找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12771|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。5 M6 K" i. Z4 Y+ M  F0 h

- c# u8 v6 s! k, B: p一.准备工作
* \. d8 v: s! T1 [+ C5 c% y6 ]* J2 m1 {3 M/ O* H1 T
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0- g% J7 C. T  E, M; s9 L& m

: h5 A7 h! `6 p" U$ X$ [# I8 @9 {4 xtengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
: G: T: o+ f8 q) U* n$ s1 r9 L, J: o0 i( {5 P3 K- Q
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz" H: F8 d4 B3 p" Y' s
  [8 L/ W) @) i. B
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
3 ~4 U  b' j9 J( u5 t
! Q4 [5 K4 F/ i/ n  K依赖关系:
( |$ t6 r' g9 c2 R/ qtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:( G0 v2 h1 ^+ ?* M/ M1 J. ^. ?
: k- D8 ?" A4 i9 n
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel/ f: m; L1 i: g1 q
modsecurty依赖的包:pcre httpd-devel libxml2 apr/ S1 s& R9 ]  E4 A% }: f+ }
+ w2 |# D5 j+ F: w4 j! Y- w9 C
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
( n# j, ~% _1 \) e0 ?二.启用standalone模块并编译
) P8 F$ Q$ r( y1 s6 X( |: O/ k. r7 b: `2 R8 l
下载modsecurity for nginx 解压,进入解压后目录执行:" {  u  V; B, ], n' d
. Y5 ], e( p- V9 \7 E
./autogen.sh( ~4 p  x) \8 E2 l' O5 t  ]: o
./configure --enable-standalone-module --disable-mlogc
8 @; O1 N3 `5 P: `' Qmake
% C/ w+ q0 I4 r% C0 F( U% S3 z) h9 v三.nginx添加modsecurity模块; K3 m0 l: s$ w: Z

& a, \% R  X1 k) r0 d% U在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
0 V/ x/ ?2 d: v+ g( p5 g$ f1 S! c" h! I* W2 J: Q' y0 s; }
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine# Z# Z3 t1 k. C) O
make && make install+ x' q- d' G3 Z5 |9 t
四.添加规则
+ ?6 C- \8 X, ~! h6 n( y4 |6 {( F' m/ [3 ~: t9 X
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。+ X5 E7 i  M: q
# T- q& A  r, A: d6 ?- Q$ ?
1.下载OWASP规则:0 u# X8 z2 W- p' Y5 W! z* r( W" T. g9 T

+ J3 g* c/ K  r- dgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs; t  V, O( \/ J! N- |  r" Y
! S0 g  A" b) p4 d, a% n3 g
mv owasp-modsecurity-crs /opt/tengine/conf/
  @, p4 t* J4 M. c/ g) _7 V: Z/ b+ C0 u: K; l! u
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
! h  T. l6 U+ F: z' X3 O7 w2 n2.启用OWASP规则:
: w- P" l2 N( i$ r
- x, G# A+ q! Y# T: ^9 z- \7 K复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
! W+ {4 t- r. A! r& D
- B3 i: @( M+ T/ d编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
6 a% I3 k" c( d- V% m4 {/ u( B2 `# r( {
+ K: |4 r4 j5 ]0 L$ Z9 U6 fowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。/ \( |3 ~" S0 T8 e8 M
# x! K- W3 Y+ }/ }* _$ O' V7 I
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
9 J* ~+ H5 Q- J/ ]5 E6 MInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
6 z  G" N8 K' }# R) g0 D  Q; }) @Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
' G* z1 G0 c. _# D% ~" [, nInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf/ M0 i+ l9 z! r$ l' U  E$ T( N
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf6 l" a+ q! c$ e* S/ ^- T" J9 y
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf4 y1 v, @2 [( @0 a. _1 c! e  x) v6 V
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
, m0 z" d9 p! a1 a五.配置nginx
3 L% d3 K4 ?$ f- t
& _3 |( I) w& `# N1 @在需要启用modsecurity的主机的location下面加入下面两行即可:
, o3 _; C% n+ s7 ^5 S2 M- S* k# ?( l
ModSecurityEnabled on;  ' ~+ ~& }# X8 S0 V2 ~, z
ModSecurityConfig modsecurity.conf;& X; I8 K( g; F4 r
下面是两个示例配置,php虚拟主机:* `1 ^( D' f. i$ E+ ~
1 G9 b+ F7 v9 n3 C" n" K
server {
" ~4 j- y! ^9 x      listen      80;
5 V, P5 r( n& ]. Z! s      server_name 52os.net www.52os.net;
( y  c6 O! `0 D; D     
  z5 M* O) K( i1 `' a3 ~3 w      location ~ \.php$ {3 P/ c! Z; i3 f8 ~( g) ~+ U  B: k3 Z. O
      ModSecurityEnabled on;  
% U7 Y5 w  W7 R4 w      ModSecurityConfig modsecurity.conf;
2 t) u9 m5 Q3 R* ~7 o- S5 G" l- [+ f4 B  `6 p: v# `1 v! M2 N
      root /web/wordpress;- ^. x$ x; ?! M. h, |( q
      index index.php index.html index.htm;6 v- }: i7 E: ~1 V, V6 L
  & j0 `. G8 i) ?
      fastcgi_pass   127.0.0.1:9000;
6 b' ~* g; E0 S2 K4 a% w      fastcgi_index  index.php;* I! z: H+ j" U* G
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
5 h/ m! D9 r; |$ m! K2 p3 X7 U8 B; @# \( q      include        fastcgi_params;
% C  V6 |- T$ {, o! I( y9 S+ r      }' `7 ^" n/ i0 ~3 v; e
  }
3 v. U, G  K% p& U7 [upstream负载均衡:$ _- z  J) O' ?: i

* G$ ?6 P9 O# ]$ [( E6 ~upstream 52os.net {$ S% e& p& ]% F' X7 o, s' z' |
    server 192.168.1.100:8080;( D# ~) X( l  k0 d
    server 192.168.1.101:8080 backup;9 L1 I, H0 ^6 h9 K; B1 C1 N
}2 |& V5 p) j' U* T, H' N
5 _3 G/ l/ z# A
server {
1 m# p5 C3 G0 [+ X" |9 B) Olisten 80;
) l' h, V: U" ]/ x% Qserver_name 52os.net www.52os.net;* M. r4 [9 i5 l& m* {& |$ E
0 I! B) Z- X* x1 }6 [
location / {9 _/ {0 i% o% Q1 D4 h6 |
    ModSecurityEnabled on;  
; x4 g: m' M" ]9 P# R    ModSecurityConfig modsecurity.conf;  - k3 E9 N% x5 N$ z5 K8 L

% T3 V( E1 h' r        proxy_pass http://online;
1 F! H' t0 ~6 }' f- Z1 F        proxy_redirect         off;
* w: h8 N/ v" A$ l3 |: S5 G/ }3 r* o        proxy_set_header Host $host;% [+ J9 k4 u% F" G
        proxy_set_header X-Real-IP $remote_addr;
3 W5 C3 \5 W& P, {- S! s; a" C        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;1 N# ]2 a" s. L; H7 ^
    }
, x3 k6 }2 J2 r}
8 T* \- w1 y9 l/ ]3 h' [* `六.测试2 Z9 r! _' e' {1 a. t' D

' Z8 @" @3 p+ Y7 X- n+ B: B" I我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
7 H3 Z3 {3 v9 g) G* s' \& M
1 [7 O2 o. Z" r( B- F( ?. p<?php- |8 ?9 S: Z! W6 B# l2 U/ }
    phpinfo();    0 T& N% |0 J! y  J2 w
?>
4 r4 M2 @# {# c9 g5 |, s& }在浏览器中访问:
, x* s0 f, y, Y1 \7 }4 x$ c9 F. h+ g0 y+ ?. ^% F* ^& j: E
http://www.52os.net/phpinfo.php?id=1 正常显示。
  E3 T1 X5 [: `0 E1 n- }http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。) A: S1 @, \. D' j% R
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。; \. ?0 N+ h+ \& l( |: G2 K
说明sql注入和xss已经被过滤了
9 Q- O& W8 l$ i/ O
( ^0 Z9 h0 Z% L8 J& `) T6 F6 {1 C七、安装过程中排错$ U7 F8 d( ]- P( r2 t% G
3 @$ W/ c; g. m8 ?& h- W+ H4 t
1.缺少APXS会报错
7 P1 C" @" c9 z, w; p- _& O; Q1 L
0 H$ a" {( t) h& d& U3 a, T- A' zconfigure: looking for Apache module support via DSO through APXS' F. {0 V0 j" p' U& [2 s$ q2 @
configure: error: couldn't find APXS
$ n$ Z1 W# T0 x# Z1 L" o3 ^apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
  N6 @( w& p: h' u" ]" \/ x, N解决方法:* A1 N. M' h& A/ n* Q

% f4 q' A% S* Q- H6 Iyum install httpd-devel& v$ ]% ?) \# L0 ~1 ^- z
2.没有pcre
7 w( ~; a5 Q& T- Y  d& d
. f! t$ s, v2 \5 Y) r+ D7 C, econfigure: *** pcre library not found.% _6 Y0 ~0 L* V; V) V
configure: error: pcre library is required" A  q6 t! i/ u* W$ S+ B& G. |* V
解决方法:* A! \" e& {9 T# h  @

  r/ E- P! M' p4 H  tyum install pcre pcre-devel
( Q, {4 f+ [8 }/ e8 @: N3.没有libxml2+ Y! `; `  T9 d7 _% |) _2 x' r4 w

$ T9 N2 K& n  e2 b- [
% _$ v+ B% w9 X! y# @configure: *** xml library not found.* A7 ?: |: s) u" W
configure: error: libxml2 is required8 D/ t& j' b+ J4 e# d# P
解决方法:2 e0 O2 G+ |2 F! L

! W4 t: b) P. E, o# }8 qyum install  libxml2 libxml2-devel
# a( c, c) W% y4 i/ v4.执行 /opt/tengine/sbin/nginx -m 时有警告
% S. ~7 S- k0 @1 o2 u
: W( B6 R5 r2 {- z4 `9 p% HTengine version: Tengine/2.1.0 (nginx/1.6.2). E: F3 D  J5 e: a
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
. |* k, f1 v4 t& V9 @/ K2 I原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
6 F7 ^, j+ M3 ^8 K( |+ L
7 B/ h9 S3 v  C0 q  u0 _: |2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
# m& u+ Z+ {, [, U2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
: b9 Z3 ~; U+ |2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
, `: O7 `2 Y- B& B* J2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"  ?8 t4 n2 F" \, V
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
& x. y6 W" U, x2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.$ l) E9 @9 p, K3 e
解决方法,移除低版本的APR (1.3.9)
" Y+ b$ l5 [7 A$ B+ A9 A. [7 X
7 A2 q$ V6 L$ @9 ^8 v$ ayum remove apr# ?- e8 |' ^* N" c" n
5.Error.log中有: Audit log: Failed to lock global mutex" |( p7 o- Q8 U& B. ~5 o9 E

; ^6 K1 e8 ]3 c* N2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
3 B- H" Q) o$ Q3 X3 _global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
! R/ ?0 n7 M" @  U1 _' m解决方法:* _) d8 N, Y6 q
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
4 r+ r. v. {9 k' t/ e# X; ?# \4 q* k+ c5 j
SecAuditLogDirMode 0777
$ A. }1 s0 N- x" M! k1 SSecAuditLogFileMode 0550
& z' h8 `) Y7 ]1 q- BSecAuditLogStorageDir /var/log/modsecurity
4 \# m3 X5 S$ d0 Y3 ^, n, }# |SecAuditLogType Concurrent# [( N" p# f2 \2 p
参考文章:- g5 p. F% _3 P0 @! |8 R
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX3 k0 l8 A) ~& u, Q( g0 q
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-10 08:35 , Processed in 0.065996 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表