|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
6 s0 j% u0 [4 ~& _' T/ S! |) c
' @( y" r5 P! N1 k. I s; v一.准备工作* R9 x; R, _, m1 C4 h& g4 F) T/ W
- B+ w5 S; D# U
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
* S! s6 S" }6 }9 O$ E
m& V( D. @( g% L5 n& K4 mtengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz, x$ S$ z; s5 V1 p* U5 d' Z
- ]# J8 u5 ^& u7 v: Omodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
; ]- M" _2 b* c9 }6 O3 z' C, R% N1 r- t G# |3 c
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
, T' _! o9 Q: [3 W. y0 W
8 A" v4 B) L; Q依赖关系:+ s2 D- L4 h& s; Z O
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:* K' _4 z2 y2 u
' s# }4 t; D3 y4 Y2 v: S2 g& c& fyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
: @% @, r. [" \/ |modsecurty依赖的包:pcre httpd-devel libxml2 apr. o" k8 r: ^# L2 p3 y% K W3 d
d2 x V [3 ?7 w6 I7 h8 [" Oyum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
& J( p# U8 l& F% t9 T- h3 T二.启用standalone模块并编译
+ j9 b/ j: J3 e: q# H6 T7 l( l, |( v& x; z9 X G: y
下载modsecurity for nginx 解压,进入解压后目录执行:
7 `0 w! t( Z& z4 T0 x C4 {5 I7 {" a% a8 v; r9 p; D
./autogen.sh
! K5 n7 B: U+ f3 |: J) F+ w./configure --enable-standalone-module --disable-mlogc
4 g; m# K! Y1 I& X* Hmake
4 T) b+ k" ?4 v" X7 i三.nginx添加modsecurity模块$ E, E/ r- B) G+ U, _& U1 U
5 f1 Z% e% |4 Y9 T4 `5 n1 j
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:- ^" _ s( g/ [- W. N% A& C% K
/ N/ Q) h* J T+ }+ j. W4 i, t, ~./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine9 c ?8 E4 N* h2 j- A, o' K9 Q
make && make install
1 t* M( U& {3 p1 y% H四.添加规则% Q9 W' M4 n% A8 v+ E/ q' W1 I+ Z
1 j; ~0 b5 l+ z- Z/ B& cmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。( ?5 K9 @0 Q+ p( H" _( G7 p
7 u J/ V! w3 E: m9 `% A! c$ } p' e
1.下载OWASP规则:
' D" Q# x1 ~ {3 j
. Y+ j; H7 C; E) egit clone https://github.com/SpiderLabs/owasp-modsecurity-crs6 e6 P; Q) C: x2 p6 m$ c
& ~ _9 ^0 d* n( L, pmv owasp-modsecurity-crs /opt/tengine/conf/
, q( `7 c* O2 O4 N0 I
' V+ V$ b2 ?9 n8 _5 [cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
! d; c* a2 _9 A( Z! P# M2.启用OWASP规则:$ _" @0 `* U" M. `2 r
* {# S4 m# ?; u$ S复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。: C8 F: L: {7 O4 Q$ u5 x
) Y' d! S/ b$ p, ?9 k0 z1 |' Q编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
5 ]: k5 m- V2 n: E7 v, P6 o" P/ ?$ O$ @! |- w6 n
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。( U3 _( P5 [5 ^- \1 T
! O+ }% F) }4 i& P% ?
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
7 G# X* [ k5 m* U/ ^1 m( ZInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf$ _( N7 e X& U: a- k
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf! f8 S: {, X6 M$ f. N5 Y
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
. v. y) F' _; x( i! W0 c& FInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
8 X+ m, K1 X& E- R8 f: RInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf8 f: ~& }, q, P
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf4 e6 n. o6 G( D" r+ z4 @8 k$ w
五.配置nginx
( Z' o2 A$ Q* n3 u9 N
! f. w, p, M, t+ L, r在需要启用modsecurity的主机的location下面加入下面两行即可:
/ O" z+ f/ |+ u Q4 U7 W3 v4 p H' I$ M
ModSecurityEnabled on; X( `$ e1 i6 I% Z7 x$ j/ t8 F
ModSecurityConfig modsecurity.conf;
r. d( _3 S) F0 x# I, [3 U下面是两个示例配置,php虚拟主机:
# H+ F4 D- L. `- O3 g- r% h4 C& |
/ n8 g/ Z/ M3 E; Aserver {! r' G h/ K9 T7 I1 U$ ^
listen 80;" v- c7 q5 i$ k4 ^" C2 r; k
server_name 52os.net www.52os.net;# v$ T2 P" u$ ~: s
3 C4 g- `+ h' A
location ~ \.php$ {7 D0 r- u; L: k2 v: {
ModSecurityEnabled on; , t" [; D8 P8 L
ModSecurityConfig modsecurity.conf;
( m+ m1 ]; v/ w
9 t7 N" a- S7 j: J. R root /web/wordpress;6 T5 x, }* o3 H+ P
index index.php index.html index.htm;
; y8 p1 z8 Y m/ w
7 B' c/ ?+ h( R9 z! R fastcgi_pass 127.0.0.1:9000; y1 G1 N6 ^, n5 l6 t
fastcgi_index index.php;7 J% f2 H" C. O. s' s6 Y
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
9 {, N4 u& P( ~- j3 I. e+ {# o include fastcgi_params;+ W3 L: [6 N2 A$ V
}
6 Q( n$ i/ u* y: m0 V) I. m0 s. f }9 o4 u! o) U4 x/ N0 Y
upstream负载均衡:
7 ~9 Q# Y: p7 F2 i9 \! }
. K5 k) Z; n# k4 N: f& Bupstream 52os.net {/ E% S' }+ l) M9 {1 S
server 192.168.1.100:8080;: i! o' y( M1 U5 k8 }" d: V$ R
server 192.168.1.101:8080 backup;) a* C8 }7 `( S* N) s, P8 g
}! w# K; V1 o0 u" v
( U8 w" N; W5 O2 t p: U
server {
& k/ T) k2 ^- S* ? ~0 Plisten 80;9 ?0 t* D7 S; `3 o9 ^$ i
server_name 52os.net www.52os.net;
" n) u2 \9 P; r# I2 `9 k! K7 l$ s2 j: Y
location / {
2 }4 U7 E# R2 e1 w7 G ModSecurityEnabled on;
. Q. S- K. o$ |8 n2 m ModSecurityConfig modsecurity.conf; * A4 k, |$ }7 k z. Q9 j. F
1 l9 t$ C: d1 |+ o2 ^3 D
proxy_pass http://online;
) f r: H& k4 M, s0 x# |& N proxy_redirect off;+ z5 `0 d% b6 I. v" o
proxy_set_header Host $host;# j5 X& G" K4 q# o& i
proxy_set_header X-Real-IP $remote_addr;" ]* M: C$ I9 Q" X7 M
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;. _( U$ t; p& B2 ~1 M) Z
}" ~, W% b8 H) y, W2 G2 L8 _
}
% Q+ N# O. ^0 ~# y$ V六.测试3 m' s- J# r* m6 @9 s7 y& F) v. v
* B( \4 h0 h- |% w L
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
! x- W' z7 B; H h4 `
& z$ ?" Y% ?% ]9 ?6 `7 l5 q# W<?php& W! P! d( s% t$ {( s5 o5 c
phpinfo(); + y5 g) c+ {9 k* _. T
?>: u9 t! Z. @; X/ Q2 E
在浏览器中访问:
- l/ e- |9 I a8 E0 a8 P3 l) `7 `- q5 f; `1 Q- Q* s! y
http://www.52os.net/phpinfo.php?id=1 正常显示。
: k. o5 r8 p! j2 M( V1 ihttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。3 R2 E3 ?. T( u: _8 A2 q* ]. j# r
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
: l) x6 }! l4 C5 Z! T说明sql注入和xss已经被过滤了
1 i8 P9 W% B2 G& p7 c, s# q, y5 d/ Z% b E" z' ]
七、安装过程中排错
2 w9 a5 V8 M `2 U1 w' y/ n9 |3 ?3 V# a1 i" E
1.缺少APXS会报错
$ [9 T/ o$ U1 ?* D" I/ ?
+ i( f" K- x Uconfigure: looking for Apache module support via DSO through APXS
" r M& U5 C: N6 Vconfigure: error: couldn't find APXS/ i- \' ^3 F. p
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。' R* ^2 Y) e2 ?- a @6 @1 V8 A7 z: \
解决方法:
, S+ }, _3 ~) |7 x
& \! a& ]) n2 O+ fyum install httpd-devel8 b" p+ f2 B$ u" P$ S' |
2.没有pcre" P: a8 [- ?9 W$ k @1 ~9 _
* H: x6 j# d6 G3 e, J
configure: *** pcre library not found.
7 \/ F8 u7 M# f8 yconfigure: error: pcre library is required6 p2 Y+ v d D; C4 [( G" j
解决方法:9 k1 R* {% U5 p6 s: ?: P
5 X2 t2 k# ]8 i+ Y& n! \$ c9 hyum install pcre pcre-devel/ [7 Y2 H2 m1 b: ?
3.没有libxml2
8 z. u" ]- ]2 e4 |3 p$ u( f- {9 F$ f$ I: J+ V* m
6 b3 |# z1 L6 q$ P4 K7 Tconfigure: *** xml library not found.
7 f& R8 g% \1 [* B( pconfigure: error: libxml2 is required
3 i9 I( V5 ]) ]* w; K0 {7 G( Z解决方法:1 O: R* j0 T- Z4 z+ d
# O. H1 [( ?- ]# u$ J
yum install libxml2 libxml2-devel8 a" G8 X; z2 G$ w
4.执行 /opt/tengine/sbin/nginx -m 时有警告/ f. [0 E$ u8 c" v% g, m
8 s2 R) I$ V W+ K3 o( R
Tengine version: Tengine/2.1.0 (nginx/1.6.2)" O1 E% b$ J$ v$ V9 _
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
3 ~+ z3 d4 ~# P3 q$ {$ m4 q原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log* \/ O" Y4 G' s, j1 o
) e1 }: j% G5 e! z D2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
: W6 _- }) t- B+ K# \: V2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"# u) q; @1 t# @' F# h
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
2 W' p6 C2 }- M) V, X2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"7 n* I* v7 g0 H& E$ c
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
6 K8 E, x4 Z4 u2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
J2 w( _, \& ?5 r, f5 p3 Z解决方法,移除低版本的APR (1.3.9)3 f |, l/ z8 m7 l
7 L5 B" f: \. e: hyum remove apr% o: @4 m) R* A, [' H# }
5.Error.log中有: Audit log: Failed to lock global mutex
/ j0 B! m% D/ y5 Y6 w( l
( q+ Z( w/ _8 ]. _2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock " u' O; _" J k& }7 [; v* }, p) U
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
+ ^4 K8 K# ]# w! s6 d+ z解决方法:
5 ^7 x, a9 a3 W编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:! e( s" e, H- K, U- M
6 J- |5 {" V+ Y4 ?SecAuditLogDirMode 0777
9 }. M0 x2 C0 m6 @ aSecAuditLogFileMode 0550% m* q1 \' v- g/ X# ?6 f, y
SecAuditLogStorageDir /var/log/modsecurity
- x5 \, A7 N% FSecAuditLogType Concurrent+ w' [# e( @# L& b' h1 c; u
参考文章:3 r7 E/ E Z) \* L z9 l: k
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX( K) b( H9 v1 Y
http://drops.wooyun.org/tips/2614 |
|