|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
2 J1 K' K" g5 X0 E/ ]- [, s, f7 ^7 @% \7 E4 a! A3 z" U
一.准备工作; S) \+ m" ~" q d8 v
5 E: V& J% ~* L系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
9 Q: R/ t; A% x/ i6 q3 ?- X$ N! _# y- S$ S. m# J' E. w
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
: _/ \- w- P1 |9 q
( y" K5 V, n; d4 @. Hmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
1 W P: x4 q1 s# }0 r7 d* ]5 Y2 E( j5 G. |- H8 S- l, C! a
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
: k+ k. L. K& n
# E2 \0 Q. N% A6 n" w5 ~依赖关系:) W9 o/ w/ Y( |( N3 b0 w7 K5 z
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:3 K" F# D3 `$ F
! \9 t/ w: z! g: A$ M. J5 [# M9 Hyum install zlib zlib-devel openssl openssl-devel pcre pcre-devel5 r& J6 |% p3 k' [
modsecurty依赖的包:pcre httpd-devel libxml2 apr8 _$ ]4 W+ J4 d6 U! Y& D1 X, z4 U# E
& {1 |, |% R9 _) e5 t
yum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel, u$ m1 H- K( D$ J i- b) ^7 O
二.启用standalone模块并编译 O: n4 N( T( s8 C7 S
. J: W F0 ]6 ~# |8 W& z下载modsecurity for nginx 解压,进入解压后目录执行:9 Q, ~* W+ w& Y/ A& b/ S# e. H2 A
5 k0 Q2 _) O, S9 Z6 L/ ` w% t$ G./autogen.sh
6 q7 O% N" `- x& A./configure --enable-standalone-module --disable-mlogc
; l( A- `" w, d$ n$ _make $ |* a, |1 h$ ]% B$ ^* y. n& D: o
三.nginx添加modsecurity模块
5 P4 T! W+ F) r2 K7 O, ~: y( _: w3 g9 {% a. Z
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
6 b' v; _' O4 v6 C0 t2 G% D m- s' V( v8 S' |4 \2 s9 S B
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine
9 B- s4 H( T" H* {0 nmake && make install" G$ v" \0 ^9 u# n' x
四.添加规则9 i" b$ E+ F, G7 X! X! d
1 Z% y: w* |8 B& @! ]( }8 B
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
4 }! c/ ?3 I( ?- g- u
* l& T3 G7 V* L, _6 t1.下载OWASP规则:
; D7 u6 e) D& M) Z! r1 T. A9 j; L& L: g, P) l
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
% k2 p$ _" o/ H" h3 i4 Y# l& ]+ ~3 V
, `8 }- g& H, z; i% x- \mv owasp-modsecurity-crs /opt/tengine/conf/2 {9 z, m3 \ H$ |' D7 K
0 g) c* w+ Y. O$ u2 q/ U
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf4 l9 I' ~( B* n9 I1 r. T* [7 w
2.启用OWASP规则:8 h$ Z+ U, |, O2 Z( z3 i
3 ?( E' O3 U! ]8 A S, i1 L
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。1 s; w8 I+ u0 X) ^& z2 H, I* N
B# T& l% A1 [7 j w" [
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on
5 @( ]; o+ W. m+ h/ O8 b$ T7 p6 o; y+ X! n
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
" }0 x- u" b3 L
/ ~" u+ E5 S5 s+ N+ i( GInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf8 T F/ t5 c/ X+ y
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf/ g/ ^0 U' X8 `* X% w
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
8 T6 y( k) X* p: OInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf7 R7 Z" e1 l( y( g4 q2 W- i
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
! C. k5 \% V! e6 x+ j9 uInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
" e# E5 b4 f6 X2 dInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf. i7 D$ o4 c% t# ~/ V/ ^# Y
五.配置nginx
( n8 n& Z; e* ]# K" h- x( M; @7 X1 z
8 k5 R5 k7 z* V& M: P! \# _1 U: E在需要启用modsecurity的主机的location下面加入下面两行即可:
( Z4 d5 [* Q. O+ G7 n# p/ ]+ \5 [
ModSecurityEnabled on; ; a. {$ y/ X& c, s5 l
ModSecurityConfig modsecurity.conf;
3 u4 v1 l, B9 p6 C, C4 g下面是两个示例配置,php虚拟主机:6 w* U& J9 V0 b
5 X. _( A* [# G1 C4 [
server {
1 k- E& |6 \7 d F( i5 a3 P listen 80;" N9 e1 F# h* ~, d1 i5 c4 e* t
server_name 52os.net www.52os.net;! G- H9 H( T3 O6 N" j i" i
/ v }; D! P; ^
location ~ \.php$ {1 y/ h/ r6 w) M! O7 r0 s
ModSecurityEnabled on; ( H; A: Y: K' x! e' X
ModSecurityConfig modsecurity.conf;& }+ m; e) z4 d4 }# E9 A1 n0 t
+ q7 j1 F. \; c root /web/wordpress;6 ]: L; ^. z% P
index index.php index.html index.htm;( G7 b: H, `' o d* d3 E# Q L y
! O" D% o- v2 W* n1 S4 m fastcgi_pass 127.0.0.1:9000;& a$ }8 P+ h# o3 O
fastcgi_index index.php;
& e/ P( `' J/ k# _- u; ]1 A fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;, p Q* v: U% R) y. f/ p' C+ Y. T, e
include fastcgi_params;2 g2 C; V: T4 c
}
- K7 a& \0 v" m* j+ v# M }
: X1 q' i( w4 q' n; `' t& {" Mupstream负载均衡:2 L9 n, B( @% A
) N, \. t6 h) r1 N
upstream 52os.net {/ F8 \8 C0 c9 d+ v" s
server 192.168.1.100:8080;
2 Q3 \$ P4 ^- E5 }0 u: ~% \2 W server 192.168.1.101:8080 backup;5 E5 o' h% X+ t
}
7 W7 s% r" [* M9 |' ]
5 [" l8 k6 [ t* b. Zserver {
V/ l! S7 L' e7 G0 j6 ? h" a9 H# Jlisten 80;
5 d' f( W( T- R9 N/ bserver_name 52os.net www.52os.net;
7 N( K7 b+ P$ m7 ?" d4 z m: e# H- ^: g6 q
location / {9 f+ B& q ]& T! y
ModSecurityEnabled on; % C! V2 o& w4 ^ G, z0 l- ^' c
ModSecurityConfig modsecurity.conf;
. i# V/ g5 a1 I( Y7 i8 W5 u# g- B6 Y5 z, I! t
proxy_pass http://online;
+ A8 X1 W$ k% C4 e, \ proxy_redirect off; H( X A$ K8 o9 X% i
proxy_set_header Host $host;5 Y* U, @0 ?- Q; K. f9 _; H
proxy_set_header X-Real-IP $remote_addr;
* t4 i B8 [ M3 K) e G proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
9 A4 y8 R- b6 J$ h& w }
) F7 w* v* G& c}
( o1 }9 c- ~) Y1 B2 U; a六.测试1 g1 B/ X, I1 o& y3 h
9 u- Y6 b9 z. P( S9 e8 p% {/ W" Y5 y我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:3 J0 N+ w+ r; x6 i- y& P& ^
# j: U# O9 O% `# R<?php
& U Q, R+ F0 x a) i+ E phpinfo(); 9 X: z5 Z2 w9 |
?>
6 E! |9 ?: ~) Z) S% J在浏览器中访问:
* n# g0 r7 N$ E, v8 T$ p+ Y7 Y( |) Z* }* b q/ }4 F1 O# m' P
http://www.52os.net/phpinfo.php?id=1 正常显示。
7 L0 r1 Z% E @; t9 c6 _7 [* ~$ |http://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。0 o% Q" a v+ e6 x8 o: ^6 O0 f0 }
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。
* `) a6 U0 U+ C. X! i- l1 @说明sql注入和xss已经被过滤了
8 o, r) q8 D- r. z/ H
% _% H7 J! k( ?+ F. ^4 y# i. Q七、安装过程中排错: m4 M! l, F5 f
/ a5 w+ N/ S2 E* W: ~0 P$ N, P. e1.缺少APXS会报错
5 ^" b6 d; e6 O" ~) ?+ O. } a: u" b" j, k0 L
configure: looking for Apache module support via DSO through APXS8 w& j) F0 k* p1 a+ N- A
configure: error: couldn't find APXS
, t; O V+ @2 `; Z4 H3 h2 h$ O* p9 K5 Fapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。
6 t, ]6 T; N3 f0 c* l解决方法:, w/ J) Q. `( }* R" Z3 ~
% b; B9 w: K* E U' R( I
yum install httpd-devel
! W, B% F' z5 a5 Y$ z2.没有pcre# W9 a9 Y5 ?- B) R# U9 D% L+ Q: @
! F1 b1 o! x/ N9 i$ g
configure: *** pcre library not found.
, k/ p3 _% Z. K. Rconfigure: error: pcre library is required
/ @: I4 m4 z5 i4 P解决方法:
# R# _/ F( ~% E4 u- y5 g: M
% q+ Q1 q( U9 @yum install pcre pcre-devel l5 v4 B D' H9 V2 _6 @2 s4 H2 A
3.没有libxml2
& t3 |0 }5 L0 U. U( C1 J2 V. K8 M) q, N. D0 ?4 r) N* Y4 C
7 g% ]0 C* J% H6 g' M+ Q! D/ w
configure: *** xml library not found.3 k% h. m1 Y. A; u, p& F
configure: error: libxml2 is required
6 H- H, E( ^+ _! K4 A/ s解决方法:# t) N% X2 i. X9 H
! W. s- ~" g6 \9 D( l
yum install libxml2 libxml2-devel
9 x, e" Y3 o- y \7 t2 T4.执行 /opt/tengine/sbin/nginx -m 时有警告, g$ y+ i0 l8 K0 H
: n$ l0 Z7 i* s: S4 l4 I5 BTengine version: Tengine/2.1.0 (nginx/1.6.2)' _8 c' y5 s$ O0 e+ }/ b( R9 U
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
; S2 C9 m2 v. g; b( p5 b原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log& J0 K3 |7 `: Q: I, D8 b" ]# V6 m
+ e! g0 o$ w; C0 v! r v5 B' }2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.- G a; P6 r' z* z }3 }4 i) r
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"/ ], ?0 {2 i- c+ ?- m& b, D0 x/ A) i
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!" n- v# J: K" n w4 G3 z( V
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
" O; E2 u9 W+ N/ o: `2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"$ W" Q9 i9 [3 i* ^$ S4 f' j
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
$ n2 n/ ]6 y1 k* f6 |/ q解决方法,移除低版本的APR (1.3.9)
; G W9 B; G, e) N! ~: `" L5 t; Q: k5 @/ u
yum remove apr
$ r. ~8 k6 D6 X1 [: L1 ~* S5 K5.Error.log中有: Audit log: Failed to lock global mutex
C0 G G6 o) J3 R' ]( G& N/ B5 |+ ~4 D; I, Q
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock $ ^! g/ j) z$ g8 C8 f5 T, S# Z% w
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]7 [) C7 o* T9 u) ~+ S" K+ i$ ?
解决方法:; t% v5 O8 e8 F
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:+ T, [2 r3 e" j3 t. |, f
* C" O4 H; v$ bSecAuditLogDirMode 0777
- V: K' q4 i! K, `SecAuditLogFileMode 0550
. \! o8 C3 P5 G, j7 n O6 PSecAuditLogStorageDir /var/log/modsecurity
0 s( F' r- j0 t$ {( cSecAuditLogType Concurrent5 z& f3 E: ^; D. A. }
参考文章:6 y- p2 s3 C+ S& f- I
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
5 J; w/ L5 D# q$ Ghttp://drops.wooyun.org/tips/2614 |
|