g添加OWASP规则
/ {* [3 A% c9 b. Z' @ModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。" P4 u2 l0 @7 d) D* M2 l
/ Z/ d6 h3 n4 Y" ~! G/ b
* u* K6 Z/ e, q下载OWASP规则并生成配置文件" Z3 p( r$ q* L h0 Y3 a
$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git
6 a/ @( k d$ A( A9 G0 t$ cp -rf owasp-modsecurity-crs /usr/local/nginx/conf/( R+ ^' ~4 w, [' x0 Y( U& T
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
! G2 p, U) m" d% P& Y$ cp crs-setup.conf.example crs-setup.conf
" C& z4 Q3 C9 {9 x$ p. B7 p配置OWASP规则5 C; \ o5 _' H
编辑crs-setup.conf文件
c! c3 U" o; P7 `% R8 c
# q1 ?) A8 R& V9 |- Z: ~
" j" J3 U4 j1 h" q. B$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf
- r7 g" D/ ]& D2 E$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf; ^0 L" k- g; v- A$ Z7 E
$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf
4 j; h+ } y1 g( O6 M$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf9 \6 t. m3 j6 n
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。
- x5 ~2 _3 o/ W! o* r( j" A3 J8 H9 s
- i' E4 I/ L: G3 w5 R: [2 O9 A
# ]' Q1 s: |4 g: Y# q# Q6 e& h3 H启用ModSecurity模块和CRS规则
5 u0 z$ z+ s+ Y! G复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。% ?/ a2 u! x/ J r
) z! N4 T, x' f
" Y4 e# |. [7 O# E% t) V
modsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。2 B1 p4 F! r) {7 v) }
5 t4 c- m+ I. Q& V
1 k' p& v4 ?- z) K# M# v7 Z$ cd /root/modsecurity-2.9.1/2 f& q8 h2 E0 Y0 ]8 ^4 C
$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf 4 A* @+ A. k/ q* _- M0 W% f
$ cp unicode.mapping /usr/local/nginx/conf/
\: ~# c5 _- J: n* H, [将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。, L! p& N4 @# S2 ?9 ~/ x1 C
8 v- u; m9 Y# [7 X9 ~' T
) L2 A7 U) ~4 h: F. a) w @) u, q$ vim /usr/local/nginx/conf/modsecurity.conf
8 `# ]% _2 T o* ~ _. wSecRuleEngine On
1 G) c# y7 |5 J7 U1 EModSecurity中几个常用配置说明:
& O$ @7 Q7 y+ U0 g, g6 m, [$ C# u
! l d3 |& y' ^2 g
3 q) J3 e- |2 V# y1 }) l1 F; t; s1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。
0 n' k0 G5 k( s/ n% k) P' j
1 d9 n$ `4 ~* ~5 t3 K/ b
/ S1 |6 v* b8 K2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。
0 B2 z2 H, Y4 d8 k* Z' x! G% }3 ~$ L/ q$ x: f ?
1 D2 \6 k. X% a3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。# {5 S% q& D4 t( N2 B
5 g$ }' A( u; p$ {1 B$ Q4 m& {
8 `7 d: Y, M6 {1 O; m1 ^) b
4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。7 A' m7 U0 A7 k- U; P" a
5 j; j1 Q* W1 a9 i1 d9 P! i6 ?) ?' t9 P' M6 C l
在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。
' S1 B1 `( r" s2 f0 B8 j5 a4 Q/ r' g0 u+ x
: [+ o& C5 n- R; S1 e1 ?/ Q3.x版本CRS) K- V% Y4 a' s) [* J5 {
$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
/ G9 s& q7 A& v& H# 生成例外排除请求的配置文件. P/ y3 c C8 u3 E2 O2 a. i/ ^0 A
$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf& C8 I! K/ a& }1 \
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf& K# a# _$ g9 |6 n
$ cp rules/*.data /usr/local/nginx/conf& ^6 @( x- O5 d' [8 j2 |
为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。0 G( q- h0 e' K$ M
0 }* R! m8 ~- O" s0 q. f6 T
+ P/ M% S3 W ~; B! J$ vim /usr/local/nginx/conf/modsec_includes.conf
U: D' C2 P3 M4 I! y" w8 k, W3 x, z. D4 K: ~; F
[Bash shell] 纯文本查看 复制代码 include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf 7 e6 n( v* S [5 m' f& I# ^; @
6 M9 k( ^5 h5 l" t( L( I# [- P注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。
8 ~( x- P0 P+ g" Z
+ h( e8 U9 i% w. A5 J1 F0 n j: }8 O0 l% P' }5 d7 V0 m- M0 I
配置Nginx支持Modsecurity
- ^& D: e; Z z/ B1 c7 n) A4 w启用Modsecurity
# x2 C( n- q4 V: k: @2 N使用静态模块加载的配置方法
: @* `) F/ R8 G& s, [在需要启用Modsecurity的主机的location下面加入下面两行即可:
( |( U$ q3 | I3 X; F
+ d; W$ q( o9 b' a7 x9 y, H& l, Z* e" @" d1 H' ~. |- n
ModSecurityEnabled on;
2 |; M- t) h. {* j- HModSecurityConfig modsec_includes.conf;
& |* ^, f- m' i5 o0 g4 a" r( ?" x+ W修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
r: j- W3 X+ y, M' p9 ^# N0 M2 O
8 C; M6 o9 ?4 y8 i$ vim /usr/local/nginx/conf/nginx.conf
3 D2 R4 t" f% Y& L( V
1 e+ W# }" K! X% A, Z: I
4 [6 S& _2 j9 v7 B# `8 userver {
8 O! i* y3 F( G" T/ `) D listen 80;
0 u( G! e& Y8 X server_name example.com;# E0 w6 D- u% n0 N0 [3 P2 c8 w
. ^4 a9 i/ t3 n# O$ y
1 } R- B6 B2 U% O2 b location / {
# X a$ U+ J) z4 A& n# E ModSecurityEnabled on;
$ }) `3 X! D" Q! w& R; f. l7 | ModSecurityConfig modsec_includes.conf;
% K% V2 u( T% D# B: \: E root html;
* D: Y# p. ^2 `$ j- G index index.html index.htm;7 |/ f8 A: ?6 b; f
}
- ]3 ]6 Q% o, v& a}8 b4 w( _0 j- V" j
使用动态模块加载的配置方法% U; J1 a* ^* S: R
在需要启用Modsecurity的主机的location下面加入下面两行即可:" l9 Y) e* V# ~8 a2 _9 u
0 a o& _0 N# y! c( H! B* [
W' X8 ^" r! k2 o0 I
modsecurity on;) K/ H& {7 H4 u4 ^
modsecurity_rules_file modsec_includes.conf;) |+ q% a! m+ ?) a F
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
+ L( L1 u! R" i7 ?; _' T: ]0 i4 L: v" i. [" `) W
7 B% P- F) {6 v& J$ vim /usr/local/nginx/conf/nginx.conf
" c- f4 x$ h G2 @3 x1 Q/ A- c T
( ]2 T& W" d+ R
7 j* I o l: Qserver {* N. s7 E0 m0 L1 @# P3 Q O
listen 80;3 f) i$ C% x( ?* ]# w
server_name localhost mike.hi-linux.com;0 f! K$ ]. ]$ C1 ~6 I/ F. ~
access_log /var/log/nginx/yourdomain.log;. \8 U" O, B1 X: N! ]4 a
* [' j& s6 `& W
$ S/ k! Q+ |( `" |. M+ \ location / {
( c5 |/ i- ]" F. d* ?( P2 J
9 ]" g% ?- x" `5 e3 Y/ {! X
. o% {6 L3 p5 g" z5 _* d8 l" Y modsecurity on;
/ R$ ~- }0 s% c( s& ]* F! e2 K modsecurity_rules_file modsec_includes.conf;
1 Y& A2 o* g0 ], Q root html;3 t- a8 l' { z
index index.html index.htm;
7 O5 d7 E7 n0 E3 A: X# `! R}& U% ~+ T1 E. l6 E0 D) J n F
}
3 T* X$ f( a2 ?+ d$ p$ W, V' J& B验证Nginx配置文件
+ K; b( v! ?9 C: T$ /usr/local/nginx/sbin/nginx -t
. h( g' a& a$ h: [! _nginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok
$ b. A( S" _$ y$ p2 g; D6 Dnginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful
+ w% |0 P+ x a; A. x: y1 `) T- ]启动Nginx
. r: x4 M/ m- k: n8 O9 x$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
3 i2 t, w6 |' Q& z+ y$ ~& ~0 n- _% w5 }0 r! P
测试Modsecurity ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。 在浏览器中访问默认首页,会看到Nginx默认的欢迎页: [/url] 这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页: [url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png] 接下来,我们在前面正常参数的基础上再加上 ,整个请求变成: [/url] 就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。 [url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png] 查看Modsecurity日志 [url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url] 所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。 $ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.logModsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。 ( ~8 p' H- X! H0 K! f: P2 `0 m
|