找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12777|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
* h+ P- p7 Z0 W/ I+ l2 L2 S  A$ M: S  C# E& d* k
一.准备工作6 I( z6 d, f+ x

) X  W. H! ]9 O" p6 {" \1 P系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.07 R5 j  c1 c1 d
+ m$ s0 N3 O6 J" A  _1 z
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
( A# R- g- q6 ?: e
% k* x# e6 f4 l: V2 {modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz& M, l% o# r: O7 c# }

* Y$ E8 l, f- s) `OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs# f/ O: C8 @+ b8 D

- c. u" c, T; Q. Q; o" w! Q( y依赖关系:( [; V6 U2 t& K1 E& y: a' M
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:+ Q" _) J5 y# r3 b2 H( q3 L2 H
9 U9 j" ^% n2 v4 ~3 x2 U
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
6 k, d4 \# y, `5 J5 T" ~modsecurty依赖的包:pcre httpd-devel libxml2 apr& U& S  e, w* V, _

' |% y* P7 j6 ^5 j  qyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
) C5 ^* ?4 h9 C9 d二.启用standalone模块并编译% \6 a' f& p6 S4 |/ L

; |$ E( s' [; a下载modsecurity for nginx 解压,进入解压后目录执行:$ F! E, f3 o) C/ q- C( N

# C" y' F6 N7 s./autogen.sh
6 f* t$ e! j7 d4 Y! s2 d- }./configure --enable-standalone-module --disable-mlogc
) V0 f! g% ^- B+ ymake
, i! u/ l* \: t/ {三.nginx添加modsecurity模块) X0 z( A3 i, C+ d

2 S9 t1 `  A) I# b4 ^+ Q在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:" i  e8 H' [) D$ S- `- [

/ Y# s+ T) O6 n6 r. \/ R./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
+ T# U- e7 y. Smake && make install
4 z8 H, ]( S5 n四.添加规则
$ J/ L! ^( H: z; R: c
. z" L$ \5 J' K2 Hmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
6 \* I% n" e. t* K& B9 A' }% l( t' B' t" E3 z. O
1.下载OWASP规则:' D# f3 m0 U! o) Z0 D  B2 F

' H- {% J' o5 P5 Z  @8 U4 Mgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
, ^' {5 P/ Y; B6 v! M! K2 [6 k% m4 q  R. v8 D- W# |# M: q2 @
mv owasp-modsecurity-crs /opt/tengine/conf/
% w. G" s& D! h% t& _. @2 |: W8 ~. r9 G# d8 e/ D
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
; W" C- [8 g2 b8 A8 L6 I2.启用OWASP规则:
" w! C1 ^1 l% ?( C0 G( l; w4 ?/ b" y2 {- X
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
5 V. _% F  |: ~+ X' \) m( g
9 r. k8 w/ v, k' @1 U编辑modsecurity.conf 文件,将SecRuleEngine设置为 on$ C- m/ d1 l0 x8 w
& Y7 i9 e3 U1 G. q# A
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
7 D0 |7 Q* E% x5 R; z1 Y; F5 t% Z
3 i/ [7 j. @; V' cInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf& m9 q4 W/ h* {& o9 L0 t
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
) P, K0 X' [/ E' L7 }7 N. zInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf2 i5 o  S4 S8 O2 |- b
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf8 n, y) H+ {* L" u% V
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf/ t3 ?- Y) l9 m" A8 {! C
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
. ]  O( t, P0 J5 Y2 hInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
, \* ?' S: S, k* \$ z/ H五.配置nginx
+ Z' _' i2 D0 G: K, @
+ b7 k0 z+ w) ?在需要启用modsecurity的主机的location下面加入下面两行即可:2 |, J6 Y) E/ m, A+ b

8 F0 @; B! [/ k# \# p( ^ModSecurityEnabled on;  - f% G9 X# ~9 I, G1 y( I
ModSecurityConfig modsecurity.conf;
. r  f& o: g6 _& N/ |下面是两个示例配置,php虚拟主机:
$ L  {( c' F: A) u9 |9 ?3 u* ?) S
server {9 b, p6 o( q% n
      listen      80;
0 q; f+ U4 |! K: n+ U$ w( {, P* h      server_name 52os.net www.52os.net;0 F$ H8 W$ R5 [0 Y5 W8 l
     2 n9 e( y8 g$ r
      location ~ \.php$ {& {& X! c3 y, s+ R5 I7 T, N# l& D
      ModSecurityEnabled on;  
+ I) j1 U, R: [) m) _4 }7 n0 m' s/ s; x      ModSecurityConfig modsecurity.conf;
, q4 z! ?2 O' T6 M0 s* V4 H' f( b% W2 V9 f) X
      root /web/wordpress;
7 s( G2 H/ x6 i" Y5 b3 @$ n      index index.php index.html index.htm;
8 U8 w- s* z5 R- v; w  & m5 ~$ @1 Y" u
      fastcgi_pass   127.0.0.1:9000;( f7 Q2 H: M# N5 T" I, {
      fastcgi_index  index.php;
& m" t& s4 T0 W2 z# d      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
7 \6 o! @, X$ p" G' E9 m7 c- f- Z      include        fastcgi_params;
, O3 j2 `8 ~3 ~' y1 q* ^      }
2 a7 Q& N6 [( {* |7 T' S  }
2 M9 {* k( ^: q8 uupstream负载均衡:
* J; Z/ B7 G5 S. e' g, D
+ K$ R5 n5 \: \5 G& gupstream 52os.net {
* J) b: ?3 C" @    server 192.168.1.100:8080;4 j, t1 M0 d7 F3 L6 f" r
    server 192.168.1.101:8080 backup;
# R9 p2 R, K; K5 z* R" T. H+ Q}
/ `4 q" S  J+ Q6 Z. B8 ]8 f
) z* Y) X, x* H+ wserver {, v( a% P( f" I  G6 n5 h+ U6 P  K
listen 80;7 {5 [+ @- W" [
server_name 52os.net www.52os.net;. Z3 m1 O- @  d" I$ o- ^) P

4 J) ?/ G& ]) [2 o# W( Xlocation / {
) f8 A' |* l1 q: j; h    ModSecurityEnabled on;  
' R% t- y  B5 X7 Z. c$ G    ModSecurityConfig modsecurity.conf;  ' Z/ F$ b$ V# C

, k" Z) q8 G$ l" b# B2 q        proxy_pass http://online;2 Y4 `# }- H6 e2 s
        proxy_redirect         off;! x' k7 s1 M: U' c9 s
        proxy_set_header Host $host;
3 \$ F, _' H; j$ a        proxy_set_header X-Real-IP $remote_addr;
) B* c" d+ H) ^4 D- ?        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
" Y' l: g4 t- U2 g    }
$ i: E# Y; p6 C$ d8 I* A& L" \}
/ H6 ?* S1 |, ?/ T8 Y六.测试1 x8 J' s4 c7 }% G# |1 v- F! l% p/ B

% x. C! v. w% W6 S我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
9 Z4 y$ z2 M& S8 A) z8 M; l! E  I$ I! @  r3 ^) ^
<?php7 o/ g2 w( r4 L; {/ {( s6 Z
    phpinfo();    1 [# G6 _# z$ T2 H7 \
?>
2 V9 O1 Z8 ?* F4 R# y! i在浏览器中访问:1 j8 n% \7 s' a! g
0 ?- F- s7 G$ d
http://www.52os.net/phpinfo.php?id=1 正常显示。
* O5 O' p0 ~4 \0 S9 ^* Z& qhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
, w# Y- T6 x, i/ \/ Chttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。( K2 G) s* {2 N- |  W. j
说明sql注入和xss已经被过滤了
' R/ @( t5 l1 x
6 p9 q! {( w0 G6 K# h( o七、安装过程中排错6 V5 |- h6 L7 K8 _: T

" u, n# C3 f! M: e9 `6 m1.缺少APXS会报错
- t% m+ p! v7 D* I. ]- D3 Z5 Z2 V0 V
configure: looking for Apache module support via DSO through APXS
. C+ g! d4 ?# R1 b- M# cconfigure: error: couldn't find APXS
# j  o- c7 ]& [; u) M( |apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
; S# o. T' w0 o+ d解决方法:
( _5 v# m& m& V0 {- j. W9 L9 ~2 T- E7 i* C1 q
yum install httpd-devel
+ `' V5 i5 b& E4 _, i- r2.没有pcre# h: \" e. b% u5 R" z
7 A0 h" k; N* h3 e" b$ P
configure: *** pcre library not found.+ R; h6 p# b0 W; T
configure: error: pcre library is required
% e; t. e5 ^8 i1 j( S1 K解决方法:
8 M& T9 a5 X: Z. V; x- }- R* a
) w. W1 N# R* P# H( v' [3 ]yum install pcre pcre-devel  q- Y1 E6 C8 \1 F
3.没有libxml2. p1 z* |7 I: c- |& O$ j$ Y
9 S3 L  U: f3 Z- p, ]/ \

1 t0 _: e3 Z0 ~8 t, p9 z1 Qconfigure: *** xml library not found.
+ C: S: R, E) y8 I. @configure: error: libxml2 is required
6 b- R3 j" Z$ `解决方法:
8 |( S; a* N# V* E+ e2 _0 o+ D( y, `1 i4 v/ E0 C5 A
yum install  libxml2 libxml2-devel
0 ?2 D# U: }% p& X0 u4.执行 /opt/tengine/sbin/nginx -m 时有警告
1 c3 r, R5 Q: ^
, W# t, `. n( ?% [; _6 C/ q; R* Y8 gTengine version: Tengine/2.1.0 (nginx/1.6.2)/ o/ F" F, W* o6 \9 T. p: I
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!3 g% O" v- g$ C0 R9 M3 V
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
5 q1 C! U* Z4 {( x: L9 M- I: b4 w. v" K8 z9 J$ v8 Z( B
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured., c, f$ j! ~$ T# m. O4 {
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
; I, d5 r( X$ y6 g; ~/ e: k2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!3 e5 U: N0 D! V
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"! y* K  n4 c3 s, s0 s0 d& r; \3 ~8 r
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
6 U8 s( c% v5 o( L. c7 y5 \2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.$ w( y8 y  T$ }' E* r7 m
解决方法,移除低版本的APR (1.3.9)
; B. n, P, l  E& ]! J" f9 j& P6 f. |6 h! B: M
yum remove apr
( d- I# C' f9 Q2 w5.Error.log中有: Audit log: Failed to lock global mutex0 E4 M6 f% F) `* Y) m7 y' S

- o6 Q3 N0 U( Y* l2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
/ z$ E7 P2 J" E4 k! mglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
* P5 q2 N+ _5 _5 \& Q  X  r  @解决方法:
6 G$ z( D" p: N$ ^编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
  c. [4 W! l, e& s2 r- e+ y6 j! x0 q3 o: W0 M  ]8 J" e& n
SecAuditLogDirMode 0777! y# X9 k, l, C1 t; Z( ?
SecAuditLogFileMode 0550
+ X7 A2 H; m4 H( ~8 n4 O' j; E! @SecAuditLogStorageDir /var/log/modsecurity7 n. a# S7 F4 k( J% m
SecAuditLogType Concurrent; U. @; z* {% n. J& U
参考文章:9 S" L# w% o0 K; q) n0 N
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
1 Z2 H5 S2 ~# B( U; Q6 ?  V4 [http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-10 21:46 , Processed in 0.069142 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表