找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12692|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
2 C" b2 o8 [7 i
4 }% b9 \# Z; p; Z. a7 U8 j- S一.准备工作
  I2 t# }' V- D5 A7 ], Y0 _
0 u" q( J( B+ `$ c( |) [6 g  s系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
6 U! M, _& q* D2 C2 S( Q  j- x; r8 m, [9 V6 @$ P: `2 e
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
4 p0 Y0 p# ~) q; E& C3 q4 V* T! M- t: B' v! t- I; Y
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
4 G2 k# }0 e1 A: p5 ]+ C0 D+ X  _. O! j8 ^3 }* Z4 M1 ^! w
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
4 q  d0 l2 J7 A- u( i
) ^. z) Q* X+ U& C依赖关系:
* m/ |$ v- ~6 u; y3 r. y7 _+ g- Dtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
" X% S. ?# Q/ j% H4 e
9 y: m+ l& t$ t. ~  ]yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
* T, O, p- |2 G- j$ f+ y' D# W/ Bmodsecurty依赖的包:pcre httpd-devel libxml2 apr) z2 V7 L  H  R1 a. \

' e' A/ g0 I" ^; p7 Oyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
7 O! p. l; D6 ?: K6 P9 t/ y二.启用standalone模块并编译9 x: R/ x* h/ s" w% N" X8 q( u5 K( d- k

& f. @6 n( V2 l' ?2 e. O下载modsecurity for nginx 解压,进入解压后目录执行:
( R2 \8 {, F, l' I( d; u4 w0 e! v/ u- _, k0 R7 E. {
./autogen.sh
8 {. [4 }3 R: j& X4 \& f./configure --enable-standalone-module --disable-mlogc( H9 l, B/ G+ ?+ W; M4 }8 e
make
0 ?. l- |5 [7 u5 u* r9 F三.nginx添加modsecurity模块
+ |8 k- y* P/ ]3 |
5 c6 O- B$ X* z! j在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:4 ]+ t4 F5 s0 o0 L
! v1 \! f- R6 x1 L) y
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine5 p' f3 O* T% i/ k
make && make install9 s9 Y$ V  ?5 _7 B9 A" |/ H1 g
四.添加规则
8 o+ E( Y3 u4 Y" r! Z" `2 Y8 }' h- `8 S% t, `; q  x0 E/ b% m
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
; j! B! ^8 x$ `" A$ T* N" w% _/ d+ E) _' L+ F, _/ ?/ z
1.下载OWASP规则:' r; j; ]' i5 ~" y5 ?( Z

, }6 c1 t' Z- B4 c; Pgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs) `, l4 |2 g' G/ z. x

- V- }1 p" K' l6 \+ lmv owasp-modsecurity-crs /opt/tengine/conf/6 y, t' M1 c- \7 L) I& d. l  N3 c7 V

/ {- \- l. Q; _8 dcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf9 x# |0 e, N  O, Z0 T
2.启用OWASP规则:
7 u/ T' e* D% Y# A# C: W5 r* G" o4 B2 O
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。& N8 k$ i$ }4 I+ P: W
  Z* V$ q8 V4 O+ T" Q) h
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on1 U! i% o0 W2 V% X) P0 q! f
. U# {4 b% g+ `
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
0 j$ |2 J4 v3 C3 D  `7 s4 z( D
) o; M' C% ]+ j2 _Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf& j. I; U- [3 r! P
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
4 _& \% ~: P* [; }Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf$ Y" e6 K" L- F( B3 p
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
/ U+ F* r7 \8 W' w- @. GInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf3 s) s9 v; \6 t0 J& \5 V
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf" b: Y$ d/ F! |' k# R
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf2 H5 }. J' E7 c
五.配置nginx; y$ d$ L$ e6 o# ?
: b; i7 _& O5 {3 M# \( V9 a& P! n
在需要启用modsecurity的主机的location下面加入下面两行即可:; j6 V2 w5 B- o. i& d4 s% r, S
2 t" {9 a9 v+ r1 m* E) g
ModSecurityEnabled on;  " i& Q+ I# ?; O/ ^/ V: j
ModSecurityConfig modsecurity.conf;* k, ?2 b! l4 r/ v
下面是两个示例配置,php虚拟主机:
! n8 ~; C6 K5 _) C, ?+ q7 x3 K) W( y9 Z5 @
server {
6 r" Q% ^% {" `9 k/ q$ T: X      listen      80;+ \- `2 K! a' p9 g6 c
      server_name 52os.net www.52os.net;/ ]. r4 _2 D" k3 c
     + r# t; R8 w% Z
      location ~ \.php$ {" P- k7 [; z" ^! u, g% D( k7 `
      ModSecurityEnabled on;  
) v6 J, k" T2 z" Q; Y, n      ModSecurityConfig modsecurity.conf;
$ K7 K5 H1 u8 O  H" g9 L
, _9 |, a+ r) h( R      root /web/wordpress;5 Q$ e8 \, O; ?2 L
      index index.php index.html index.htm;1 j  d: E. W; m  ]# X+ p1 a$ n1 C' v
  + k# i& C$ J6 l( ~; ?' H5 B+ K
      fastcgi_pass   127.0.0.1:9000;6 |- _8 p( L* S8 U
      fastcgi_index  index.php;& p# d9 W" [  Q! X9 r! d- g1 p
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;) Q/ J8 O0 F, w. {! G
      include        fastcgi_params;. k5 p* W9 t  g1 Q5 R
      }
$ N) Y9 _4 s1 N" y( Z  }
6 Q; M4 V4 D+ K% iupstream负载均衡:
  F6 F/ l1 ^+ J% s2 l- _
8 v  c' I% I( J# f0 @0 @) r3 uupstream 52os.net {5 X- B: D8 W* l' \+ ?; l( \
    server 192.168.1.100:8080;
0 Y2 v8 f6 P& T' s+ j! Y# Y( e    server 192.168.1.101:8080 backup;# w$ N% B  [; Z( r" A. ]' D  H7 f
}
( Q* ^2 e' `/ L7 j1 c& ]  l9 D
# O3 i, ?" D7 a1 h, \% tserver {# m2 y- l% v" @- G" [; A
listen 80;
$ z! C4 n+ ~* ?- }) _; K# nserver_name 52os.net www.52os.net;5 z' L. v+ `9 o4 U& I$ s- N

5 O  K8 r4 Z; ?" ~  w0 A+ Klocation / {
: A0 a. F) q# Q$ j4 E( C    ModSecurityEnabled on;  ) t7 G2 X" Z7 a  J
    ModSecurityConfig modsecurity.conf;  
, ~* B; [. \7 T/ c; E
  @% s* E) r% {. N2 \- r# H        proxy_pass http://online;
2 f1 {9 u. j# ]4 E7 F6 ^2 N& k        proxy_redirect         off;% u/ [+ p6 ~  }& G( n4 K, g
        proxy_set_header Host $host;
9 F' w8 i0 m( }( H3 F4 `+ \        proxy_set_header X-Real-IP $remote_addr;% x9 |: b! Y9 d& p' K, K
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
, V, w9 V+ B7 Y; J/ H# l  Q) x0 M    }
7 N* }4 _2 N& f0 B}
& B, I( }8 U% W  ]六.测试
( ^9 l* J$ f/ R) Y, f
" m1 o( s# \/ i我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:, S; |, A+ N9 }. o7 u) |" U  _: F
: u7 |4 ?2 J* |6 m+ \3 {# C
<?php7 |2 D8 E$ T8 e6 M4 C* s
    phpinfo();    ; O2 _: L  F; \* p" A9 @2 n8 W" b* _
?>* m) D9 ]! Z$ H- j
在浏览器中访问:
% K1 ~4 R; A( m7 [( `2 U- a7 C, l  G/ z  F& D; O
http://www.52os.net/phpinfo.php?id=1 正常显示。
: L0 ]* h% L. s% l9 R& Zhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。4 |2 K5 w% C2 b9 b, f. i4 r& e
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。- Y# o1 B- F7 c- r7 o% e0 f& k) x
说明sql注入和xss已经被过滤了. M" |' M/ Z7 G
% u& k1 X" i% N/ G+ w2 ^
七、安装过程中排错* Y- _+ e9 l3 }8 Z4 C' [5 g" F$ @

- r2 r4 q. Z3 Z' r3 S  [7 N1.缺少APXS会报错/ v% [) Z- H$ e: q% R6 i
9 Y2 n, T# q/ |
configure: looking for Apache module support via DSO through APXS
  {7 p9 `% G& b% Cconfigure: error: couldn't find APXS
5 ]/ Q# Q5 F, l/ `# ?8 P6 Q9 rapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。( B' }5 _; e" ]) g5 k+ Y* t
解决方法:
6 j6 [  z; g( q$ r1 P
' Z( ]( ?* r3 Z# c5 G3 I, Zyum install httpd-devel# H$ M9 M, S% u  S2 Q! s
2.没有pcre
' Q3 e9 e' V' Q$ `3 @3 k5 s
' J2 [/ h) g  j% Yconfigure: *** pcre library not found.+ v4 `, W9 A, K& B9 ^6 E2 N+ [
configure: error: pcre library is required
3 Q8 q! q  V" Z" G  ~5 G( L解决方法:
) ^+ m/ p$ R" V) l, V5 S8 h/ B
( P" ]) O8 N  I; X# L* lyum install pcre pcre-devel
( k5 R- b9 d: w  E3.没有libxml2
1 t! q- j* d: M. K% O$ L# |" p
0 W$ B; \) V$ F
9 g# g! z; o8 |* i: k% qconfigure: *** xml library not found.$ n/ q% J7 r+ E
configure: error: libxml2 is required0 |" P, S, c( B! \
解决方法:1 {+ u8 Q3 u$ o5 k# r0 d9 x+ Z/ G

' }6 {5 J& i  p# e8 ~& iyum install  libxml2 libxml2-devel$ h6 z2 S2 j% B
4.执行 /opt/tengine/sbin/nginx -m 时有警告
" C* T, d7 v, R1 x# ~3 y" j
$ Z" D# i/ W8 C. j0 cTengine version: Tengine/2.1.0 (nginx/1.6.2)
* I  T) k; B  w  l- n. z# rnginx: [warn] ModSecurity: Loaded APR do not match with compiled!
! a7 k! {) \! a' U% n0 d原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log% w. |9 _  Q4 H& O- K
/ L  U* c/ E9 F6 j$ x( d# c
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.) D& l. K) k  u+ H: w% v
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9". H1 S3 K; O" C2 p2 I) Q' J" r
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
- k7 p3 E5 L  u- B  B4 b! N2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"* {& }4 P# I: H8 y" L
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"1 P% v; T! s  L" k& P+ l
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.. l2 q& _( ]& G9 @9 y
解决方法,移除低版本的APR (1.3.9)+ P7 P" T  D0 g
, j8 x7 w  C  P/ ]4 r5 B( b
yum remove apr  y/ Q' P. M( M, H2 s
5.Error.log中有: Audit log: Failed to lock global mutex
9 ^9 v! P/ |3 ?9 R* _3 O2 A3 N# b9 ~: @. t
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
. M# p5 A% _+ N( _3 L+ ^global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]: n) ^7 }$ u2 S0 j* t& H
解决方法:
& Q4 y8 Z# z& I0 ?& G% \编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
. h4 ]6 |- \& u$ y+ r' G' {3 N5 y4 T
SecAuditLogDirMode 0777
% r! |; p8 ~& f) WSecAuditLogFileMode 0550, K6 ?7 Y; m: D5 j. e) O1 K0 F- t
SecAuditLogStorageDir /var/log/modsecurity
% ~& V7 p! y4 v6 ZSecAuditLogType Concurrent
  ]/ a2 \3 F6 U% J( c参考文章:9 H1 W- X/ }8 Y
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
, E' P- T5 C- p( F0 B* vhttp://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-9-30 09:33 , Processed in 0.086363 second(s), 20 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表