找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12731|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。2 X) [0 t; C4 X  D+ |6 g* I4 q
1 S  a! B* O$ S' v3 }# u3 E
一.准备工作
' a. X. W1 _$ T2 @5 Y3 X* |
0 P. J2 F2 M/ a3 O( W" M' d系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0* t" B- T2 N2 k; k
7 S! L( b6 Y& h4 J
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
8 i: P* v# b- v6 y& D* K% N( \
0 Z7 K% c) q" @modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
. w" y. C, N& W% [2 ]( e- }  T: x
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
; G" `9 M! h. R/ m( C9 J
" J+ H/ c  a/ u- \1 T4 }' _依赖关系:. {  f& w8 ]/ K
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
8 m5 V/ m0 n" Y/ ^7 R; r2 @, ~; F( N$ M. Y
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
( @$ M4 d7 c/ P" B8 J& o" kmodsecurty依赖的包:pcre httpd-devel libxml2 apr- ~1 Z7 l0 Z/ L1 b3 _; y

2 |" x" @* ?/ G2 k: @yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel8 O/ K7 R. r5 @, m4 s8 I8 t( `/ H
二.启用standalone模块并编译( N9 X2 C1 X/ y! n

4 ?& s; X2 y* |9 |9 d" w下载modsecurity for nginx 解压,进入解压后目录执行:
/ p- S# C! q4 `- b% X& P* K, o8 }) h  Z/ t+ i5 N
./autogen.sh
# E% B$ X5 M% ~: \$ m3 \6 x4 u+ c2 i./configure --enable-standalone-module --disable-mlogc5 |2 O& G  j2 v1 e  o, u
make 9 U% V7 A! d& `0 ^$ x; O& P
三.nginx添加modsecurity模块. H/ e: @( q9 W1 k8 a* F

2 c8 T! q! Y& K, \在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
  t# u. X7 F9 d/ w: F; E$ N" J( T* ]$ w' _# H, L! C2 v
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
0 p% t+ @, d9 n8 g! _; b* fmake && make install  e- z+ f: D' i$ b/ C6 w( _
四.添加规则
; c7 E7 o7 T& Q& c* w) E4 j1 h2 c* L, ^% p* j3 i; W6 P+ i
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。) o/ J( u) K! x0 `8 e& e+ n
2 Z; v3 e, O1 q/ W+ g+ ?$ Z
1.下载OWASP规则:
$ A' j! ~! y( c3 z9 h8 c) N( {  h, l! @
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs7 \/ a7 o3 M' B: [; t( n

9 u9 l  m% _7 R; F! z/ Imv owasp-modsecurity-crs /opt/tengine/conf/
6 g! O& ?1 J: h9 x5 v3 s2 T# L8 ?$ M' ?2 z: A3 _1 v
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf, J% n3 Z* M! n
2.启用OWASP规则:% h' f; A, {* {0 e: o" c+ u* h3 Q
5 n3 p. l+ M% P  m, F. k) H
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
9 K2 m3 a: T  H3 o1 h! d0 J
4 C8 n" l7 V" X& A/ o$ h* R编辑modsecurity.conf 文件,将SecRuleEngine设置为 on' z+ s- W% P. V4 N
5 \$ s1 _3 @; E
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。. u1 c, _# Q" g+ ~. M
! T. A# M1 v6 `8 D) U# l3 L! o. N
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf/ f( _8 Z# b6 O# A% j
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf5 x5 p9 y+ y" d9 u1 _; ~0 F- q
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
: l3 c9 a! L  E" L6 wInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
. I6 B$ v3 I7 |5 uInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf2 @/ |$ l' b* I9 L4 B- Y7 d0 z4 p; ~6 {
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf2 ]& x8 A7 l2 B$ u
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
4 K7 O' V' X) m, O7 w- @# T五.配置nginx
; r: n9 r( R6 X9 j  z% q8 e. B! i  r+ v) g+ t  s
在需要启用modsecurity的主机的location下面加入下面两行即可:5 b1 G5 M! r  V/ T! u# S6 u

' @6 e# Z; h) Y" ]; d; b% YModSecurityEnabled on;  
3 H7 w6 ]7 M( ]2 B. s7 `ModSecurityConfig modsecurity.conf;* s) Z6 `3 P1 U+ @
下面是两个示例配置,php虚拟主机:
) |$ d' G9 G: j: r; V
6 t& B. B' J: @: K$ \3 t) e: e% ~server {$ z" N5 k) I) e: F+ j  I( P0 c
      listen      80;
8 k# `0 z6 S7 _3 a      server_name 52os.net www.52os.net;$ i7 q+ b$ Z2 s+ z, {6 M
     6 V6 l% O1 T5 D
      location ~ \.php$ {
7 r5 M; U1 @$ H' {      ModSecurityEnabled on;  ' w, ?2 T, `' c/ ^' L: \8 x
      ModSecurityConfig modsecurity.conf;. B0 ^5 W# X/ g8 K! Y7 O

. B( r. N1 T$ ]      root /web/wordpress;. v+ c- x3 G7 x, T
      index index.php index.html index.htm;
& y# \4 k; V1 ^3 [, t% d" N  
( o2 a* N" ?/ H% O      fastcgi_pass   127.0.0.1:9000;
; x- I8 |2 H  y- P6 h# b      fastcgi_index  index.php;- H. x" `, g6 o% v
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;2 J* D# B; Z. |7 `- \! r- m
      include        fastcgi_params;
( V0 i3 v. p  r" [      }  |8 \- C% _. A2 n0 v/ F6 I6 W
  }3 C) e% H( @. K% b# ^, F
upstream负载均衡:
& F* p! J+ d+ ^9 V" z0 y+ q2 y% F
upstream 52os.net {# C% \  o0 U' z9 h7 X: Q: o
    server 192.168.1.100:8080;6 r* L8 D% r& r- J+ ?7 f/ B
    server 192.168.1.101:8080 backup;. b8 Q) D8 `/ }/ \. Y3 Y3 y- j
}/ Q! G* p3 [& d& H# h. e
' N* i3 m7 l# t: Y
server {
5 Z. B3 q, {1 V& Y( _  @/ ]listen 80;" e7 k% j' D7 g/ K( P; H+ _
server_name 52os.net www.52os.net;
: n! Y" n) k* w9 C, T) }: c- _
. `8 m$ S/ |1 F; B5 w# `# [# Y: z4 alocation / {
" q; A5 [3 F: J# R( F    ModSecurityEnabled on;  
% A0 V; _- M' S/ e8 C    ModSecurityConfig modsecurity.conf;  
9 Y( N( ?9 [+ a" Z% ]) r, w( }8 n+ Y9 i) f5 Z; `/ _6 U* I4 e
        proxy_pass http://online;* n1 v8 a% ?& l3 X6 R; X& F7 v% V
        proxy_redirect         off;
  m$ `8 E( n$ ]        proxy_set_header Host $host;- R- R9 h0 e5 S& Y
        proxy_set_header X-Real-IP $remote_addr;5 `- k% S4 M# E& `8 M% S% [& u
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
+ r9 Z5 ?/ ?8 N    }$ x3 s8 V# A; s1 m9 w+ S! m. J" J
}$ V2 B% C; k" R
六.测试
, C7 F) K0 L1 g8 |3 \( z- W2 M1 _2 T1 `
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:# l3 @7 s5 S8 F1 {% E

& G4 k+ h% S! }$ k' o+ F* P<?php
) @' y1 Q+ y: t0 R    phpinfo();   
; k; X# t! ]' _1 Q# T% Q?>
+ N% N. y& g  u, S在浏览器中访问:
7 q: O1 o3 {6 \1 S4 E. x6 I
: ?; P8 |% H6 Q6 C) [/ chttp://www.52os.net/phpinfo.php?id=1 正常显示。, n( B: L" n1 X7 p8 j
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
4 g& H; \9 \) T: l# F0 @% m8 Bhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。! G9 x1 Z1 w' v+ M
说明sql注入和xss已经被过滤了
* H; R1 N/ v& h
2 N' a% w' j, |# H& h七、安装过程中排错
; E7 s8 l: i; U  v) B: `& a% Y' j9 \8 `
1.缺少APXS会报错
, k- `; r3 V% n& Q4 X! k$ Q- n; t
% ]. N, |! K5 p0 R  Zconfigure: looking for Apache module support via DSO through APXS4 g9 T7 i4 I' Z+ m
configure: error: couldn't find APXS6 L6 ]( C. o+ q  y+ P
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
1 Z- l/ L( ^. ?& e" B" }8 W解决方法:9 [% @8 o  D' \! a" C' [) h- V# U6 j

7 s7 @" S9 L! i7 q3 i! \yum install httpd-devel
5 s8 q* K: g2 P9 g2.没有pcre
8 a) y# R$ D) i) m, o
) A; u8 y. v# {configure: *** pcre library not found.# v6 j3 |" j; G4 r$ F% O& A
configure: error: pcre library is required- N2 y" F8 X* s6 N7 w
解决方法:
  a. @1 |; i+ H7 q4 U* v2 d
& Z$ Q9 U+ [" uyum install pcre pcre-devel# T6 o$ Y4 w& A9 r$ c5 ^
3.没有libxml2
  ~2 x" D) ]4 e, q2 @0 B( |4 }7 k! {' }3 z- y0 m+ ?1 }2 c
8 ~5 `0 @7 F& y, S
configure: *** xml library not found.
+ ?3 R0 b0 }6 \configure: error: libxml2 is required
( m# }. ^* D* V& ?: f解决方法:
5 `( b; a8 V; {% i! f2 Y6 W4 N. C5 A7 A, t5 C! `, g) C7 T& |1 y
yum install  libxml2 libxml2-devel
9 {$ N% @" K  [+ T4.执行 /opt/tengine/sbin/nginx -m 时有警告, e) j9 a! L3 L: x

- Z$ E1 q7 o$ X, N9 w& XTengine version: Tengine/2.1.0 (nginx/1.6.2)! l% U5 d) ~! Q3 J
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
: I6 ?9 H" D! e* k; W原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log4 Y9 k5 W$ Q4 l* q3 ]

& x% I& o7 v# J/ U& Z2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.4 {! p2 e" T* D: Y1 n
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
( u  [4 o4 i1 k2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!. @' d, N. j- _) E: Q1 H7 |
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"% r' z; ~+ u% D4 b& s  D: J
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
4 [# O$ ~8 p% l7 k( B4 t2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.3 R; ]; J: E( a- y, S) ^
解决方法,移除低版本的APR (1.3.9)2 a0 q7 x) ~4 P
; ]. p3 a) O" [, t& F
yum remove apr
% o9 ^9 j- L, z6 t5.Error.log中有: Audit log: Failed to lock global mutex
4 s% R* _' {; f% Y
$ q( V% _+ d) H) g' n2 [2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
# K+ b& v0 C* v+ ]. uglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]" F9 V& K: _8 u5 a
解决方法:: Y" K# J# i; ~& g  D7 N" ]- s7 V% P
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
0 b2 e, {5 \- d& O7 H3 B1 o' l* u( q2 `; T$ Y2 d6 l
SecAuditLogDirMode 0777
+ A' i/ j- z( f, H+ S; o" sSecAuditLogFileMode 0550/ N" ^4 k1 F2 C6 t
SecAuditLogStorageDir /var/log/modsecurity7 ^3 I/ N. X  f, N( `7 {( b
SecAuditLogType Concurrent9 \5 Z1 q, G* J- p) N/ z$ {
参考文章:
0 }4 t- E; v/ S6 [( uhttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX& k$ n6 e) @$ G% }8 ^$ t+ W
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-5 02:06 , Processed in 0.069593 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表