找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12779|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。( L5 K. m4 P9 L- y8 R. G! z0 k
, r; P$ \- a* j5 B# G
一.准备工作
3 G+ y! w" B% C- t
, Q7 h; {: t3 z, @, n系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
4 I: L; f3 x5 j* ^3 b1 A1 W/ J/ h  C( o+ B$ I
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
9 E6 C' s& [9 n
8 K. q5 }4 z' C: w& umodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz4 x5 ?$ ^$ K" h+ K& m8 j% D' Y

/ l: W) x4 g* v$ _- yOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs6 @. ~, Y9 o8 Z9 o

* K( D0 O; ]0 p' D7 g: u依赖关系:2 L, ~# U- q+ _5 z, [
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:' Z$ Q/ R# L  R' u- j9 ?' L; p

; X: }; E  _  g4 Q0 Hyum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
7 I# J3 n( p9 c. F6 Wmodsecurty依赖的包:pcre httpd-devel libxml2 apr
: \) _$ |& L# t% E4 m! V0 v
5 [: ~) C8 {- V8 {7 Uyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
! ]6 m% c' K# ^1 z( i1 Z二.启用standalone模块并编译/ e% V+ D- j" i2 E3 @# \
3 f: A: ?7 T  z) Y2 B; e; w* J0 ^/ ^
下载modsecurity for nginx 解压,进入解压后目录执行:
  X  Y# q' V9 W  c3 b. T7 q
3 Q3 t4 Y$ d, _1 T; g( ?./autogen.sh1 {* x4 c$ D' S5 u* s% b6 j) O
./configure --enable-standalone-module --disable-mlogc
/ ?' u' |" H' q# q9 o5 q4 Hmake + v; k) ?- Z! a3 n! `! e- k
三.nginx添加modsecurity模块
5 P+ F' }/ u  c0 @( G$ V& b8 }. j1 W' U5 o* e
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
4 z7 Q2 }8 f/ `4 Y/ x% ?, ]; d/ i. j2 c6 A! }( V4 G
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
3 h8 \2 q8 U( P) hmake && make install1 b$ G. k/ `( Z; a
四.添加规则
* c  ~4 P8 _8 b
6 n: I" `' k) m0 C) j7 W& }& kmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。& F9 y/ b. e1 f! |; X
3 r4 r2 D; H- n1 o. k
1.下载OWASP规则:
% m4 G. Q! p9 d0 i5 @: M, m! H, r0 q5 ~( Y5 E
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs% Q7 L: o/ r8 Q  V( O. y) l
. s8 g2 F0 ^' g" u/ T' z
mv owasp-modsecurity-crs /opt/tengine/conf/
- ~6 Y' s  K! j7 O* }$ k
! [; b) S, q5 q( T/ T4 D" Vcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf; x" l# A. u) X' D( }; l
2.启用OWASP规则:
; t$ d6 l4 }% Z7 Z8 K2 a
8 Z3 O1 _* T9 k! w  B) i% q复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
# I/ j( O' ~( X7 v4 w5 t
5 ^0 y; `+ [" V0 D编辑modsecurity.conf 文件,将SecRuleEngine设置为 on7 e/ s5 X6 z- v( J$ G3 M; ~" K
5 w; B8 F) Q5 n; n$ t
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
/ ^3 M( e0 ]$ |
" X+ O& }; q) {+ ZInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf6 u' @/ Z8 R; |, D9 u4 e
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf( z9 `3 K, @+ h% R! B/ `+ ^. S
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
6 S! I6 G1 [: Y+ m. U% y+ m6 p* XInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
; @3 {$ U  B/ FInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
9 V0 T0 l" {* N$ K- ~Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf- q+ F1 [" w( J  C% e' _
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
1 X3 S) b; ~6 M" W! F- b6 q五.配置nginx
* F% T0 N1 ?8 W: b( J  `; ^' H
+ j* d6 L- i  ?8 c/ q: m在需要启用modsecurity的主机的location下面加入下面两行即可:% y$ g. S( r$ q* w' @- D
1 S$ ?9 F; R; e$ h. a1 r4 {
ModSecurityEnabled on;  
: k& `! v: b2 U& J  z$ Q8 OModSecurityConfig modsecurity.conf;
' \- }3 |, E6 U7 W: h+ d9 I下面是两个示例配置,php虚拟主机:
! m; ^" q0 \: l" c) C9 w2 O# W/ D3 h! \
server {. I. q  p# K7 m. L  y$ X
      listen      80;
, B' g8 ^  L$ J, `* O# T1 O5 P" o: ~      server_name 52os.net www.52os.net;# n6 W0 Z2 s# [& z. v& a' c& R
     4 W2 H; J2 S' {% u! d
      location ~ \.php$ {* k$ V, b% D# m. ~
      ModSecurityEnabled on;  3 o8 w- C2 b* a, E: @! L4 U
      ModSecurityConfig modsecurity.conf;. G+ [6 l9 @4 s) f* {/ v
2 Q" Z3 A( d/ n0 |
      root /web/wordpress;
! K! I/ g3 o6 ~7 p$ B      index index.php index.html index.htm;+ W# s7 |+ a5 Z- M" P  v
  
4 @  Z+ o/ I: g! q. P( K# q  h      fastcgi_pass   127.0.0.1:9000;
, m" X1 s' k' j! r      fastcgi_index  index.php;& j  d5 c# j  W1 Y+ ]
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
9 a6 {2 m3 V! j5 G# m) C0 f2 ^      include        fastcgi_params;
. h7 w5 H8 `8 l# V& j. q5 \      }
8 Q. U+ B: g+ k1 K( N  }& r- C6 E) [9 T5 t/ c6 O2 n9 t
upstream负载均衡:
2 q* i! Y( Z5 O; B9 U& n% W5 W8 z
upstream 52os.net {
. L4 ~4 [3 U: G" I( f8 z, T$ s4 E4 g    server 192.168.1.100:8080;
+ K( O1 T6 c( H! D: o/ X3 u5 B    server 192.168.1.101:8080 backup;
0 _6 \( n, k; Q0 G3 \+ u7 k/ T}. @8 c( M6 b+ \; b* v- @# L

. G' o- }- m" b" M  }  v. Yserver {, J" V5 ^# }4 j9 H7 K# u7 c& o" k
listen 80;/ T+ n9 y9 R; A/ E% R/ ~  ^
server_name 52os.net www.52os.net;
+ n( G3 |9 H! ^& t0 U5 C
- F$ P6 C6 |- `. p9 m$ r0 u1 hlocation / {& C8 Y: C7 J+ M/ n9 n* j6 `1 }
    ModSecurityEnabled on;  
5 i* \, b' k/ M& l    ModSecurityConfig modsecurity.conf;  0 O+ @: h+ i! o

0 _5 |: t7 D2 b$ W% R8 ]$ w        proxy_pass http://online;
  |. _) P/ E2 a: k) T5 g        proxy_redirect         off;
3 ]$ j& w/ Z( Y9 N; n1 a        proxy_set_header Host $host;
8 @1 o! n& T& V! I        proxy_set_header X-Real-IP $remote_addr;
6 z9 E2 ^9 }, q1 _( X# i        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
( l8 P/ n% R8 c- i  _9 Q    }
/ Q( U+ {6 c1 s3 F& D! J}( ~& O- X, v, A8 T9 w
六.测试
$ @: ^" U2 y' [. @4 M" k5 A4 X6 T* z5 x( a# f6 }
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:/ U! M4 O% X0 a8 P# i

8 y+ Y+ i: z1 k; j/ T. x<?php
/ ^! T7 v4 J) X2 J# Y$ \    phpinfo();   
9 i5 S0 Q) n; \?>
7 q+ H  O" k2 @1 _在浏览器中访问:
5 Y+ S2 j, p& j) q& w6 X9 }4 k7 [; r1 V; W
http://www.52os.net/phpinfo.php?id=1 正常显示。
5 R( q1 d: Q$ Y- \http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
5 B2 n" _! F) u# g: n0 Yhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。* q  Z9 T* J. P' @+ A0 `
说明sql注入和xss已经被过滤了
; B1 r% w3 B. q# C- k; ~+ o8 B( J
" H& ?8 Q/ {# C" x4 ~  X3 L( m, \% o七、安装过程中排错
. }6 d- h7 b! l0 I+ x
) e1 o% T6 k& y7 C9 Z1.缺少APXS会报错
2 o) z1 f) X6 E" M. {* ?. o5 u  x$ }. n. l3 C  K  u/ P& Q, s
configure: looking for Apache module support via DSO through APXS/ ]$ J. @/ X# y/ z8 K* V, l
configure: error: couldn't find APXS  b  O$ P  p8 h' P
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
+ W: M7 ^: s2 w7 @8 N* J解决方法:; u. F) Z' l, t! {. ]% J5 e
3 W7 \6 C) e$ U5 c
yum install httpd-devel: |$ a( S. F! o1 u* Y9 `( q3 P6 S
2.没有pcre/ f% w) [8 V& z" q7 O2 i9 _( y
9 ]9 P2 o& r$ _  z# S/ ?1 }7 ~$ T
configure: *** pcre library not found.# Z1 @4 v- [% N) m& z# w, f5 a
configure: error: pcre library is required( C6 I2 q+ V; q! z6 r1 E
解决方法:- d' R# [& c8 t$ Y# G% F

& @* I  c2 Z* ^( Hyum install pcre pcre-devel
/ \7 I! N# @( @, H; h$ D, j% ^  R: t3.没有libxml2, d. E, z6 Q7 o- G/ a/ ~( _  l9 y

1 k0 ?9 @& j+ C6 S: N8 A8 a2 j# N  f# j+ Y( N$ I6 Z
configure: *** xml library not found.
2 {, [2 ~3 F$ o$ K* cconfigure: error: libxml2 is required
( B* Y& o* {# l7 b9 U- y/ H解决方法:7 _' \: S9 h. o& H' u' ?& h  ^, s
& d' R' l/ b9 O8 ~  D, R
yum install  libxml2 libxml2-devel
5 G' ?% C7 w$ [4 ^/ O: j8 j4.执行 /opt/tengine/sbin/nginx -m 时有警告% y1 [. _0 `! N' t* ?
# ]  `7 x+ F# d' C+ l9 a/ Q* f" i
Tengine version: Tengine/2.1.0 (nginx/1.6.2)
3 i: L& b# |" E/ Y% Xnginx: [warn] ModSecurity: Loaded APR do not match with compiled!
1 [7 e9 }5 G9 x: Z- s原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log2 B! g/ T) l, E! C: E7 n

) o1 f2 d% _0 m2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
2 U1 e6 b; ]# j5 R2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
: D; F# D8 N/ Z8 W( L8 {8 l  Y1 c2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
# D. e: Y  N" s1 D0 c2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05". S6 ~1 F: w) r. i
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
+ I) U; ~. i2 o5 z2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
* Q( i6 l. c6 U解决方法,移除低版本的APR (1.3.9)! j9 c  l/ j7 |% s" H; {, k# y. h
( C9 z: N6 H1 K2 I! g! L  R; N/ X3 Y
yum remove apr6 E0 [/ a' B: k: Q
5.Error.log中有: Audit log: Failed to lock global mutex0 t& A% g0 u# ^5 R

$ U. @- I( W) ^% D6 u$ G2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock       s5 Y5 F8 r" j3 Z* X
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]* ?7 D) D$ s/ a& N. X8 [
解决方法:
  J5 @1 {& @- o* U# ]" W! P编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
  d  b) v5 y3 S, N) P+ f+ @4 c7 S0 I9 y. w
SecAuditLogDirMode 0777
) r$ n) \! u! Z; e9 I. l. \& K) TSecAuditLogFileMode 0550- ?- F! w, r: L! W+ ?3 _# Z* ^
SecAuditLogStorageDir /var/log/modsecurity
! C+ d6 t; M6 X2 o0 Q" LSecAuditLogType Concurrent! [* E4 y+ X, A/ j) `# j; F
参考文章:
3 U9 C& p* l  X8 v3 U& o6 shttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
: r# f" F( R2 J4 ^, Y) @; uhttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-11 05:08 , Processed in 0.070795 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表