|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
3 P w, z5 I- W) G( h4 e
$ M' b* X8 C. [1 a一.准备工作
$ \% A Y. l8 |- |9 Q7 U( o6 [! ?% w& Z% N4 Z2 L0 s' m
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.05 i" z# \* e7 H3 C# ]% m/ j; n: }
! v* [/ Z( Q" R8 e1 \" S3 K( e) ]tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz/ K+ r/ n* H3 V
& S$ A+ Z1 U" [) Vmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
7 y# G1 c# u; N( l4 W
" s: y9 B8 M }+ @OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
: S6 Z# F; b# n I. B- M
+ L* o6 n R: T; @依赖关系:* G' s: j! }6 y4 v# V3 a0 u
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
6 Q5 I- x5 |; p1 |3 c9 l
& o c6 \$ S9 ^$ W% H$ H1 \' Qyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel# l; E: w I. v& S+ q
modsecurty依赖的包:pcre httpd-devel libxml2 apr b; Q3 {/ a! i' g
3 T; S0 \# y& s' E, O/ a$ E. Yyum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
1 a" ^1 x2 V# ~ h二.启用standalone模块并编译6 R w# s* O9 |8 B
7 _$ l' H" S$ b4 o
下载modsecurity for nginx 解压,进入解压后目录执行:
# O, s) _% Y( x" v* b! V/ g* S$ w+ \9 |8 ]
./autogen.sh- F5 m! l8 G0 d" B8 s
./configure --enable-standalone-module --disable-mlogc
3 R$ L) x u* u! d) o: rmake
7 e5 y3 f$ G8 f6 G& m4 z2 g2 a! A* W( m三.nginx添加modsecurity模块
" F3 o3 V( p- x( R2 L( B$ i- a
5 }3 f; H8 n6 J" r5 U在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
9 s9 B, M3 C- W3 O! @; ]
0 t2 ^( A$ Q0 x5 x./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
/ p5 F7 A% ^ d* Q; s! b5 C, l3 zmake && make install% @$ m0 Y; t' g2 \) r
四.添加规则1 u- c' |7 S) }9 x! M r4 @5 {
9 [6 Z; N3 N, k( B) O7 Imodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
) z* W1 P8 x9 e& R+ S8 ?
2 w; X- |) c% V/ N6 I1.下载OWASP规则:* m( [7 S4 A0 ]7 z
4 a$ e: [+ ?8 j5 M7 q( s0 R
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
1 w! B- n0 ~: n
2 M* l9 @+ T& x Imv owasp-modsecurity-crs /opt/tengine/conf/1 e+ b5 ~" N4 A0 e; ?& o' v
/ h+ N' g& c. _ s7 ]$ c) D! V
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
& s. a% ^# q9 G6 ]" s2.启用OWASP规则:
! l( @" V& L# S# C# g
2 t R- c% t/ J4 z复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
$ g/ {7 i# f- i) A4 N7 _
9 b# F) r- ^. H编辑modsecurity.conf 文件,将SecRuleEngine设置为 on- K% }+ f/ E" F N- d+ }
7 g. R0 \+ k" iowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
( m7 ^5 r" S0 j! F, _$ \& t
" [1 [: P( P! aInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
; J) ^& `" `4 R- r# bInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
/ w. ^ |; M# F9 [Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf9 S3 L8 k" \* M8 ~* N/ s
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
: B1 M' N1 l. L k0 n4 }Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
' i0 C: M ~" ~& P, W8 g4 E; GInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ c! Q( e8 C6 w9 o
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf% B: N0 X- T1 `6 \9 v0 y+ }
五.配置nginx, ]$ p3 Q: u" ]7 g9 }$ ?- _
5 s/ C. o- W4 S- S1 v$ r7 [. W% t7 @在需要启用modsecurity的主机的location下面加入下面两行即可:
% N8 N& J" e# q7 R, ~& r9 Q
# H5 C( v6 I' R$ \* w' M9 N7 QModSecurityEnabled on; * ^$ D5 n& i1 i# ~) c+ A& J
ModSecurityConfig modsecurity.conf;
4 S2 u$ t4 {( ?; Z- G" D* O下面是两个示例配置,php虚拟主机:' y! _4 ]1 t f( n- m' \5 K
! e, i. z5 q' M- s" W
server {2 V* P! x& l4 |6 s; v( T! \) \
listen 80;
1 h+ O$ P1 y% v+ z: Q1 O server_name 52os.net www.52os.net;
: n, }1 d T0 p$ _( E1 N- r
: q! U a# ]" L+ J' X8 p; ^* K, B location ~ \.php$ {
" M9 H8 `4 _, W0 r ModSecurityEnabled on; ) F+ T- E: ]* I! ]
ModSecurityConfig modsecurity.conf;% _* c6 {. p W; c& @: X
; F# X5 G/ L6 ~- \3 ~. S( M: K root /web/wordpress;4 }; w$ C- i% ]% v1 ~5 a
index index.php index.html index.htm;
+ u6 }- S3 O- h- M& j ! ?4 E8 V4 i R/ W2 Y! e% _
fastcgi_pass 127.0.0.1:9000;! G. N k* z* j* u
fastcgi_index index.php;
. X/ ]0 K7 p$ }5 M) P fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;8 O& V) D Q) R, A
include fastcgi_params;
* t# a- K7 H: H, i# u% E7 ~ }
5 N3 K9 K( y" y/ [4 x' f. j' V, a }
: \* j" E" F) j5 R* uupstream负载均衡:& d- q% u, P9 b( b- Y
& ^! G5 a6 _# I5 m# k" wupstream 52os.net {
: s* f) ~2 q0 E5 I server 192.168.1.100:8080;
( R3 B1 V1 n& L" o8 t9 R server 192.168.1.101:8080 backup;/ o, _0 X2 w5 y
}
. ~3 _" G+ C# u9 I5 v
( X- h2 r7 X; h5 W1 H0 bserver {
0 K- R8 o: f$ b+ W L, {! [7 x8 Plisten 80;
& W% u* ?, g1 \( a$ I& aserver_name 52os.net www.52os.net;) ~. u& Q \. h4 i/ q2 V8 n
( {1 E: p7 @4 d/ W/ k% Q$ j: M
location / {3 z' `6 i9 T. o+ b/ ?+ J
ModSecurityEnabled on;
: K( h) @# h- M" ?' D ModSecurityConfig modsecurity.conf;
A! i) h* j, a, A( \2 K! \; {) E% x- Z( Y( A# ~* \. S0 K7 H. X
proxy_pass http://online;& E+ N E/ |, T& e: `; f7 V6 y
proxy_redirect off;
" K3 ?8 a9 x7 r- U% l proxy_set_header Host $host;
: G4 |) j- `4 J/ D proxy_set_header X-Real-IP $remote_addr;. v2 p4 o' k% }0 U- ]
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
1 G) g4 ~! y- w0 M* c }
3 [5 i2 S5 j3 h8 Q7 t i" q9 l}
' C `' Z( k. Z' A* e$ k2 @' L六.测试, c' K3 g# x5 P: g- R
; M7 A- m1 F" v& ~6 F- p# E我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:* |& P; d' r! A" [4 q/ R4 W$ G
7 Q2 n7 Y; {# {: ^
<?php
/ h4 v8 l; c8 [% B phpinfo(); " Y0 e: U$ T9 Y) l2 r& A
?>5 a. \' r1 `5 g1 a/ q. N r
在浏览器中访问:
0 M `, f, w/ y4 f2 U# w6 c) M
) i: M& q: o) W9 U$ u0 ~# I+ Y) whttp://www.52os.net/phpinfo.php?id=1 正常显示。. o5 Q `$ }. }
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。; p9 _2 q) e( v1 g
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
. ~4 W& A) O6 p: m! L$ a/ F) {* Z说明sql注入和xss已经被过滤了2 P. _) q" X% ~. P% `8 j
4 f) R; Q# s5 M) e3 k
七、安装过程中排错
% g% t+ k5 k) a- d5 `0 ?9 R8 d. k3 R8 s9 i3 i* E% U4 Q
1.缺少APXS会报错/ R/ z, f/ r' ~
( W: k( K! ?1 j" O4 ^6 z: G# A, ^2 gconfigure: looking for Apache module support via DSO through APXS
& ~& ]- C' T8 @1 I+ ?9 S" }0 Nconfigure: error: couldn't find APXS
4 i8 [5 k2 Z/ ^8 ^2 W6 m- Rapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。. G$ i2 W6 t. r- ?3 ]; a0 x0 ~
解决方法:5 X7 | F) n4 g, p( O
! h+ Z9 n3 q+ b' ]" }! U9 Y+ b
yum install httpd-devel6 C7 N8 I& y$ H# v
2.没有pcre2 n/ H- B( O! ^* d# }5 i1 x; L' g8 n" }
+ I; Q6 q9 U; }configure: *** pcre library not found.
9 |7 W' Z; @% S4 {6 Fconfigure: error: pcre library is required1 l* O# P5 M0 Z$ r. W o; n, P- `
解决方法:/ ~8 B2 ]. n; |: @* l' S0 [
8 H& B# E- B% `4 L
yum install pcre pcre-devel
5 ^, x. J7 a# s" n7 x- E3.没有libxml24 U% _6 v' p7 e2 V
3 U* f, T8 v0 u" \& L+ e( l$ b" W' `
configure: *** xml library not found.: R: q0 D8 Y7 z2 g5 [8 O @
configure: error: libxml2 is required
) T, }, _% k8 g% E6 `% I解决方法:
( y7 o- M) t% }% N* c' e' b
, C# }( V5 w2 C, f$ kyum install libxml2 libxml2-devel
& K3 ~. z5 I* v4.执行 /opt/tengine/sbin/nginx -m 时有警告
( ~0 s$ b0 u3 \* M K% X; [6 r1 X" X4 s2 Y
Tengine version: Tengine/2.1.0 (nginx/1.6.2)/ q1 v" N G7 q/ c8 ]
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!7 U- Z# o+ m& Z2 s; b/ Y R+ I
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log9 L- G2 Z% @" s0 u: ^
( z4 O2 _% g: a7 j8 g u2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
, _: s. D4 [; l- J4 o4 ~2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"; ]# E. J: z; d) g }
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!" K2 T+ Q/ S% _3 T
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
6 A3 K, I. x, Q; x: E' U2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"% }+ Z3 d; t9 B( m$ \2 H- Z
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
5 |- v: K) y; l, i% B0 x( X解决方法,移除低版本的APR (1.3.9)
/ R3 P# D/ N1 e0 ?; Q+ B
u1 T! F! n9 P& P2 byum remove apr+ H/ e1 p( M1 m8 u" }$ q
5.Error.log中有: Audit log: Failed to lock global mutex: `% K3 c4 X& D- M
. ?9 F* Z* S: d+ y
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
3 L# e' ^0 ?3 d! Vglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]* Z% P" W3 G0 j( j% h1 U' A( v. _" C
解决方法:
* k Q! H* @7 l7 O- G编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
( }& w- T) b& C
4 v6 H" C8 w& {" f! F1 n1 RSecAuditLogDirMode 07770 b, t6 s1 L/ f @7 ]0 ]' N
SecAuditLogFileMode 0550& t6 D# k: D/ }* ?) L
SecAuditLogStorageDir /var/log/modsecurity2 b& O( t$ @9 O0 M8 D
SecAuditLogType Concurrent- N2 m0 E7 x% @) V
参考文章:
4 _9 C- {* U) t( k1 V& n# x+ shttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX, g2 ]4 R3 r1 g2 u% W+ k; s
http://drops.wooyun.org/tips/2614 |
|