|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
% I o& |5 }6 j- ?: C; @0 P2 w* t2 i t% L2 z
一.准备工作
: B9 o+ D9 @" J1 M2 h# e# s' k8 d2 R# F
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
; z r3 |, L. e6 ^ ]7 t; x0 E$ M9 _% p2 H9 I/ Q! `
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
: _& r! f# D3 i8 [& ~, O" Q- J* W+ `. ~1 y! {* C! c \
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz* Z; z; B& g. P3 ]1 V/ i# M
& O) n* x+ B1 oOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
* {. C2 M" d3 J: Q" l( `: H3 F& r0 |' {* |4 O4 i9 y
依赖关系:
; o9 O7 u m% dtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:+ y3 R+ E' A% }! c7 c
( M& X9 o& p! M8 z5 h# H, M
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel9 l( A Z6 H/ x( X; M, o
modsecurty依赖的包:pcre httpd-devel libxml2 apr2 }8 k" a6 ?4 l2 _
2 L S0 q0 j2 G8 Q! i' B" n( {yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel
( ?: J0 u. M2 I' P9 R二.启用standalone模块并编译
! B7 Z9 w$ n# A- @2 S( z: u7 G! H! l
下载modsecurity for nginx 解压,进入解压后目录执行:
( a' A! H1 Z( @( M* w$ k
. G& M( s- J4 b$ C./autogen.sh( d- N7 L$ n& |2 ^2 d
./configure --enable-standalone-module --disable-mlogc+ k! {, q- e, N# z6 |# l9 c: q! M
make 9 }$ T( k* Q% Q1 r
三.nginx添加modsecurity模块! i# D* @% ]# s/ g; L0 s
. j5 u# M! N* d% R0 i5 D2 f( Q4 q
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:2 g3 J3 C! r8 u) @3 t) D6 H
2 S5 M: Y( P' O0 R( O7 p./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
; j8 s4 [) _' e% l* k; Ymake && make install
& S2 X" G$ I1 H7 n$ d1 W h四.添加规则
- E2 l1 Q3 ?& N( ?$ e9 X$ m8 h: D' `5 m( g$ L! D: v+ s
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
5 n9 B% G9 P: f4 G: I5 Z( @% T7 v& d: A5 e' z0 e/ T* B& E0 n
1.下载OWASP规则:1 x* b! \ ^8 }6 n# B) |! u
! b; u3 I- o& Q5 h E, t8 Ngit clone https://github.com/SpiderLabs/owasp-modsecurity-crs
7 w- M/ L) k. ]
}0 }1 B$ E# S! ?: z5 vmv owasp-modsecurity-crs /opt/tengine/conf/8 C6 o$ Z5 g. m
& V+ }7 N5 K! v
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
2 ?* R. @+ A2 O6 ~! q1 U4 z2.启用OWASP规则:) L" X# U' i* j' J2 ?. O" Y' ?
, V! k; r4 V$ p9 f; o- d: t复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
% I: x7 c" s1 g
7 `% _: F$ K$ E: o5 F' n7 S0 l Q, \编辑modsecurity.conf 文件,将SecRuleEngine设置为 on/ \3 e! B" A7 i# _) s) J, b9 ]
e2 P* L' n0 W# U2 c/ aowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。: ^( E0 [7 L/ w& e+ ?2 F1 s
5 G& T( e* n+ P1 i- h" eInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf$ k3 b S. X n. L5 n0 c/ k& m% L. ]
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
: ?: v# C- P: I r) EInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
) w* p# \. B l: s/ c: p7 rInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf2 R- n( C; v' {/ n" c3 \3 p
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf& d8 g6 r v4 [ [$ L5 ?' ~& x. [
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf0 L: F' h) P$ ^& w
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf7 U- Q5 R( e9 h& w0 o0 R! B
五.配置nginx
$ L$ \. Q9 Y# j( J- u& _! P4 w, l( ]
在需要启用modsecurity的主机的location下面加入下面两行即可:: _7 c* h" F" c8 C$ S
: [5 q+ I Z. k3 Y1 |& x" E' T
ModSecurityEnabled on;
3 J6 t' A# t0 Q0 P$ @* |ModSecurityConfig modsecurity.conf;& W7 p, E+ P9 A; _( X6 i
下面是两个示例配置,php虚拟主机:
% Z4 e0 X, i$ l
! L D- |+ O# u1 Jserver {
# G/ L/ `9 E0 E' { listen 80;
) h/ U4 [ {4 o1 }. n server_name 52os.net www.52os.net;
4 _/ }4 o- W* q, Z( n + E" q5 U2 S- ?5 v* Z
location ~ \.php$ {
' _/ w! C- d/ n5 w ModSecurityEnabled on;
8 b5 Z9 n6 X- W! @ ModSecurityConfig modsecurity.conf;4 U7 ]7 F( \9 W( h5 q
+ u4 T w2 ^1 b, I1 m root /web/wordpress;
( b( N: K1 N# K# g" g index index.php index.html index.htm;7 \% c/ X: e4 T7 X( o2 m7 R
8 N0 O/ d7 N7 L' \
fastcgi_pass 127.0.0.1:9000;
9 }; i" V% N/ V2 X fastcgi_index index.php;
7 n3 T. l. j$ Q0 ^. \; Y4 a fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
2 G9 N/ |/ z. v! N1 m2 S include fastcgi_params;
) X7 ` f6 W+ b) u. O+ \ }
" [0 s5 _" Q+ {0 M3 \, d }: m0 K/ Z$ M9 T6 `: c1 l
upstream负载均衡:
% } b2 J* A7 L; J: c$ C$ R7 y# K2 y& v3 i
upstream 52os.net {
: a# f) A" W) P server 192.168.1.100:8080;- W4 r! ~* m9 n; S3 G
server 192.168.1.101:8080 backup;
- Z" j: m, {9 Q" C}9 G1 N$ w& z1 I" ~# T* J. r- ^
/ a7 C$ ^3 O' z7 `+ H2 g
server {
" \! I: `# f7 G: O \listen 80;
" d# x7 ~$ B5 R/ J2 P) ]1 }server_name 52os.net www.52os.net;
. e# `1 N8 n0 c9 Q
% H: Q" \, J- xlocation / {8 X' V% p3 A% Z0 ?( F
ModSecurityEnabled on; ' t s& W) \; w1 o
ModSecurityConfig modsecurity.conf; ) {" p9 o* p9 ~ U+ c8 b
3 f. n% _* ]) ~3 T
proxy_pass http://online;" N- L. i% e& s5 O7 T$ I! G! s
proxy_redirect off;3 ~6 f; Z/ a4 J2 e9 R; |: L' I0 ^0 w
proxy_set_header Host $host;
! \+ ?8 m- h; G, u6 E% O- b# M7 D* C proxy_set_header X-Real-IP $remote_addr;
) ?0 d3 u* D F1 e8 D3 g proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
) h, b7 _( [& ^# {& p( H, V }
3 ~; \8 l8 L4 r) G& B}1 U# R" j; r5 n: Z3 O5 N8 n
六.测试
7 t" [3 y" ], T- ]; v) C# g5 r2 U: ~& f" y+ M1 N: C. {& p
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
' W$ d' k6 s! Y& V. c- W* D8 q" U- e7 s8 a
<?php( S/ n2 C% G4 p6 V
phpinfo(); 0 _% ]; D( K/ F9 T7 `+ d
?>
2 p- e, q# \4 ^% g) X/ [在浏览器中访问:2 I' `, Y ~0 G3 S+ E3 N; x
/ ~7 ^2 z( G; Z
http://www.52os.net/phpinfo.php?id=1 正常显示。/ z+ h. _0 L$ A( c E4 o. n/ k
http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。, d1 P4 t# D' }; Z
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。2 z! F" H, F$ h8 }, @5 c' u
说明sql注入和xss已经被过滤了- K. c1 d5 n' {7 w' \! p( w
9 B& g0 |! a Q9 V七、安装过程中排错7 q+ C. R6 @0 G" m6 F3 H
0 x$ w2 u4 \/ C8 p
1.缺少APXS会报错, w4 E9 c. X; }) ]2 W G! d
% S3 Q1 x7 e5 Z* x- F* Y/ s
configure: looking for Apache module support via DSO through APXS
# i, s" M/ r, L. Z, Gconfigure: error: couldn't find APXS
$ y( f2 O% c, `6 q( vapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
" j' u* P( R% l4 R5 \2 \( F解决方法:
- t) T9 L" S8 {8 l6 R# B$ T5 H. N+ z ^6 T6 R4 X: J7 t
yum install httpd-devel
& ?) ^# U+ e, y# u2.没有pcre# @2 m& s$ R0 g \; u) M2 @- w% l8 N* ]
5 b: T" f4 r! Q0 ~% ^" B7 z
configure: *** pcre library not found./ r+ ~: V4 w( d! n. S, g
configure: error: pcre library is required, v, v7 V1 D1 ]+ s$ k# m1 ~
解决方法:
) b( X7 u' c7 P! n: q' \
# F+ ~2 o2 e5 L l `( q! L3 ?yum install pcre pcre-devel( m3 k/ ^' }) u8 @6 D
3.没有libxml28 \' `, t7 J/ X
: s6 Y8 d' }/ L- n
3 c7 }) T0 G, F" [
configure: *** xml library not found.
6 U) Z, m t) H3 mconfigure: error: libxml2 is required2 l. G0 o$ R; Z6 {/ J
解决方法:
1 g/ y. Q1 Q, K( v, h( Z7 q% B# ]1 i. C" }0 B# \! H
yum install libxml2 libxml2-devel
5 }$ f9 {8 q9 m4 C4.执行 /opt/tengine/sbin/nginx -m 时有警告
5 p8 g1 k* m0 Y/ Q' V4 m1 i; L9 o1 U, r3 s7 {2 b
Tengine version: Tengine/2.1.0 (nginx/1.6.2)4 ^. n/ t6 N t5 Y, O( @8 Y* c3 b
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!5 C g7 r- p6 k8 o& a
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log' w0 T( o1 J9 S& k u @
5 {& x0 Q. H7 j- k! H
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.- }1 j2 F! g: P" o0 D
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"' V* K! t) L8 }2 v) u% H8 T
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
/ @6 ]7 I5 y" A6 t2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"9 b5 \2 K3 Y. j9 \" w Z
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
: w& g; g v( u9 |+ i# U- ~2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
, T- A3 _0 c3 Z. x9 v: F* Y& y5 {解决方法,移除低版本的APR (1.3.9)3 ~( q7 l0 M- H( ]5 x) p' l
/ q+ ^# L8 Z4 c7 k' Hyum remove apr
. J& ]8 F- O# \# C0 H/ i/ r5 ^* ?5.Error.log中有: Audit log: Failed to lock global mutex
) _% { b! T8 C& n2 ?
# N4 U8 B: q/ l7 |$ _9 z2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock . G9 C8 {3 W' n" W, p
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
0 b( f: b ?7 j6 ^* V解决方法:& ^3 E) c. u# n0 V: i( `
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:! i; A" s& M% G4 P+ Y
. ]2 n. f2 W: _& U% O2 ISecAuditLogDirMode 0777" `6 T: l9 O$ \- F- Z7 J
SecAuditLogFileMode 05504 V7 \8 p ~7 f: I$ u3 {
SecAuditLogStorageDir /var/log/modsecurity
3 a) v* X' Z2 ~6 I X# JSecAuditLogType Concurrent) x9 B! N" D" C
参考文章:/ e6 z% `7 c0 z/ o! F+ p3 M
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
8 K, L9 I8 P* B1 H k& x3 n( phttp://drops.wooyun.org/tips/2614 |
|