|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。$ a4 U5 [/ R8 ~2 F( ?1 _3 B% T
6 u q" O( V# a2 R. B. N
一.准备工作6 w+ W. r# ?7 i2 p. g* i0 K W
% Y$ }" j4 n# A: J q
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
4 n: D% v% ?# t4 o% J7 u) t4 g: @' y
' m! H/ B$ W; V8 r1 Q: o, K( ctengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz2 }' S0 u$ v, c' p' `3 N' x0 q
3 [( n; x B; j2 wmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
2 V$ ]# Y+ n3 G+ o/ |5 Q
% A' T0 y9 p; P- c) u/ K7 r! D& ]OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs T& _' r$ L, @% t+ s1 t7 q
+ ^+ X7 Z$ J6 ]1 M- }5 R
依赖关系:
# T# S- g) A: f- d* C2 rtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:/ ~' D! u7 a- }5 E s& N: F
, O% ~: R N& ^% M- }2 O
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
) ^5 e2 r" _; @1 ?4 tmodsecurty依赖的包:pcre httpd-devel libxml2 apr
+ Q9 m! B- N* \! ~0 H* W. Z& a {$ B) I$ _9 {; _
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
6 w0 u$ y. o' l二.启用standalone模块并编译
+ x3 j; r( _. a1 O! M
9 M( i( a, K8 K7 y0 d: p2 M$ M% E下载modsecurity for nginx 解压,进入解压后目录执行:
7 R' S5 k, U9 F+ Y+ P5 Y7 y3 Z9 `& T
./autogen.sh
2 Q" ]/ M! t* u4 V. ]+ |2 Y. I./configure --enable-standalone-module --disable-mlogc8 C8 V; X. ?! g' W/ C
make
/ n1 c0 p/ o& k6 @% i' _# H三.nginx添加modsecurity模块+ f& Z, P9 D M& w# ~ l4 g
9 |$ r+ |( q/ ]# R" s
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
5 D/ x$ }8 S- ?* n3 m8 B3 `* N7 w5 S+ I" D, J# y- c3 Z H
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
' K* t' v, i( I7 I4 [4 _make && make install
9 e: ?) p0 ~: O* H" z/ ?* r8 W四.添加规则
# i2 f7 v- I. R% ]1 O+ ?2 ]
' S! R/ m& U; {& L7 X* xmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。 m) _/ ?; n w" Z! j8 k
1 e* ?+ U+ ?/ F( U% E1.下载OWASP规则:' _& o8 m0 \7 m9 |
& c# t8 v1 T- x- Igit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
2 Z0 i! t4 Y% b0 k8 ?1 u) M. Y* p. t& I3 P3 T/ i; n. }: I+ s, }
mv owasp-modsecurity-crs /opt/tengine/conf/$ I) s- K/ M6 i4 W! c) k2 r9 F4 B
: S- X2 d4 [4 E% M. a) ^
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf1 u; r$ j0 B8 n
2.启用OWASP规则:
9 ?6 w( q7 m, s" u( c+ D. J5 L3 K: e6 U
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。& m1 i1 Z! m8 K7 u, _) ?
# |& c6 t7 \. _0 x. _( r6 D7 V! y
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
- d" ^- m$ V0 o7 L5 K' @! |5 e- W( Q8 s4 h. i/ \8 M
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
, h& Y$ O% y. m, p {% k3 y6 U* J" s% G ~8 g
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
# z, I+ e3 H$ L; N) v+ @$ J3 zInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf2 r0 q; `$ _9 n3 l9 n
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
7 a2 d0 _4 L* W. K8 V& zInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
' l- Q0 h: k4 F& d/ x9 _Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf' X8 V; L _! Q' h0 X( M
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf7 N- z, o- v$ X- T/ ?; [. A" l! @
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
( |! v) p: R! P5 Z& [五.配置nginx
: ?- N ^! w9 C
2 Y0 Y `; F; B# d2 M* T在需要启用modsecurity的主机的location下面加入下面两行即可:
. q3 S k3 @& f8 m5 b
$ k; Y0 I u5 T. P7 HModSecurityEnabled on; 5 {% V% T* ~3 c% z/ v9 v
ModSecurityConfig modsecurity.conf;% d/ H1 }/ z) O; Z* }
下面是两个示例配置,php虚拟主机:
3 M0 T- T) X+ I7 D8 l+ F4 X: ]8 [1 Q3 I* X7 z1 Q8 C
server {
$ e& ~. R3 w0 c/ @% \& n. {- s listen 80;. R" y9 h, n, {% J6 L7 {1 I B4 Y: Z
server_name 52os.net www.52os.net;( V0 i4 ~ n7 U- I3 K
* X; ~9 N. U( Z1 m
location ~ \.php$ {0 ~5 }- H) ~0 Y$ s4 p( G2 `6 }3 V
ModSecurityEnabled on; - ]6 Q0 e# t! `% x& }. t6 y0 W
ModSecurityConfig modsecurity.conf;
. v* s) h1 \8 h- ]% N8 W8 J
- D& c. P, ]% }, X' F% i root /web/wordpress;' l+ i2 t5 L1 t) E! t( U4 h, d
index index.php index.html index.htm;; f! Y* t& T0 \$ ^) e
, B6 b5 i& E2 G* O fastcgi_pass 127.0.0.1:9000;
% O# @3 P' i! d0 R& ~ fastcgi_index index.php;
! J4 X; `, M/ m0 I fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;& a) M6 d" b) N& f% B
include fastcgi_params;
3 ~% k8 Q5 `5 R3 D0 U }
2 I2 [9 w- f) U. u }
% k* {1 ], c$ l) A5 A& |7 Z/ C* Z+ y! Supstream负载均衡:& w4 ]3 m& M: T, g5 ?0 X# }' c
) P4 X, O k e# V! [) U' d
upstream 52os.net {( t4 l/ T2 j( {9 Z* P* A/ B
server 192.168.1.100:8080; ~" M* c1 w; U% u+ D# S
server 192.168.1.101:8080 backup;
5 Q# m( m" }1 m4 H}
P2 c, s' J/ U q) i
4 d$ V* b' c5 J# O( B9 |# o, H% tserver {4 C9 [6 m! K1 v: U; A# r' J, H
listen 80;& U9 c0 r' Q6 `0 O2 Q- o# N
server_name 52os.net www.52os.net;
! c5 @$ D, Y8 J; w8 G" s9 k% _) _: F; ]! \4 ?
location / {
/ `4 U: t* I% H* {: ~* m ModSecurityEnabled on; 9 Y' y4 i) m6 R* J8 e
ModSecurityConfig modsecurity.conf; + j$ c- Y: A! v2 @, B
6 y: G- N, Z+ O proxy_pass http://online;9 }: S) Q$ w- S# u" ?4 I1 t
proxy_redirect off;+ W5 C! v. o p% g6 z m6 I/ U
proxy_set_header Host $host;5 N3 u4 q, o, b. e" s/ D
proxy_set_header X-Real-IP $remote_addr;4 n6 ~; t! V" L4 D
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# i& y8 L, \5 k9 i" h2 d# M* b+ m }
. b$ v' ^, A v% E7 G) X+ s}
5 k+ B! ?3 L; A+ J( J1 @六.测试
: p- t/ G8 s2 G. g; v1 ~8 A. _4 H7 z! ?& N: X3 K
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:0 k0 U2 r* B- w: Z
0 ^( _1 X0 P e) ]2 U" D8 y3 Q<?php
: T! g2 p8 L) Q/ J" P7 W phpinfo();
O: d8 Q5 L4 Y* f, ]0 O/ L?>
1 H9 L( K; j7 D* {: K+ F0 K在浏览器中访问:
- B: I4 q X2 f" |+ b, D) m( }* r5 j4 k1 P
http://www.52os.net/phpinfo.php?id=1 正常显示。& F9 H2 M1 o1 K# ]8 K" D' [7 ?
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。/ g+ H( H: o8 W2 w7 q9 w+ N* y
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。+ s7 Q" S6 ~# P/ P+ s
说明sql注入和xss已经被过滤了; Y+ N1 M2 h; ~- F* }4 g5 c \, x0 Z
H. ^) H$ x% k, N! R; m; c- ~( F$ s7 E- Y七、安装过程中排错
4 v! t: e B/ N
0 {8 Y, D" W1 y8 a1.缺少APXS会报错
- x4 B# M8 |8 u9 D
& K: l8 }# C& \6 O G2 ^configure: looking for Apache module support via DSO through APXS
- J7 O# E6 ^/ o+ p) p9 Kconfigure: error: couldn't find APXS) {5 f" H% Q* I% m
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。9 q/ M9 `$ {5 R5 H" T/ v
解决方法:# C! R+ A: K' Z! M4 H; T# g
3 j$ e" c2 w; V) F, \6 u
yum install httpd-devel
/ K* r# s! D" K7 ?0 V2.没有pcre
! Z8 O3 d7 e1 |5 m1 U! ^& A) O) l# K, U5 ]( @0 i5 l$ m
configure: *** pcre library not found.
8 \1 k, @4 m) A- Dconfigure: error: pcre library is required
% x+ i5 j# X' {5 c解决方法:
3 p; W4 Q1 x& \5 Y5 j. ^7 U @
* j% w) P4 e( V' }yum install pcre pcre-devel
% I, C# W" c4 |+ t; N3.没有libxml2. T0 d+ h6 R7 n' Z9 j
4 O/ F1 K) M1 b( `8 l2 d: J/ K9 Z# ^
6 F5 m" D2 M9 c. K) pconfigure: *** xml library not found.* b. O0 W/ C* z
configure: error: libxml2 is required
- w1 }; ~4 @1 G0 I解决方法:1 r7 i: W5 D4 |* Y2 W! A( Q
( {& B! b# R& ^0 Hyum install libxml2 libxml2-devel
7 c7 ?, H/ _& K. k: f; C4.执行 /opt/tengine/sbin/nginx -m 时有警告! H& O2 K- K' m6 C. A) o! z2 p
/ \3 S+ D, [8 Z' E
Tengine version: Tengine/2.1.0 (nginx/1.6.2)% b* v) f* V6 c7 P& U8 {2 n' A
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!) G3 c" `! {! n# V4 \9 I
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
. f M0 G+ q, {3 Z+ `* W6 ~& A: V/ D3 a- K9 O
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
- e X0 g$ {- T2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9": P# o2 S5 ^3 q- \9 D3 R/ H4 \+ r2 K: N
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
. k! W1 [% P# \8 l" \9 f' j2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
# l1 N6 m4 }) T" W; e, ~+ E" ~2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
0 C4 v; A; v) Y; N+ }2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On./ o- z7 C J! K$ v
解决方法,移除低版本的APR (1.3.9)
4 [0 ` f: E( W' t/ S
3 B1 d+ q' B3 ]7 t3 vyum remove apr
$ u5 B0 C8 r) g- n, l5.Error.log中有: Audit log: Failed to lock global mutex
6 q% G! \1 j' e+ P
3 a1 j3 t/ m7 S2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
" L- o, s) l) uglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
- [' { H5 N) ]2 ? ]9 u解决方法:: i- D9 S& K/ r6 c9 g- W4 R
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
9 I7 r* k# Z& W
) O; d, `; d& l4 e/ wSecAuditLogDirMode 0777 h& B6 V6 J& I( F0 G+ L% s6 t+ I8 Z
SecAuditLogFileMode 0550
( L' O' g/ `! lSecAuditLogStorageDir /var/log/modsecurity$ e# p* r8 _0 d3 M& q. J
SecAuditLogType Concurrent) v- ?* e9 F9 S$ ~) J/ k3 K- ?
参考文章:9 p$ f' b! C% K9 N0 f
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX. Z0 w1 {: P/ x5 w
http://drops.wooyun.org/tips/2614 |
|