找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12492|回复: 0

利用ModSecurity在Nginx上构建WAF

[复制链接]
发表于 2017-10-19 17:34:51 | 显示全部楼层 |阅读模式
ModSecurity原本是Apache上的一款开源WAF模块,可以有效的增强Web安全性。目前已经支持Nginx和IIS,配合Nginx的灵活和高效可以打造成生产级的WAF,是保护和审核Web安全的利器。
* M6 ?8 D7 Q5 C5 [4 ]+ r. u, I
; \9 v4 ]# w; Y- f2 K2 E% e. ]4 q+ U, s. i) a  {
在这篇文章中,我们将学习配置ModSecurity与OWASP的核心规则集。" }! f4 t- x; E4 _% U1 S

$ J, f. U8 [0 v3 [, B0 _( T
  t: x1 x' P" z什么是ModSecurity
; [% ]4 j" J: UModSecurity是一个入侵侦测与防护引擎,它主要是用于Web应用程序,所以也被称为Web应用程序防火墙(WAF)。它可以作为Web服务器的模块或是单独的应用程序来运作。ModSecurity的功能是增强Web Application 的安全性和保护Web application以避免遭受来自已知与未知的攻击。6 V# E4 m# C3 `
; h7 V6 t  ~) p+ n

8 v8 p0 b- O" R. A$ u8 z2 |$ f( ~ModSecurity计划是从2002年开始,后来由Breach Security Inc.收购,但Breach Security Inc.允诺ModSecurity仍旧为Open Source,并开放源代码给大家使用。最新版的ModSecurity开始支持核心规则集(Core Rule Set),CRS可用于定义旨在保护Web应用免受0day及其它安全攻击的规则。) T1 R$ [5 G5 x* e

$ }, O/ k( p2 b( D* {! e2 s
; T$ U) P, j  E+ a0 [' ^' D- ^ModSecurity还包含了其他一些特性,如并行文本匹配、Geo IP解析和信用卡号检测等,同时还支持内容注入、自动化的规则更新和脚本等内容。此外,它还提供了一个面向Lua语言的新的API,为开发者提供一个脚本平台以实现用于保护Web应用的复杂逻辑。! o8 K0 _4 p8 `: N

8 W- n4 d8 V" X* G% F$ }* N+ p8 ?: q  K5 ~
官网: https://www.modsecurity.org/
8 |0 d% O# {# [! s8 v1 x' W7 j9 \- C; y  d

4 ]: R& n" S$ F  A) X什么是OWASP CRS$ Q5 d  w$ F3 D4 h+ g6 h
OWASP是一个安全社区,开发和维护着一套免费的应用程序保护规则,这就是所谓OWASP的ModSecurity的核心规则集(即CRS)。ModSecurity之所以强大就在于OWASP提供的规则,我们可以根据自己的需求选择不同的规则,也可以通过ModSecurity手工创建安全过滤器、定义攻击并实现主动的安全输入验证。4 Q" c; {) C$ ]4 L3 ?6 o% k
- f2 [- S0 D7 C) i3 k+ a3 c

9 d4 r# @! Q* c+ ]' p8 M- [& ?1 ]$ WModSecurity核心规则集(CRS)提供以下类别的保护来防止攻击。
( E- x" C4 I: v  v: P# h; Z. `. r! x0 m
' @) _" Z: m, u( B  v) l  |4 D, H1 `
HTTP Protection(HTTP防御)
3 F/ k( e1 ^/ e5 xHTTP协议和本地定义使用的detectsviolations策略。
( ~( M' T, d% Y7 Y: H
% E$ ^8 }8 g4 w; H  Q$ R  m
- F. I3 P0 U5 a% \  Z. yReal-time Blacklist Lookups(实时黑名单查询)$ I2 j6 n2 p5 r" Q( i
利用第三方IP名单。
+ X" U% L& X) z) y4 O. W' Z) B4 e! L& e2 `: q5 c

  C+ y: K7 c+ h6 ~  R  MHTTP Denial of Service Protections(HTTP的拒绝服务保护)
* Z  n+ N+ \; R防御HTTP的洪水攻击和HTTP Dos攻击。- V2 C- W- n! Z" s

! M2 j/ x8 ?8 U5 _. }' [* G$ n
* {1 r7 b3 J* E: r! X& \; c0 F! {Common Web Attacks Protection(常见的Web攻击防护)
2 X' T! E; Y' F+ e检测常见的Web应用程序的安全攻击。
* V$ V0 X1 e; {; J" f4 \6 F* ]2 z
. l. V" x1 @: T/ Q. O& R& ~( |
Automation Detection(自动化检测)
1 S; J6 ^( o- r- h; Q8 i& S- u/ u检测机器人,爬虫,扫描仪和其他表面恶意活动。
6 e4 [' u* K  i+ d1 P5 f! v
: U9 p4 X" V8 W/ Q/ {
* i# H8 c& G% T6 `Integration with AV Scanning for File Uploads(文件上传防病毒扫描): R& [2 `8 H$ H# r
检测通过Web应用程序上传的恶意文件。5 I* s& [0 F% S) V. g
8 E& h* x( f4 X! G

+ O# W; E/ O0 iTracking Sensitive Data(跟踪敏感数据)
; H9 j' [" ]- ]" g- x信用卡通道的使用,并阻止泄漏。
& G$ U. x2 Q0 L0 V* E* U2 o9 ]; ?: S6 x- {) [
5 A1 c9 n: Q# M. e1 B8 g+ N
Trojan Protection(木马防护)  y3 ~5 q% M+ E
检测访问木马。
1 g4 K( w* {6 h- f) H9 ]/ }, W6 C" ?9 P" b3 e8 b! x# y

6 [! j2 W# v0 I) i1 f% ]2 y7 `- zIdentification of Application Defects(应用程序缺陷的鉴定)9 o/ L) e! Y" U3 r
检测应用程序的错误配置警报。9 M. H( X- C% E, h  w+ H: F
7 G% g5 ]; I! ]

; ]2 q. R4 x; ?/ e( Y9 `Error Detection and Hiding(错误检测和隐藏)
5 F2 H) x/ y  ?检测伪装服务器发送错误消息。
3 \5 G4 ~  N9 N1 I4 T  B2 A1 T& V. `! U$ D+ Y5 C, K3 {

8 G/ E2 X& V2 Q6 c2 u安装ModSecurity2 I) @0 {# ^8 p$ W
软件基础环境准备1 X1 @8 O* @! f6 e
下载对应软件包: f+ X: g4 @" H
$ cd /root
/ \5 `0 ?6 v# N$ wget 'http://nginx.org/download/nginx-1.9.2.tar.gz'
- {% `' S1 _2 c7 i  Y7 F$ wget -O modsecurity-2.9.1.tar.gz https://github.com/SpiderLabs/ModSecurity/releases/download/v2.9.1/modsecurity-2.9.1.tar.gz
7 p( Z% `7 f0 x7 r6 P( `. F安装Nginx和ModSecurity依赖包6 e- I4 X  @$ A9 {( g+ ]1 a
Centos/RHEL7 u2 T3 v" c" w9 |& T" o8 [, Q
, J4 [1 ^0 h& A/ K+ U# \
6 |% M! c: z0 h" ^
$ yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel zlib zlib-devel openssl openssl-devel6 i; p1 d  X. q" t: B
Ubuntu/Debian
- {' t0 n- d, P$ D' I" ~6 L. I9 i* C& w: ]# r3 f4 t& |: p( ]

% r  G, v* p( [# \0 D$ apt-get install libreadline-dev libncurses5-dev libssl-dev perl make build-essential git  libpcre3 libpcre3-dev libtool autoconf apache2-dev libxml2 libxml2-dev libcurl4-openssl-dev g++ flex bison curl doxygen libyajl-dev libgeoip-dev dh-autoreconf libpcre++-dev
& [! V+ u+ u" j+ o编译安装ModSecurity
% u2 J: n7 M) JNginx加载ModSecurity模块有两种方式:一种是编译为Nginx静态模块,一种是通过ModSecurity-Nginx Connector加载动态模块。- s3 Y% ]5 D$ z" x
( C  z6 F2 ]8 I

9 H/ P0 y/ L* _6 a8 _方法一:编译为Nginx静态模块0 U  I' P! A( Q5 k8 ~6 S5 H8 \& N
$ E1 \! {) U$ `' |
0 i% v# b; A2 r+ _$ y5 U. }
编译为独立模块(modsecurity-2.9.1)! V. N5 \$ n* J  |+ `' ~" h
$ tar xzvf modsecurity-2.9.1.tar.gz
& j7 |. w9 g! E5 _0 e$ cd modsecurity-2.9.1/$ |: b1 G6 J7 r: C1 U( ]
$ ./autogen.sh& M, X& Q- {# u$ Y7 s
$ ./configure --enable-standalone-module --disable-mlogc
  U& V2 F; A$ T; e$ make
; d8 y9 Y$ q6 `3 @- Y编译安装Nginx并添加ModSecurity模块
% w/ p, Q. I3 \7 }3 f2 }$ tar xzvf nginx-1.9.2.tar.gz0 U7 y# o& D  A; E( E
$ cd nginx-1.9.2+ l; f* ^  m, B# f6 f3 ^- e
$ ./configure --add-module=/root/modsecurity-2.9.1/nginx/modsecurity/
% g0 _7 k' d8 ?$ make && make install
5 e* y! w, D, q方法二:编译通过ModSecurity-Nginx Connector加载的动态模块
- ^8 C3 H- S6 H3 E0 M* ^! c% P% s$ s$ _0 k

9 f( c" ?0 T: X. E3 t! E编译LibModSecurity(modsecurity-3.0)
2 `3 @6 Q. ^9 O! r% D' o: @$ cd /root
- ]( e3 ^# }) {/ C. c6 u2 h$ git clone https://github.com/SpiderLabs/ModSecurity0 b5 N$ e: }& l7 a2 s" ]
$ cd ModSecurity& t( n8 y: k4 z1 ?; b( S
$ git checkout -b v3/master origin/v3/master7 V( N% i" P9 f  H) j4 O  c
$ sh build.sh
; I/ Z0 |6 B" e$ \3 E& U  a% w" r: S) ^$ git submodule init- P: u. x. q2 Y& Z
$ git submodule update
8 d) n) V7 }; u# d$ ./configure
( E. E/ U& s2 v0 E$ l; ~, h$ make1 w. x2 e' p. ^" y5 q: _! H' ]
$ make install
7 G& b& X5 y) _: R# RLibModSecurity会安装在 /usr/local/modsecurity/lib 目录下。( d# t1 P( w0 s3 N& z" a8 l+ N+ n
0 J) T, }2 s- ~  l

% m' T& `( O' X! Y6 C- g2 u$ ls /usr/local/modsecurity/lib- T) Z8 D# ]/ t+ P  V* x
libmodsecurity.a  libmodsecurity.la  libmodsecurity.so  libmodsecurity.so.3  libmodsecurity.so.3.0.0
7 u$ H# O  W/ [; L2 j编译安装Nginx并添加ModSecurity-Nginx Connector模块
9 X& t, q( w! I% ?使用ModSecurity-Nginx模块来连接LibModSecurity
$ U5 y' H' a3 K% v- d" d! f6 _! t" b. P+ H( R

# `0 G/ F6 U6 |; {* g+ h" u* u$ cd /root
* p2 s2 {! i) u$ I( T$ K! I! b$ git clone https://github.com/SpiderLabs/ModSecurity-nginx.git modsecurity-nginx7 C& E: E* c4 V  B& b2 p/ V
$ tar xzvf nginx-1.9.2.tar.gz
  M) l$ i9 f4 g1 p9 D2 I$ cd nginx-1.9.2& \6 @9 c0 @7 O1 A% `
$ ./configure --add-module=/root/modsecurity-nginx
( }# y2 X3 X# c7 Z9 [$ make
/ q+ t4 f7 g, ^- i  u7 F1 [" M% N$ make && make install
: F0 Q2 E8 f, s* L/ r添加OWASP规则
! c( x; a7 w, L$ sModSecurity倾向于过滤和阻止Web危险,之所以强大就在于规则。OWASP提供的规则是社区志愿者维护的被称为核心规则CRS,规则可靠强大,当然也可以自定义规则来满足各种需求。# I$ s6 T0 k, }: G9 G+ _- K- O
' ?$ w- K. D. y' s6 m2 v# G
. Z0 P( @" b4 _; V, X
下载OWASP规则并生成配置文件
3 d- D" O; @* O% W6 _* r$ git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git, f% y! J% }3 C' m
$ cp -rf owasp-modsecurity-crs  /usr/local/nginx/conf/
" A8 x# f+ N) ~  z1 o5 K* l$ cd /usr/local/nginx/conf/owasp-modsecurity-crs: k; f5 Q( M$ R. R$ e( k4 C1 ]
$ cp crs-setup.conf.example  crs-setup.conf7 z- g0 I; R% Q  y
配置OWASP规则" D$ f& Q" b" A
编辑crs-setup.conf文件
+ m  Y7 I) S" D" W) Y
7 Y1 R% g. |5 E# g) {, h: b: ^' r7 f  m
$ sed -ie 's/SecDefaultAction "phase:1,log,auditlog,pass"/#SecDefaultAction "phase:1,log,auditlog,pass"/g' crs-setup.conf
$ T! x3 m2 W$ B  k; g  Z$ _+ c: ]- X$ sed -ie 's/SecDefaultAction "phase:2,log,auditlog,pass"/#SecDefaultAction "phase:2,log,auditlog,pass"/g' crs-setup.conf- a4 J& X) b0 K& E. Y% h
$ sed -ie 's/#.*SecDefaultAction "phase:1,log,auditlog,deny,status:403"/SecDefaultAction "phase:1,log,auditlog,deny,status:403"/g' crs-setup.conf+ g5 S, Y& B8 E# `- z
$ sed -ie 's/# SecDefaultAction "phase:2,log,auditlog,deny,status:403"/SecDefaultAction "phase:2,log,auditlog,deny,status:403"/g' crs-setup.conf, [' c4 P5 G( i# v7 s. H+ U
默认ModSecurity不会阻挡恶意连接,只会记录在Log里。修改SecDefaultAction选项,默认开启阻挡。8 _; S' w7 J0 A; j' ^( K
/ v( E3 A0 L! p; A  t

; ?1 b7 {8 B' Y- b$ c' s+ _启用ModSecurity模块和CRS规则9 ^+ q! s. `" v8 v9 D, Z0 G+ t
复制ModSecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到Nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
9 {3 h/ X0 u2 h  `# N5 I# J7 D( D
: q8 N, r" D/ S& Z/ e4 M) T, u4 c
# V; P; q: r. D6 q9 T" dmodsecurity.conf-recommended是ModSecurity工作的主配置文件。默认情况下,它带有.recommended扩展名。要初始化ModSecurity,我们就要重命名此文件。6 T) F$ T  R% b5 L/ ]3 D/ |
- D) k$ t- e) W  [7 x+ ^

' T! U5 e# [; y9 Y  m1 ^8 u$ cd /root/modsecurity-2.9.1/
- T% J" e0 y$ _- n% Y' R9 X/ W6 T' x' d$ cp modsecurity.conf-recommended /usr/local/nginx/conf/modsecurity.conf  % ?7 [& @  ?6 C; H$ W% @2 [1 c
$ cp unicode.mapping  /usr/local/nginx/conf/
( b- C8 J9 l: M3 p: A: a. h将SecRuleEngine设置为On,默认值为DetectOnly即为观察模式,建议大家在安装时先默认使用这个模式,规则测试完成后在设置为On,避免出现对网站、服务器某些不可知的影响。
: _& e8 o" l. w' m5 l. f$ ?& x" g; }
! y: }+ H; d8 F
+ c1 N/ I5 W- L2 V, |. x; D$ S$ vim /usr/local/nginx/conf/modsecurity.conf
* V& o- L) |4 MSecRuleEngine On
- `8 q' g4 @0 s& uModSecurity中几个常用配置说明:
+ R$ T6 `' D% D0 Y6 v; C( U9 f. \  k) ?8 O* t" C# E9 m
' l. L- w$ h1 @- N3 _
1.SecRuleEngine:是否接受来自ModSecurity-CRS目录下的所有规则的安全规则引擎。因此,我们可以根据需求设置不同的规则。要设置不同的规则有以下几种。SecRuleEngine On:将在服务器上激活ModSecurity防火墙,它会检测并阻止该服务器上的任何恶意攻击。SecRuleEngine Detection Only:如果设置这个规则它只会检测到所有的攻击,并根据攻击产生错误,但它不会在服务器上阻止任何东西。SecRuleEngine Off:这将在服务器上上停用ModSecurity的防火墙。/ _' Q$ e/ Z: [3 [

  w5 B3 ]4 V" c. q0 E
) f" r5 s3 c* }9 W2.SecRequestBodyAccess:它会告诉ModSecurity是否会检查请求,它起着非常重要的作用。它只有两个参数ON或OFF。
7 c* K$ ]1 h0 s  `* B% i  V1 x2 N) \3 ^% y& L+ t' G. ~% V
9 p3 u' o. T$ d1 p3 Y2 k" J( n
3.SecResponseBodyAccess:如果此参数设置为ON,然后ModeSecurity可以分析服务器响应,并做适当处理。它也有只有两个参数ON和Off,我们可以根据求要进行设置。* [7 Z% l2 k/ X% a: b. ~# X1 Y
! h- w5 r$ n" D. J6 ~* n. I
- J; t& F7 L; W) ?7 c- c& K
4.SecDataDir:定义ModSecurity的工作目录,该目录将作为ModSecurity的临时目录使用。
& c7 F+ U2 N" [3 }6 h+ d* \: {8 j) x4 w! E

" x- r, r, p6 W- P; \) R0 @( @在 owasp-modsecurity-crs/rules 下有很多定义好的规则,将需要启用的规则用Include指令添加进来就可以了。
! e8 d( l; v, X/ W) p0 Q& a: y; r6 D) s6 B" e. p
4 ^6 P2 T/ E& N! x$ f4 y" v' v
3.x版本CRS
1 X" K2 M& H  R$ cd /usr/local/nginx/conf/owasp-modsecurity-crs
. K: h, X# Y! R7 t& M7 |$ n# 生成例外排除请求的配置文件
/ [2 I, k) z' Y# l1 }$ cp rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf' s4 @4 z6 j; y5 J* M$ E! e
$ cp rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf
# v8 N0 i2 ]+ R3 x2 V$ cp rules/*.data /usr/local/nginx/conf. C  P6 b4 N  F$ T5 y
为了保持modsecurity.conf简洁,这里新建一个modsec_includes.conf文件,内容为需要启用的规则。
& K, e6 |+ a0 r/ m/ Y% _% i
: m! V+ y9 c. a* n9 A( ^
* ]8 N7 e8 [; j3 P  L  Q# |; a$ vim /usr/local/nginx/conf/modsec_includes.conf
/ A2 @* _( U% ]' k# v- O* P0 t3 S+ w" Q: M6 v2 Q$ @8 E* ~
[Bash shell] 纯文本查看 复制代码
include modsecurity.conf
include owasp-modsecurity-crs/crs-setup.conf
include owasp-modsecurity-crs/rules/REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf
include owasp-modsecurity-crs/rules/REQUEST-901-INITIALIZATION.conf
Include owasp-modsecurity-crs/rules/REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
include owasp-modsecurity-crs/rules/REQUEST-905-COMMON-EXCEPTIONS.conf
include owasp-modsecurity-crs/rules/REQUEST-910-IP-REPUTATION.conf
include owasp-modsecurity-crs/rules/REQUEST-911-METHOD-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-912-DOS-PROTECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-913-SCANNER-DETECTION.conf
include owasp-modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf
include owasp-modsecurity-crs/rules/REQUEST-921-PROTOCOL-ATTACK.conf
include owasp-modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf
include owasp-modsecurity-crs/rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf
include owasp-modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf
include owasp-modsecurity-crs/rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf
include owasp-modsecurity-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf
include owasp-modsecurity-crs/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf
include owasp-modsecurity-crs/rules/REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
include owasp-modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-950-DATA-LEAKAGES.conf
include owasp-modsecurity-crs/rules/RESPONSE-951-DATA-LEAKAGES-SQL.conf
include owasp-modsecurity-crs/rules/RESPONSE-952-DATA-LEAKAGES-JAVA.conf
include owasp-modsecurity-crs/rules/RESPONSE-953-DATA-LEAKAGES-PHP.conf
include owasp-modsecurity-crs/rules/RESPONSE-954-DATA-LEAKAGES-IIS.conf
include owasp-modsecurity-crs/rules/RESPONSE-959-BLOCKING-EVALUATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-980-CORRELATION.conf
include owasp-modsecurity-crs/rules/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf

, y3 s& z6 {% V0 q. K' c) I8 q0 G6 N- Y
注:考虑到可能对主机性能上的损耗,可以根据实际需求加入对应的漏洞的防护规则即可。
' r; o) p2 \% j) Z& H" ^6 V* a" }# x$ }4 w" W# Y9 l
$ f5 z! K& b" B( d9 ^& A: _5 N3 s
配置Nginx支持Modsecurity( e, P' @/ F, I! @* \9 L
启用Modsecurity8 S. I& h. S) B
使用静态模块加载的配置方法1 r" m# L; P7 W9 g* |6 S3 Y
在需要启用Modsecurity的主机的location下面加入下面两行即可:3 L) B8 G  d) S# K- {- k

: S- j% F) }% m9 }( a' |8 S: k+ y! p0 Q3 P* u" `2 S% N
ModSecurityEnabled on;/ K0 d8 D8 B- E8 |
ModSecurityConfig modsec_includes.conf;
9 G, G4 y8 }9 e! s& P7 r修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。; E) e9 s+ ~  J9 m4 `

# C- C. N# C4 `& e+ F* m5 @( r3 ], P' ~
$ vim /usr/local/nginx/conf/nginx.conf
* g$ {. x1 u- l. q  s! ^7 h! ?9 M$ G

6 ^4 S# V% r5 ]" T. w5 \2 u4 Pserver {
* }5 i' X7 E; |2 ^5 a  listen       80;
+ V; {+ r8 c: D7 M3 @  server_name  example.com;7 Q7 ]0 K& ]% D, }
2 G8 B1 b% N, b" B- U

6 H: m' F, G2 q! P" L/ w  p7 u! c  location / {# ]0 J# {6 s+ O4 }
    ModSecurityEnabled on;
$ R7 H+ }8 E2 A, W    ModSecurityConfig modsec_includes.conf;
3 B1 k0 R# Y! M/ o8 [' F. v    root   html;8 j/ b9 D. ?2 t! ]8 q5 ?. H+ l
    index  index.html index.htm;2 }/ \# {. G. Q( M: u
  }) r/ X" z: g" e
}
7 W5 v! R. i% r% o! h. K7 V* {" J使用动态模块加载的配置方法' U: |  ?5 o" v4 U
在需要启用Modsecurity的主机的location下面加入下面两行即可:9 A/ `9 Q" m6 L4 o4 e' a) c; m
/ a% _$ t3 p' h1 J6 X8 u5 Y

- n9 V" q: V5 }3 H# S5 }1 f* _modsecurity on;
& {, o  h3 I. E4 o! p* {$ }modsecurity_rules_file modsec_includes.conf;) `( \1 _# m, J# V/ M# j3 h. a
修改Nginx配置文件,在需要启用Modsecurity的location开启Modsecurity。
7 j, ^9 M, f  h  j2 [
7 @# ^; A% n5 X) A
& b6 n6 O* c1 @2 N# a$ vim /usr/local/nginx/conf/nginx.conf
. @* z7 l& v/ a; ^  W& |$ z8 S" M) q4 J. s

; D9 q; u5 ~6 [! D; Kserver {5 i4 J# u) `) r+ ~; W5 O4 Y3 x' j
  listen  80;# s4 a1 @* a8 N5 n: [6 W5 R0 ~
  server_name localhost mike.hi-linux.com;0 e1 h" j6 p5 f4 p3 [
  access_log /var/log/nginx/yourdomain.log;
; N2 r  S/ |( C6 L; N
- m: W# n! m* a- d  `) B3 r+ x# K1 A+ b3 s0 L# t$ a0 |
  location / {; n5 z: v6 Z9 f& E& F
  T, [. R5 a1 o% T

, p- i4 p- U2 D' x  modsecurity on;/ T! w  M0 n1 `2 ]. s/ w% Y  S
  modsecurity_rules_file modsec_includes.conf;
  ]4 ~0 T$ J) g4 g+ ]  p4 T1 c- S  root   html;# Z  ~8 |1 J3 l
  index  index.html index.htm;
2 k) I1 k! @2 W8 @}2 Z* I& l$ g) q: W, ]
}1 H7 q9 T3 Q, e0 o" ^4 d1 `( y
验证Nginx配置文件8 [# J5 I7 x* r, g
$ /usr/local/nginx/sbin/nginx -t
1 X, c% z- L/ dnginx: the configuration file /usr/local/nginx/conf/nginx.conf syntax is ok% F; u+ ~' ^& f, s! `' P
nginx: configuration file /usr/local/nginx/conf/nginx.conf test is successful
( h' J7 {0 u) K( [. B% \8 ~启动Nginx
. l% f7 x8 c8 P9 p3 j$ /usr/local/nginx/sbin/nginx -c /usr/local/nginx/conf/nginx.conf
9 Z. y& ]; x1 O0 D+ `. P5 d
/ H! E2 L, }" H/ P0 m

测试Modsecurity

ModSecurity现在已经成功配置了OWASP的规则。现在我们将测试对一些最常见的Web应用攻击。来测试ModSecurity是否挡住了攻击。这里我们启用了XSS和SQL注入的过滤规则,下面的例子中不正常的请求会直接返回403。

在浏览器中访问默认首页,会看到Nginx默认的欢迎页:

[/url]

这时我们在网址后面自己加上正常参数,例如: 。同样会看到Nginx默认的欢迎页:

[url=http://img.colabug.com/2017/06/842f48f203c6c2cd30144f29b57af97a.png]

接下来,我们在前面正常参数的基础上再加上  ,整个请求变成:

[/url]

就会看到Nginx返回403 Forbidden的信息了,说明Modsecurity成功拦截了此请求。再来看一个的例子,同样会被Modsecurity拦截。

[url=http://img.colabug.com/2017/06/246ce28e95310a32f791893d4f5c55ca.png]

查看Modsecurity日志

[url=http://img.colabug.com/2017/06/ae44dcb58b8a4a0ea761317e398b3101.png][/url]

所有命中规则的外部攻击均会存在modsec_audit.log,用户可以对这个文件中记录进行审计。Log文件位置在modsecurity.conf中SecAuditLog选项配置,Linux默认在 /var/log/modsec_audit.log 。

$ cat /usr/local/nginx/conf/modsecurity.confSecAuditLog /var/log/modsec_audit.log

Modsecurity主要是规则验证(验证已知漏洞),Nginx下还有另一个功能强大的WAF模块Naxsi。Naxsi最大特点是可以设置学习模式,抓取您的网站产生必要的白名单,以避免误报!Naxsi不依赖于预先定义的签名,Naxsi能够战胜更多复杂/未知/混淆的攻击模式。

. g: P8 C% w+ v* j

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-3 11:21 , Processed in 0.078251 second(s), 22 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表