找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12671|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。9 M5 p6 \/ ~& t
  q9 C! A) x4 X
一.准备工作
' S: i( n' T* n) ~* g, S, Z- e
7 j8 p- }5 U5 {+ m, l$ V, [$ O系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
2 `) n) X; i9 @3 l: O
0 P7 E" C8 a( d$ E8 Qtengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz# j/ o" t! q9 j$ n* ~) C# s- d* v
; U3 w2 r" w% i& x
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
' V7 n7 y+ U0 n! H% ?3 ~* V( b( ~* G" G. z+ C5 F# i
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs5 M& t4 N3 z. o0 P- `
/ U- Y; f  g3 {* v
依赖关系:- r& _- R! z, K. V- L9 A
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
8 E8 P2 M7 x7 F% G/ J2 s. w9 F  ?8 `
1 E7 W# Y3 ~& v0 b: myum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel/ K  d; w+ B# k: m7 x9 l3 P+ k
modsecurty依赖的包:pcre httpd-devel libxml2 apr0 p+ j7 y  i# m' ^
. M# X3 S# \& Q6 ^" k8 m
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
8 E2 f9 b6 D. w3 c$ O! I" }, A二.启用standalone模块并编译
: h% v2 G) Z; ~5 {- O  ~
* P/ S0 S" i' T6 N7 w4 ?- j下载modsecurity for nginx 解压,进入解压后目录执行:/ f$ D: v) [9 E! Z' h
$ n8 `2 Z9 k) {8 n9 z7 D$ n
./autogen.sh3 \0 `& ~& w+ t+ `% y- n, S0 l
./configure --enable-standalone-module --disable-mlogc  m( ?# n& {# w3 q) T; m. n
make 3 O" ^/ [# P) i& n& F
三.nginx添加modsecurity模块- ]  X" F8 [) G( a7 c- V: ?

. _+ y6 K+ w$ Q/ ]. B/ A, P$ u% ]& m在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
6 Q0 ?5 i  _) K# i& O( z$ |- @3 w: O; w+ u% R
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
% N6 `7 g5 {' t0 Lmake && make install
1 ]; U# G& U) B: j# T# a四.添加规则1 Q. T- z, B! H( r7 N6 P
, O. S) ]1 C) ^& y
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
2 h8 U, ?2 @0 w0 ~; W+ k6 d1 M" J" O+ w. z4 F% y5 j
1.下载OWASP规则:
9 N) a; k" C! Y, K9 e! M. [- @* i" k
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs4 A( W1 _4 E% w" h4 t* f" n

5 Q$ f/ T4 x( e# x  P) imv owasp-modsecurity-crs /opt/tengine/conf/
9 u1 k  `0 F7 B
1 A% r; i# L" F. C" ?! qcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
( C  O/ v0 c* y, l! X2.启用OWASP规则:2 r* X' P- j1 P& I/ S+ {
: ^; d! S" Y( R3 Z
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。- I# @5 {3 D6 Y8 Y8 Q" r- L

+ }3 I8 B# n/ \5 ~! V. L- Q编辑modsecurity.conf 文件,将SecRuleEngine设置为 on( [* x) n$ k, K" z
  R/ D8 b- {- u% v3 e/ `
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
) p  I% @; X- I- s2 f( l' x0 s) ?2 W. b9 s! d$ t$ W" F- `
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf; M: E, _- W4 {% `- ^
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
3 X! }) _7 N6 g, zInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
* S( {" x9 g; ZInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
/ W, c- X5 N2 `. _1 vInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf6 P+ H5 a8 J# b4 G) v/ w
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
  H! n1 O" A) E6 P5 M! v" N4 Y/ F3 WInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf% ^4 Y0 `3 t; ^+ z1 n  S3 ^
五.配置nginx* d' N* j9 [$ V% p, I, w. _

6 |  E: F" q0 ^在需要启用modsecurity的主机的location下面加入下面两行即可:# K! p( m" R) d+ t. L  |

4 U+ J; K' e7 Z7 U& _ModSecurityEnabled on;  
. ?- T9 A( F( g% s0 P) W0 z8 CModSecurityConfig modsecurity.conf;# y  T% y% Y# @
下面是两个示例配置,php虚拟主机:
; P; U2 E) _. w
3 ^4 J, \: n0 d- Z& |server {
7 @3 ^2 \8 Q4 v      listen      80;
2 X  W( p1 c3 P* }: O# x" Q6 G      server_name 52os.net www.52os.net;1 ]0 [1 }6 ~# \3 F7 \
     ' I$ ?! }& a  ^, ^2 v, p5 w' C
      location ~ \.php$ {
- L; b# q1 T) R  Y% u0 h/ Z3 w      ModSecurityEnabled on;  
, a% K& o" ?7 U5 K9 y8 o% H) o      ModSecurityConfig modsecurity.conf;  A3 @' Y: p) B/ G) q+ o
" a" I. a) W: f3 o1 E5 g2 Y6 V' H# I
      root /web/wordpress;
% `5 b+ g! |; [  x      index index.php index.html index.htm;; t* c* c# C$ q0 i
  1 C( ~! y) O! L4 A7 `4 i
      fastcgi_pass   127.0.0.1:9000;
7 u' G% r& B6 o/ @$ \) I& s      fastcgi_index  index.php;
, E2 ]5 x0 M/ P5 K7 l( B      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
" |" O. u0 T: d      include        fastcgi_params;5 g) g( s7 u2 g( a* D8 y; y% B! r
      }
8 V/ N. `* Z1 c0 Y0 j2 |  }
) n1 @5 H) m& P. _8 d1 L8 Vupstream负载均衡:! J$ E7 {+ {. ~, |
& K' |2 b( b0 `' O8 q3 Q. T
upstream 52os.net {
2 t, x2 F$ V! `7 f. {/ W    server 192.168.1.100:8080;$ e2 }0 [: x: S
    server 192.168.1.101:8080 backup;
% z2 e4 p- {& m5 z4 R}+ d% Q' Y7 ~8 F  `3 A

* z$ `# P2 P1 p% {) Iserver {
' O4 S! {) D, m+ elisten 80;9 }; F  U/ x. I) j1 d+ A" a9 N( U
server_name 52os.net www.52os.net;
% X0 U; k# D* @# t- ^
) e& x5 h" b# C& Zlocation / {0 R, v$ g; Z% {5 B6 w+ l( J8 d+ j
    ModSecurityEnabled on;  $ c; V+ Y0 f! R# P2 t+ D
    ModSecurityConfig modsecurity.conf;  
- l- Y0 M0 {/ L: v9 l
. a- w0 h! ]- \1 F+ \$ s; H        proxy_pass http://online;, g' P( m. |8 Y/ K) B
        proxy_redirect         off;
. _  Q8 K" p# y0 S- h! X/ L        proxy_set_header Host $host;; G- ]" x. x/ I
        proxy_set_header X-Real-IP $remote_addr;. _& ]+ \8 \5 s' a/ E' y7 J) d9 y
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
* ~- Q  @  Q6 m    }
# j* z' ?5 W! t; u0 Y# A}2 U3 a) X& m8 f2 n5 u  n- R
六.测试6 l7 J1 I& ~# r" c

, u, M% X6 q7 |4 F$ x4 `9 J我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:7 C5 X6 q" z- O' _

; \* u3 s- E2 b' z& O% o<?php
- }" I1 a8 J9 V, m# I: A    phpinfo();   
/ c# v- f$ A; C0 P4 G?>
) K+ f8 M/ G, D在浏览器中访问:7 B7 N" h( f3 h" E
- w9 A% P& p0 [2 y, V
http://www.52os.net/phpinfo.php?id=1 正常显示。
0 @! r5 {. G$ k' g/ Y. C+ Fhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
+ Y6 `8 K/ U/ d6 _. P9 K( Ghttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。" I! w9 v' i+ _( v
说明sql注入和xss已经被过滤了
' Y( v) {. c, J# h9 x* d( F) q. _
  q7 W& Z+ J9 F4 X七、安装过程中排错( `3 h: F% i4 W& Y" t* `
  G3 ]8 @- ?/ O# N* x
1.缺少APXS会报错; J9 U' f% }9 u/ _5 d
4 i7 z( [9 Z. w5 p
configure: looking for Apache module support via DSO through APXS
3 I1 b4 J! F: V( O  fconfigure: error: couldn't find APXS6 E4 N8 @. e; A2 l
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。  W7 ^) z: r7 _; ^6 T' ~* T
解决方法:' G; `: L; ]1 C; w

; k$ D6 o4 @+ r6 P6 M5 s3 zyum install httpd-devel2 P- Y, [- k3 U* v. y3 d5 k
2.没有pcre! F# Z6 u4 l' O  ?+ T+ T

& z4 n6 H7 ?9 F/ pconfigure: *** pcre library not found.
0 `6 y( N& T+ q  E. Yconfigure: error: pcre library is required
( Q& i7 L" v. Y解决方法:
9 j; ~3 J6 ~' N( I0 x; i+ j" i) P
3 x  h7 {/ t3 O! Z2 E* {  ^yum install pcre pcre-devel+ _: [. m  K: O! Y' Q+ |
3.没有libxml2
+ ]9 N" k" P" i$ F& F1 `; K
. q) Y1 r" ]3 S/ t- _& M5 R8 a
# c; C6 B; g% n% S5 {% Aconfigure: *** xml library not found.
4 X3 f! T7 f9 B8 C) P0 Iconfigure: error: libxml2 is required7 N- I( r* f$ z$ B# _2 u! A
解决方法:' \, [% \! [7 a7 }
; u, R% l2 t+ t( Q* x& S
yum install  libxml2 libxml2-devel
  b; c. I) Z0 J# ^9 |4.执行 /opt/tengine/sbin/nginx -m 时有警告, q. y6 e8 P. _1 d

- Q9 y9 E/ {1 }- n9 c1 f& L. aTengine version: Tengine/2.1.0 (nginx/1.6.2)3 q- r/ B! D# {7 T: [
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!9 }4 ^' J: U: p" C0 L; j  c
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log" P( B8 k% z) C, S2 a' Z! f
5 ^7 w9 y5 h: a7 X4 Y! K
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.% w1 e. h) P8 _: Q
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
- m8 Y3 V7 a. I  u2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!8 P  }1 Y( B' j( h
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
: ?+ G7 l) Z8 R2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
6 Z0 q/ }3 J) V: D& l. g5 a2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
# i, n8 J5 U4 S  t% o解决方法,移除低版本的APR (1.3.9)( p5 I$ v, w2 \1 V# e7 `! k
+ o$ {' {: W+ H
yum remove apr
2 M, ]. N* ~" Q) n5.Error.log中有: Audit log: Failed to lock global mutex2 @# C: w0 u4 |$ V# i+ u2 s9 i

/ Y7 n# r+ ^2 J. V4 _( N2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     ) F5 J9 ~% u9 z2 ]2 M9 z& D- i$ q* \
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]7 f( v: f" W. U
解决方法:& k+ G0 E0 o$ Q5 z( P$ s' I
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
2 V+ A& S: G4 D# `8 e
7 N" G* Y( h$ ]. VSecAuditLogDirMode 0777
2 U: G& ?  e6 H) O7 ]0 _, q. VSecAuditLogFileMode 0550
  G% G7 E, Q8 l- \* r8 VSecAuditLogStorageDir /var/log/modsecurity
+ o8 ^2 L5 a4 `/ G7 {; @SecAuditLogType Concurrent1 l% H2 f5 D; ^/ R# l' L) w
参考文章:. p+ S( R; u! K. J
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX/ D0 `4 k+ D2 ~6 y& \8 m
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-28 17:05 , Processed in 0.153578 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表