|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。2 U% j& x( o9 u1 t
3 \+ X# }# ~/ I8 H+ I2 [6 e: h* |3 z) M一.准备工作( U$ O# g6 B7 S! a) i( k( m2 E
3 |9 V8 W# g" x2 h h* l系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
+ T. m6 {8 I( f4 J2 v/ b4 H4 Y( i2 F, O# V- V
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz9 D7 p3 Q) R% C1 w \* t
) x/ {7 u& `" S9 omodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz) D) L: k* C' c! J3 u
; m3 V, q ?- G' g
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs7 }% J' M1 ^& S" t
3 o+ h: X$ y# C
依赖关系:$ U% Z6 U0 V. H7 |& m6 V# } R# w
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:% L% J# T2 D$ t7 a* ^
' V' N) f5 |- ^yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
. `3 d9 Z. A' ]% Fmodsecurty依赖的包:pcre httpd-devel libxml2 apr$ W; G; h/ `7 t8 [: n4 N8 b
: f5 E; F* e2 \4 i+ }6 u+ F
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
- X0 u( `, P9 Y* S* w二.启用standalone模块并编译- [& G/ t( D |0 O* M
) Y" Q& Y* |- _* a2 @% N下载modsecurity for nginx 解压,进入解压后目录执行:
' I" v' t0 ~# I7 f) x$ {- U! t y. G# v
./autogen.sh4 q; x7 w. {5 z m g; M, [
./configure --enable-standalone-module --disable-mlogc1 g% Q) `5 S3 D. }/ p
make
; g, B- @! M+ n7 w' a/ q三.nginx添加modsecurity模块* z& }5 r/ X+ g& T1 f' S$ y
6 r# U; z' V3 G) t& y在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:+ S$ L3 h% ?1 K5 w. h; L8 F
1 v3 W+ l) Q9 ^3 d! E, }* e! F
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine/ Z/ D* @7 p/ U' P4 l& z' n
make && make install
' H5 [( ^3 j1 X d四.添加规则
6 a m/ O: d+ Z& B1 ?1 _; U9 Y$ U7 x) s( I" i) Y
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。, G4 Z$ P2 m1 _% L
# d7 l4 l O$ ^# f! X* ~/ W1.下载OWASP规则:* B' T0 e4 y0 m+ T
% J5 z+ {: F4 w3 U. ^& U' u! Egit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
, U+ t- a! k8 }& q/ P5 d0 R' I2 F4 r5 O7 _# X( P7 ^! z+ K
mv owasp-modsecurity-crs /opt/tengine/conf/
& P: V2 h( d" G/ A6 I
) N- w' s2 e0 B7 s# Bcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf3 A. f! m- }) j8 e7 x
2.启用OWASP规则:
0 y/ k3 f* t. c; p) V4 P& c2 z3 x! I3 m) Y
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。9 D% B H& [& f+ f9 P" c, P: D3 X& _
* x! w2 L7 w L6 {, s3 i" a' L编辑modsecurity.conf 文件,将SecRuleEngine设置为 on* @6 p6 v0 T+ l* a- U5 h4 N
; }( d8 W: U! \owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
1 \& J$ Q! R$ q/ w! Q& E. ?
! O9 D! i: N8 c$ J" W: @) dInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
& f# x/ r& o" ?& `, ZInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
# H, Z- L; y4 t! V" P& y. f) r8 H' mInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
, L8 j. }; a: \) Y0 h2 zInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf, N# E' d! A$ K1 p. \/ R
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
0 M6 R* E, _5 g+ yInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf3 x0 B) `: O. \ {
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf- H$ K% P+ X% x) g/ u5 _
五.配置nginx
# {, _+ m9 l- H' S5 l$ Q
) K1 @0 G) ~: v9 u# t- U3 [在需要启用modsecurity的主机的location下面加入下面两行即可:4 ^# n: g8 z9 R4 A% m3 _
5 N6 u2 ^! p7 m5 eModSecurityEnabled on;
* p* {' J2 A- C tModSecurityConfig modsecurity.conf;$ Y* x3 \; N7 u
下面是两个示例配置,php虚拟主机:* P' N; P8 B& P* F" Q
9 V* p- `4 S8 ~, M0 [& g8 _* r
server {
6 q# R4 e# v) `) A8 p4 c listen 80;
7 O, P5 W4 l2 J# N2 O3 U1 w) t4 | server_name 52os.net www.52os.net;
: e: H H) n7 }, P1 { n+ A' N
$ R7 u+ V( b8 D0 R location ~ \.php$ {; B. p8 @. I- @+ b
ModSecurityEnabled on; 9 w9 h! X8 s/ Z {/ O { t
ModSecurityConfig modsecurity.conf;' h, A! S+ @7 M9 ^9 e/ O
& `% [- N; U2 B0 U/ Y. i
root /web/wordpress;# K* Y; k# x, v( B0 P A- I* S8 m( n
index index.php index.html index.htm;$ y3 i# q8 E8 t, Y5 [+ E, `
. M9 ]* B' n, T( l fastcgi_pass 127.0.0.1:9000;
' o1 Z5 L, _) Q$ ~* g0 a fastcgi_index index.php;7 X3 g0 t8 ]. p- c
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;7 p; U3 l) V% u7 P1 h* J
include fastcgi_params;, U5 X k5 \: ^0 B* N
} H. D" y$ N$ _% Z
}
5 k0 h9 F; {& Z7 T9 Hupstream负载均衡:7 d2 y; ]; S/ w* F
# ^0 `9 w- F$ S. G4 l$ z- P& qupstream 52os.net {
/ C8 U8 ^1 N0 a5 s2 s% c server 192.168.1.100:8080;6 x6 W U# f1 F- X9 R
server 192.168.1.101:8080 backup;
5 j I3 j3 G( j: J7 l}
. H! K. a5 f- |
6 k8 p! o$ O$ ^9 e2 j; Kserver {
I9 y. F6 L4 e9 [listen 80;3 T) Y. ^ _: @% a3 B$ b* s. o3 S7 M
server_name 52os.net www.52os.net;( j+ t' V1 {( u
/ `7 d- G6 u! y0 G4 [( ~ X
location / {2 ~. i: }" H( V6 |5 M, J
ModSecurityEnabled on; , {) z/ ^% H4 o1 m2 P
ModSecurityConfig modsecurity.conf;
6 S- G- _) e/ u' K6 m- G4 A
6 `2 z3 V/ R3 A6 m proxy_pass http://online;
2 x6 D% `+ @: U* ~% ] proxy_redirect off;. g% [+ c2 k7 v1 \! S
proxy_set_header Host $host;4 }( W: \3 i0 x4 t
proxy_set_header X-Real-IP $remote_addr;
( H; u4 B1 S4 w6 G t6 { proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;$ c- s$ K+ ^# ]6 W7 S8 `! F
}. H) n# S6 }, w4 a5 I+ K+ B
}6 C; W J: |0 d' b& j+ m
六.测试
, E3 L6 S4 c! c6 I& R5 P& l- c+ @: n1 `. f- o3 d9 I0 s2 \, m& k
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:6 y: O' G) {* V0 m
. n% x# J! U7 @4 @7 U2 r
<?php
+ ^8 A/ y( W+ U phpinfo();
# Z9 @# _. |5 I/ }+ q?>, V; o. s3 ]6 f6 Y. u: D0 Y# Z/ B Q
在浏览器中访问:( G. l8 v7 k1 S ^$ u" c
% }, N( M! ?2 w4 Rhttp://www.52os.net/phpinfo.php?id=1 正常显示。
6 G$ M+ b5 Y) [" \- T9 ghttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
2 q& g" c/ l3 J7 _http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
8 B* @( B) Q( d3 H- U5 e说明sql注入和xss已经被过滤了
) s! H0 y) Z" T* Q7 Q1 R: b$ F9 k7 Q5 _+ _3 H& Y% G) N) ]
七、安装过程中排错5 I( u' j' {6 C3 H$ J* K
" C+ b8 _* F7 k* a+ m1.缺少APXS会报错0 E- q: Z0 l k* h0 f7 m
) N7 f& y" ^# Z& ?! h
configure: looking for Apache module support via DSO through APXS+ Y/ G8 f, h$ h2 T S
configure: error: couldn't find APXS
* @0 s$ ~" z4 m$ dapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
3 E& ^1 [) E) m8 }4 \2 z解决方法:
4 q$ J0 `* ~' {2 x: U) a; [7 Y+ R3 I
3 P+ m9 y& \* K( h) _2 Ayum install httpd-devel
; X& t& o8 ?6 B% L1 G& s* i! Q( g% W2.没有pcre! F6 ~. A* o; D2 Y
5 x6 Q) I3 Z2 C9 t& `) r3 }' t! i
configure: *** pcre library not found.
" { _$ k3 r1 `8 G7 M+ econfigure: error: pcre library is required
/ {" a- ?5 J S8 k& z" z解决方法:; ?( Y/ |: |$ _7 O
/ z' q4 U) \6 k. C
yum install pcre pcre-devel3 `8 ], c$ l/ k9 F3 Z/ k( q
3.没有libxml21 ^$ d3 S# | I# _8 {
* x; ~' L1 _7 o) \
: v) O3 z5 T5 \5 t G. [' |( i- z1 fconfigure: *** xml library not found.7 E0 q" A! a+ {3 V- z- G
configure: error: libxml2 is required' `# {" n* Q- q; F P5 u
解决方法:
3 z8 |* z. Q6 b1 t
# e! S( Q" y2 N" G% ?yum install libxml2 libxml2-devel5 k, }) h4 u! w+ l/ O0 R4 ]
4.执行 /opt/tengine/sbin/nginx -m 时有警告
1 Z" X( [' v: M
& y; c( R& F# W' J: ^8 j DTengine version: Tengine/2.1.0 (nginx/1.6.2)
/ C# V6 ^6 }+ p8 H) {* enginx: [warn] ModSecurity: Loaded APR do not match with compiled!: a0 I$ ?& ]1 O" u Q; L
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log R @1 I& i0 }/ Z4 q! f% e4 @
- H( C/ W* C* Y7 J+ |2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
2 w) j3 y# z' R2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"% V8 \5 L8 E3 ^. X
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!7 k# L) q, y/ _) N+ a) m: l
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
" E; ~* p& g5 B9 L* I: {2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
" }: K: R8 i/ T0 g# S1 v" m5 H% x2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.+ O* k1 ?+ o. y$ z
解决方法,移除低版本的APR (1.3.9)
( h; F% o8 I& J6 i$ n
6 z" E1 D9 U2 V( qyum remove apr _% m4 q5 I' D2 O- `
5.Error.log中有: Audit log: Failed to lock global mutex2 J; d/ ^4 L6 m/ y
' H8 {5 j; U; H' q
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock - m# x2 z& I" k5 M8 }
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
$ C6 l( d. {3 A解决方法:. Y+ u1 }; g" r) p6 l: L M# N! o+ P
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
( g+ T. t( S8 u0 q0 ], _" o# k; |, ]' K Y0 z$ e& \
SecAuditLogDirMode 0777
/ E. A4 Y" L- c7 m" hSecAuditLogFileMode 0550
/ k9 f2 T7 F, xSecAuditLogStorageDir /var/log/modsecurity
# p4 f" C* ]) j) L; h7 USecAuditLogType Concurrent4 i$ m: `7 x/ A U2 N
参考文章:
# @0 z/ z- X3 I' i* Fhttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
" u! a# K# m2 X2 @$ E: C6 ~1 l+ l& q9 ohttp://drops.wooyun.org/tips/2614 |
|