|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
2 _, O/ V3 h1 a/ l( e; g# D$ ^7 p+ a' b" U: T4 B/ r
一.准备工作" T( E! j1 Y3 r& K. n, J
" W# R$ ~% B; i0 v% m7 P8 p
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0& T7 k& ?5 p2 O5 ~7 h
! J0 J6 i* z) `& ]- r3 w) ?
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz5 R# K, y- K% W
3 L# l* l1 o' w# D1 l. N; r: k
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
" K j! s9 b0 }9 z% D8 h" B M
# ~( r4 Q" C, c( H/ DOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs, p+ y1 O2 q4 @9 S& _
& y9 f8 R; `$ t. z+ Q依赖关系:
- A. s* ]5 I, d$ b' Btengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
5 ?3 W" R2 p6 _8 M: v- d& ~1 P/ L1 g( v* |5 {
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel, g5 I- u3 k. U% E3 a w
modsecurty依赖的包:pcre httpd-devel libxml2 apr; g# d6 P: |2 o) @/ X
0 u9 F2 m6 _5 R. G+ d
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
- B8 x5 U O6 w% d二.启用standalone模块并编译
3 B& P& @4 b" G$ [1 l& F5 N7 m( ~1 @" ~# } s* Z3 t- q
下载modsecurity for nginx 解压,进入解压后目录执行:
/ B6 S8 h. D# q# r2 Y. n
2 H2 U \3 K- L! z7 q( O* g$ k) P( ~./autogen.sh
1 _9 p5 n" {4 k9 E8 Y" q/ j3 u/ d+ Q./configure --enable-standalone-module --disable-mlogc* p, ^: g, V1 ?2 M. H5 A/ G
make 3 C( s% U+ Q0 D/ k* }3 t. _, U
三.nginx添加modsecurity模块' [# {; X# R% u% a1 o
' E+ J O9 z% x1 I2 W) r* D7 V
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:) W% [+ i% A2 f5 k
) s0 |% @: e6 g9 L# ?
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine* J) f+ q& D' @( m3 R
make && make install
8 g n& k) ^2 [: V# m# |四.添加规则8 s( E# R) n- J# ^2 ?( {. U1 `$ y
7 L' ^; j- z6 R H/ U% amodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
0 S- t l0 X% W8 `* q! m% q2 W( Y: |: b
1.下载OWASP规则:+ ]" c0 r( a' d: u3 K; q
" M& M2 u# B5 L* Jgit clone https://github.com/SpiderLabs/owasp-modsecurity-crs ^# w) |( u$ [$ K9 B
' d# G) u4 _; Q: c$ x
mv owasp-modsecurity-crs /opt/tengine/conf/
% d% ]4 q+ b& b) I7 K5 @1 v" A
! Y$ N9 g$ m: t; M6 z, acd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf1 K8 `6 h v+ X
2.启用OWASP规则:
, }9 V1 q) q/ p& t Q5 Z2 ]5 D: ~2 \) ? e7 k
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。; I$ {* C4 f5 u; B4 I. q3 f
/ e) [+ Z( u1 C$ E1 l; \编辑modsecurity.conf 文件,将SecRuleEngine设置为 on$ I$ W8 K1 e3 A# @7 l$ z* A4 `
/ m; b/ _* D" R9 V/ R
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
; l7 X% J) w' p4 x6 v: i- e2 J' J3 p8 J; e6 O& ?
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf, l# |5 h C+ z
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf# n5 }# @& v% Z
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
# }7 ~3 i- D7 Z7 G, TInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
* a5 X7 O0 n# H1 o9 O {. mInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf0 s" }2 h O1 u7 T
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf8 O& R8 v- e# d+ }
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
& Y r4 }" p4 i! ~# S! t五.配置nginx
) f7 u, H" b( `& q6 _! @# \ s( e* ]" t
在需要启用modsecurity的主机的location下面加入下面两行即可:
. J* H3 p; R0 i* p8 r. L0 r) n% X, `' W6 ~$ L, ~* ?4 S* s
ModSecurityEnabled on; ' |7 C& G# L* Z5 o- Y- s( D
ModSecurityConfig modsecurity.conf;
! o/ y# z8 x. Z+ ]9 w( y! I下面是两个示例配置,php虚拟主机:
8 @8 I( ?) s6 l3 H7 r1 H$ T* R; k Y. S: L
server {
8 l5 i; j6 c+ F( V0 p listen 80;2 k d" G3 M" h5 |6 h8 B* s
server_name 52os.net www.52os.net;$ E$ D$ r9 H W! c0 k+ J
+ Z4 ?0 M/ \6 I @+ s) z
location ~ \.php$ {
# ]; v! a' t% @# j1 b8 T ModSecurityEnabled on; 6 [$ a' b% D! W7 x8 z
ModSecurityConfig modsecurity.conf;
8 i g! [/ \+ Z, |! K8 ~4 [* {$ p+ J% J' a+ U' A
root /web/wordpress;
9 q4 h2 l5 Z) O- D8 o8 q index index.php index.html index.htm;
8 f2 P7 G* l4 ]6 a* |" g8 z5 T7 O+ j % v/ b9 Q& r2 A- J. R9 d
fastcgi_pass 127.0.0.1:9000;% d3 x D: }9 E/ F( \" A& v
fastcgi_index index.php;5 T6 j2 T9 C8 ^; T; T; k% u6 d
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;# w$ e' {. Y: \0 X$ e- ^
include fastcgi_params;
9 F4 G! s$ d3 F; I2 b }
) u# E$ D: ~# C: m/ S8 M: | }6 f; t& c7 ]. E9 C1 A8 C' x
upstream负载均衡:9 c+ w. a3 e$ Z, b. T+ ]
: w! B9 g2 Y/ _' w. lupstream 52os.net {) a/ {7 ~* _, J6 |2 f' \5 o; n2 B
server 192.168.1.100:8080;
% Q# j- i4 _' i0 d$ m server 192.168.1.101:8080 backup;
" a0 c1 f- G2 X6 T}+ ?6 P; `$ S) {" b
$ w" J6 Q- B: [9 G7 G8 s, r3 t, Mserver {
8 ?& X( t. L5 s6 a& D: }- _listen 80;2 m; [! L0 m6 z3 Q. L3 Y. u0 ~
server_name 52os.net www.52os.net;
# X5 f" a% n2 f/ V' Q6 k: A) o) k! o! D1 a+ j1 m
location / {# `7 U( { T3 u' c9 ^* x5 K( ~" p
ModSecurityEnabled on; # D$ ^" ?7 J' q8 P# _# S3 D% X9 G
ModSecurityConfig modsecurity.conf; ) B) B' n, |. B& ^8 U
' a% ~9 m+ o# |+ Y. S* b proxy_pass http://online;
; d' O1 Y, L/ k i" e g' J: @ proxy_redirect off;
% U4 Q6 B- h, O proxy_set_header Host $host;+ k% n4 q9 ^3 D* r: c
proxy_set_header X-Real-IP $remote_addr;
+ Y5 D: l- D: g8 Q& L9 _4 J+ }; ` proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
* g' U0 s6 a d8 S }
# e2 T! X- e) x* }9 G( w2 q1 J}
2 f f g' q9 [/ {2 }; p六.测试
# a/ N3 S, U- g5 b- x
: _4 P) z9 l6 c2 S7 U- d+ E我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
; Q$ x+ t( c2 C( {+ D( P8 V' j+ X/ u1 O6 w7 G$ \3 {
<?php
7 A- b: T' E) \ phpinfo(); c2 M f, ?& |& m1 U$ b' E. X
?>
5 M: M# k7 ?2 h/ E7 Y: g% Y- Q& s在浏览器中访问:& A2 b+ u1 X2 m% \
9 j+ o) b9 R# @0 V' x8 ohttp://www.52os.net/phpinfo.php?id=1 正常显示。, l, Q, z5 `* H) f4 D9 I
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
; F. R9 ~( j+ y% S4 Xhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
" U0 w7 n# o- ^说明sql注入和xss已经被过滤了
! C* C& C9 I( c( S9 a! b: F* X/ P8 h( e `7 h. V* G8 Y3 p
七、安装过程中排错/ Q- ^1 r- e0 L
. \5 G& d; q8 k1.缺少APXS会报错
, |# I& ?6 I9 ^# N" o ?
$ h, `- H5 T9 G! _configure: looking for Apache module support via DSO through APXS
1 n3 A. h) k5 r! Z# d1 }- F& Gconfigure: error: couldn't find APXS4 Y9 }: i3 s' h+ @0 W. B
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。% R) ^ B. d7 G
解决方法:4 w6 M/ h2 C+ |5 ^ m
; w1 |% J- \) g0 |9 ~6 O1 o3 @5 K
yum install httpd-devel
5 |' Y0 J# y8 C M- `' G2.没有pcre
& u* O' J) E7 \: I$ N" t _! l. t2 C
configure: *** pcre library not found.2 m p2 e( t5 A2 B6 y
configure: error: pcre library is required6 N4 W! W7 I9 Q2 u8 [) o
解决方法:
& E+ x3 @" s1 W6 k. O$ w. L3 @" u, [) }
yum install pcre pcre-devel
8 n; X4 }4 _* |# N! W: ?3.没有libxml2
, l4 p# V! g i. T5 r6 L# c) o' T( }& L% U0 A( }/ |; \9 D# S! @6 ~7 S
: s# i! h7 A+ C, q" Yconfigure: *** xml library not found.5 A; A) o& l4 Z9 j9 ]; @( i U. U
configure: error: libxml2 is required
/ ]3 \0 x( I( E! y5 `, f解决方法:2 q5 m1 a7 L7 ?1 m+ E- y0 P
! s0 E5 P: G% O3 l" Z [
yum install libxml2 libxml2-devel5 b1 I' h+ a1 Q5 \
4.执行 /opt/tengine/sbin/nginx -m 时有警告# p+ V- M# V R" V" S* ^# }
: f4 U \7 k7 v7 d2 [; Q
Tengine version: Tengine/2.1.0 (nginx/1.6.2)
1 d9 @6 {; W1 E( l1 C6 Fnginx: [warn] ModSecurity: Loaded APR do not match with compiled!9 m0 j; ]9 m# u8 P- f
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log" i6 @8 w1 d7 W" K. [( e6 S
& T3 N$ F) E0 h. r' d9 {2 E7 F2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.$ n- ?* W9 Q7 f5 c' }
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"+ ^8 J- n1 ~6 W
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
) k6 W9 D% |: m0 P8 x. g8 g& t! K2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"( ^' h: ?+ l |; S, E- N1 ]
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"& t8 a* k7 R7 h% g, p. J4 j
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.7 P. ]! N6 R) K& ^7 l9 z1 j
解决方法,移除低版本的APR (1.3.9)
$ s( x. s* z& ]/ }1 L. j7 H
; g! G8 y% D" D9 S& m3 Y5 |' fyum remove apr
+ I' l. D1 ?0 x) Y5.Error.log中有: Audit log: Failed to lock global mutex
9 }8 D! g' `$ E! r$ G; m! s% c# S8 g/ W$ `( ]0 D7 ]) I
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock `& ~* D! q; `7 g% d
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
; v* J3 c9 x; a, Z解决方法:
; d6 _* }" {+ I# O P2 n) n编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
3 c) R. o: Q& Y8 J/ @ ?/ N) |- E, {* k1 O7 n' ]; C* N$ q
SecAuditLogDirMode 0777
/ G* \' P9 s( y) M+ jSecAuditLogFileMode 0550
; V# [( q/ K# \3 ^/ H& X8 q' m( RSecAuditLogStorageDir /var/log/modsecurity
3 N$ n% a/ O. r1 N% a9 H! |SecAuditLogType Concurrent4 s5 i% Y4 G+ x
参考文章:
& g0 p7 ?( A2 V! D. Lhttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
& X% X" `8 l- V' xhttp://drops.wooyun.org/tips/2614 |
|