|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
: V) N: \. {. s! |9 y& `
7 m) V1 m" O4 b" C1 H一.准备工作$ x9 h! F {& ?/ ^4 L
+ A% h3 [$ y* D& T系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
1 l# N V4 f2 I6 I$ T% F2 p7 n( q j" W0 U; p- U7 q
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
! J) d4 Y* y- S( o" L9 i: ?, `$ x# s
" U! @9 Z) F7 Z7 K D$ [" T' \modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
( M& o6 J' M. N" o9 w b; b3 ~( q5 R% A" L- U& W' q W
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
" C' r6 d* U6 L
( o( @) B# n4 |. T* s; Q7 Y依赖关系:: ?2 f& E C" M" m& Y2 m
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:0 D0 q$ I, F) g4 }! ]0 H4 y
6 D2 I" G- D; ]8 Q/ G( ^
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
/ z' p& W, J' l/ z' Z8 L8 bmodsecurty依赖的包:pcre httpd-devel libxml2 apr$ h4 @( X: \9 `4 [
M9 Q, b7 Y+ N7 }& \
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
: p" ~) ^1 I4 y4 g6 K# _ i0 D3 E二.启用standalone模块并编译
2 z0 C: y, D; K) p- W: s1 A
6 G; Z; f' p4 i6 a; F! o/ ]下载modsecurity for nginx 解压,进入解压后目录执行:! b7 \% g! ^2 U- d, m# w
4 m) }1 k1 R) e" c6 I9 c+ q1 ]
./autogen.sh
3 k2 u* H, E5 X7 J: `./configure --enable-standalone-module --disable-mlogc
2 F i( a9 n6 k {/ Rmake
- L4 y$ ?% O) z6 a+ e三.nginx添加modsecurity模块
1 z+ _* [; O! r5 K0 ?# G- f- j; J! o3 o4 p, h& H- x" b
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:1 p6 U A9 q* [ a. \& D5 U `/ f
0 [2 ~' f/ A- d7 L* h3 v! u./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine- s/ S- {8 w9 c1 y
make && make install( d( Y% f5 l! O$ R3 k0 Y
四.添加规则
, l' w( B5 i. P/ q. M
1 `9 D; {' w: D* }5 Kmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。' Z1 }* D6 g- Z7 D& H
$ x O: \4 d, |$ J1.下载OWASP规则:" w, c N/ k1 r! q: N7 D" s6 q
3 g0 u, c- n) B$ egit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
, g" A1 R' K: s; u( A$ U6 N O6 w/ w8 g* }
mv owasp-modsecurity-crs /opt/tengine/conf// }4 [9 F) t, b# g7 q- Z
; E' N0 w' W* \% gcd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
) t, Z/ _% i" t! W0 l& s2.启用OWASP规则:
% S2 y5 n# q* I& @+ G& W4 n
A+ @9 e( B* X复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。6 y+ j4 L+ n4 k( B1 f& g6 i
5 r/ z6 @5 l8 w z2 A) e3 w编辑modsecurity.conf 文件,将SecRuleEngine设置为 on8 ^" ~- L& S: B- v
9 z/ S; s" I/ |, @. B& Eowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。. B; c) M1 v4 ]9 Z. f1 ?9 a0 g
1 b8 _( c4 h& i, H: c3 FInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
. u/ g$ M. @* \) K9 G8 t# e3 OInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf! u+ `% ?0 L. g9 N0 w6 j0 C
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf; \: f$ E2 _" C+ M1 e
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
/ O" @6 I' G& E0 R. d) a4 ~Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
- Y4 s* Z6 |1 E( ?" HInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ Z4 m1 h) H2 T% G, S; N
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf$ d$ J/ v( z# C& Q
五.配置nginx
1 [" X3 [- @6 O- q
! o5 a( S( M$ [' I% w0 l' V在需要启用modsecurity的主机的location下面加入下面两行即可:
, w" W# D9 e3 `0 L1 k# s" l) `3 \' c0 N
ModSecurityEnabled on; 4 I1 X! y) a( Q8 B8 e2 e" a
ModSecurityConfig modsecurity.conf;
* \1 S6 }0 Y) t R下面是两个示例配置,php虚拟主机:
5 `6 u1 k% x& q- F, h% H
; o: X/ b4 x6 l! J V" ?) mserver {
( _; C1 x* b9 |8 h" w$ U listen 80;
' @4 F6 R0 a$ s2 I, k# f' Z server_name 52os.net www.52os.net;
9 |4 j" ]5 r* R/ G5 n9 P1 Y4 A
- `, B' V5 Z) T" ^& V location ~ \.php$ {$ @0 g" k% A& Y
ModSecurityEnabled on;
8 ]$ A# d0 j, `: D; l, t' W ModSecurityConfig modsecurity.conf;: a/ B9 D7 a7 N( g9 p' V3 y
$ @" G7 {/ L9 G2 D ]: I root /web/wordpress;1 N' |; ?/ C! ~" A2 q. b' b; |
index index.php index.html index.htm;
1 G, j8 V, p3 O0 O( `6 v
; t. l2 W; Y. i. B2 |# g2 ?7 ] fastcgi_pass 127.0.0.1:9000;) k6 i) c+ R- V W
fastcgi_index index.php;5 i. v( \( b9 ^* f1 s3 ]
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;$ x W: g/ H; ?% |% l. q, m
include fastcgi_params;
4 i8 J5 l( T3 V }
1 k$ o+ I s* B( E: i5 ]; i }7 C4 _! Y( y1 d
upstream负载均衡:6 l% @* i6 D; y$ n0 q
9 a4 y/ @# H, Supstream 52os.net {2 h" F' ~& t2 W* e9 T
server 192.168.1.100:8080;
2 T/ s- ~4 _4 Y8 m% a server 192.168.1.101:8080 backup;
9 D' s5 ?; W4 P; S; U& Q" a}1 N0 P2 A! E+ M- \& H$ d q* }
4 Q' i6 p* b, |# u8 j
server {
8 D: c! N' b- x5 R5 \listen 80;
4 |: [$ ~# S+ @# R9 qserver_name 52os.net www.52os.net; C, x* D8 g2 `3 |
: C" y2 t3 M* W/ k% q
location / {4 j ]7 I8 {( t; V9 T- r" N& D/ R
ModSecurityEnabled on;
: x# C: t% x- Q+ Q9 d4 L- i, c ModSecurityConfig modsecurity.conf;
. F( N* |; c2 f+ |7 X* ^& f4 a) z
proxy_pass http://online;
' C7 j- S, \- v: h6 J proxy_redirect off;
% |1 t* y+ D; g X& R proxy_set_header Host $host;& l! |, M, Z4 y6 S& Y' ?. i
proxy_set_header X-Real-IP $remote_addr;; L2 x, @% }# N% i6 w, H2 s- p1 u
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- T. T9 K* Y# n% e1 g }
# }: \, S$ F, s}, m* v2 [/ S- m" b! k- O
六.测试
7 ~% `" o- b$ B2 t' r' v* s9 T {8 d1 }* C8 L! r! e% @8 b
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
) O' C( ^, _' o* c6 ?4 |$ X" j, q) o! o" m% _6 w3 x
<?php
9 n5 t5 n+ a; K phpinfo();
+ x" U/ ~9 D" G! p8 Y: \) }* D?> L. V: W" W: Y2 L4 x. M/ k, }
在浏览器中访问:
: ~! t" [0 j2 I7 B4 ` h" \; r3 Y! o
http://www.52os.net/phpinfo.php?id=1 正常显示。
( k8 z7 e+ y% T) E- o; |2 {http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
0 ~4 T2 v3 x) s, _ c4 j+ Ahttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。7 S- ~# F% l' b- v
说明sql注入和xss已经被过滤了7 d/ j9 ~# Q/ Z3 ]- U
; v6 \& o, \" i0 S! q
七、安装过程中排错
# \5 w- t) g2 ?* U; u. b# e, N0 ^6 L% J! @5 k g1 x, w/ N" }
1.缺少APXS会报错5 {; i+ [! o; U, t5 o1 y2 e( s6 h
6 f3 {7 `6 R: I
configure: looking for Apache module support via DSO through APXS3 f; X% P; @: \ H% W" @8 I
configure: error: couldn't find APXS9 ]) _/ L' J. ]3 r/ M
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
6 ?! q5 R' o# a6 W6 N解决方法:
+ ^! Z3 \- X0 H; y G Z/ }: x# D8 o
yum install httpd-devel
! N$ m4 f1 o# Q; s" H8 V1 b) B2.没有pcre+ D4 z6 @; o& U+ r. e
z6 Y d# i. G. r$ h8 [& Fconfigure: *** pcre library not found.
8 W* [2 x9 _ K; ~, E. Bconfigure: error: pcre library is required
7 q s1 z' V% ?2 j3 \! c5 |0 ^解决方法:
8 A& Y1 h' e1 h& J) L0 c" _' \7 m7 H
yum install pcre pcre-devel7 d' c k2 n& u# f4 C1 @
3.没有libxml2
4 H7 f0 ?" a1 f
% n" R; y+ }2 {. W
, [1 f4 p C; R( U- p' mconfigure: *** xml library not found.
+ ^6 m& r9 _; S' _configure: error: libxml2 is required
9 Q1 b4 Z( d0 h- y E解决方法:, p p. Z: S5 }
4 o& d; t) m" P0 o( u
yum install libxml2 libxml2-devel
l) z- T! D2 l" \2 b3 e5 K4.执行 /opt/tengine/sbin/nginx -m 时有警告* B- b0 R l- E$ Q1 B! X6 `2 Y5 W
! n" U! e9 H8 I: h; gTengine version: Tengine/2.1.0 (nginx/1.6.2)4 c, e* ~" ]& y. c
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!/ o5 E, ~' k: e5 ]( d2 _- E
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log4 |: t7 j4 N* X# t/ L3 e
* S* w2 J. v0 A' F' b5 a2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.
: j' d6 t( I5 y( {2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"
( p: h; v! j) U/ g% [3 O; `2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
: Q4 Z" H" \5 L2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05", p. T2 N; E) |$ L- b
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"6 y Y6 I, j. T- X3 ~2 i
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
2 R# W) V, U6 a3 o6 ^( _; ?8 S. I解决方法,移除低版本的APR (1.3.9)
; c- Z$ A9 I8 e/ o& P6 j0 ~* t1 g
; K! }% R- n* g" P( \2 Pyum remove apr! N+ f/ v3 o% [. I- o- o; J/ y, @
5.Error.log中有: Audit log: Failed to lock global mutex
9 \/ Q3 ]; p, u5 i/ Q$ g& @% Z; t, p9 h; P, T
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock
3 u( v5 A2 y: X' \: d& A1 x- Gglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
+ K9 x e& ]$ r, `! }: W2 n解决方法:
# p: [- |) ]! ]8 H编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:8 u# n& L1 s) J
" [8 H M$ H; h) G/ O2 NSecAuditLogDirMode 0777
4 a1 a. k7 s, F( ySecAuditLogFileMode 0550 F( u, d3 \4 X: O
SecAuditLogStorageDir /var/log/modsecurity( C; P: r1 [: l- |
SecAuditLogType Concurrent
. u! I$ s2 _* P$ H" N+ o1 Q8 n参考文章:
+ c. K; C2 K: \9 r: Lhttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX: h! U/ h& `6 e
http://drops.wooyun.org/tips/2614 |
|