找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12705|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
0 L9 Z1 k4 a) p9 e' K) }: J
& u8 X2 _$ c0 |+ n. s4 K一.准备工作
5 M- z1 [; ?  P" ]9 g
) I/ h8 g8 k& w7 M# r; n6 s系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.07 v  S, |2 B( w1 V8 [
$ J% S+ v3 v' @7 V! H
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
! j# J- D  P& ?+ A0 l- d) m9 E
9 ]8 K, s1 ^9 G8 T  K6 ~modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz& `# ^2 h0 R/ {5 S6 g
3 @4 f# \  e, J1 W4 r: |0 L+ w9 f
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs. j; R; q! f9 i2 b  ~
" r7 o  e* v: D3 h, l/ J
依赖关系:1 w3 w- z* E8 Q
tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
& ~  V) t, W! j, K  p6 C8 G% `; H" h" j6 i  ~' S
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel
1 R; M2 q7 f, P3 p0 V+ Y% g' gmodsecurty依赖的包:pcre httpd-devel libxml2 apr
; u3 g# |! J' a; n7 |* D& S! _
1 s! g! K" m) Y$ Q2 Hyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel8 J1 A& Y) |+ C  W: K. S
二.启用standalone模块并编译
3 e$ P$ A- l/ E: F  l
  ^6 U; W8 ~" a& U9 A下载modsecurity for nginx 解压,进入解压后目录执行:& v. q& A# f' k& l/ p% b8 G

( T; {: \$ U0 y6 V7 ?+ C./autogen.sh4 t& C' n2 r3 I: J9 ~: D, K
./configure --enable-standalone-module --disable-mlogc, c) d& G3 }0 Y! c5 M
make
' n0 N2 Y* ?1 [, D! {0 \三.nginx添加modsecurity模块& ~* q' b& _# B% q/ e% I! n

' d* m, s8 V5 _* {; U; Q9 |在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
. _3 O4 {, |4 }7 t3 F/ {) _- I& u; r' C1 s
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine& r1 @4 r8 `6 @; ?5 k+ ]( y
make && make install
$ m# G$ \4 a' \# _" J8 Q7 c/ n四.添加规则
6 [" u/ A* w3 v/ `6 w5 N3 }
/ _% `8 Z' n, ?3 W; Qmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
) z/ P; o0 V: J& e0 v0 V* W2 m- I2 p& m/ v) i2 @7 n3 b
1.下载OWASP规则:
7 Q+ A  E  B/ B2 q
/ d2 n. S2 y' \) }. o# @git clone https://github.com/SpiderLabs/owasp-modsecurity-crs9 A& H4 r& W" a1 W* T' P! W7 K7 \

: L& m4 S2 V& Fmv owasp-modsecurity-crs /opt/tengine/conf/
6 G9 `, O2 h2 Y2 E
4 \7 C" V2 t6 `$ {cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
3 L* B. d& z& }9 c2.启用OWASP规则:
% N3 X" u0 e$ q, s# o, E( m! b6 e7 x9 l8 F' a& F
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
. S( R  r/ w" D9 L
3 v% J, v: S7 T  l7 W: _- _7 u编辑modsecurity.conf 文件,将SecRuleEngine设置为 on* R) {9 u4 p* d% I# s# q
$ p  Z# i& u4 [% g. C) P% O
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
! F7 D" J) x4 N, e3 G9 Y/ o
2 @1 @8 s* _; n( q1 d" JInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf- N1 Y9 n7 E& X
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf- {: ^* k: L0 ^  s; S; H: U3 @
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf6 y0 y- r5 J. L1 K: }) u
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
# w6 H+ i$ u' @* r3 J% H/ QInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf
2 }! F0 C' L3 F5 m, ]* k; EInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
4 ^% R) y& g7 b0 l. }) R% o" ?Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
% T% D0 Y" v1 g& f: N, ?五.配置nginx* D# j* ?' Q; _

; A3 |. u$ Y( K在需要启用modsecurity的主机的location下面加入下面两行即可:( @0 `. e2 ]/ o, g- M; n2 ~" @

7 p" ]; X0 ?: K6 PModSecurityEnabled on;  
% H" m% D6 s! @% {ModSecurityConfig modsecurity.conf;" U  ]' _) H/ r
下面是两个示例配置,php虚拟主机:
/ i3 n) u4 ?; ^- z4 u4 ]8 L- E2 f. O" N9 G9 ^# R
server {& F7 y( y8 {# E
      listen      80;! H8 Q: `/ }/ a5 T1 V% N
      server_name 52os.net www.52os.net;: _2 Z; H- f1 S
     
7 M9 t$ @2 k- n  ?, ?! O& r! D% |: w      location ~ \.php$ {# s0 ^7 f- a/ M5 R: Y
      ModSecurityEnabled on;  
6 V- T1 w0 B; _- ]" m9 T      ModSecurityConfig modsecurity.conf;
9 n+ [% W0 Q, {+ k9 w$ {' o
- ^7 Z, x3 d$ \0 K" v% ^& Y      root /web/wordpress;
" M8 J; j7 d+ u. A+ F      index index.php index.html index.htm;6 k& C5 w2 s( K3 ~
  
5 e3 j+ P" b+ V( N. b& \3 H      fastcgi_pass   127.0.0.1:9000;8 w+ r5 d+ Y8 E. g  `7 J, h4 K0 N
      fastcgi_index  index.php;# J# P8 ]( Y/ L- `; ]2 `7 B5 i
      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
* O# M* k! P& o& V- q! Y6 l! p* @$ h      include        fastcgi_params;
0 N: h" g4 J  m      }
9 S' |* j3 J+ W' Y  }
% ~& [8 P1 A. A# e3 g3 aupstream负载均衡:7 o9 \' G% n. G
$ t# p3 R, m8 d6 r/ j$ D
upstream 52os.net {* q6 _4 s& ], a" C$ K" f# {
    server 192.168.1.100:8080;
, r2 _7 j0 U4 d! x6 U& h9 q8 N- e# t    server 192.168.1.101:8080 backup;
& e# J  _1 E! y6 z5 {4 o6 D# b}4 B% s) l% |8 R) y5 d% Q# u3 I* l

- e: z' H, ~4 U8 R7 |server {$ Y8 c- G9 V9 H/ a/ n
listen 80;/ r# ?" ?* Y7 B. X0 X3 x
server_name 52os.net www.52os.net;3 l) l7 V, E! w$ I, z5 c! v
0 h' V9 g) L/ g. t2 d) E7 M
location / {2 [6 W4 {  N) F4 r) G
    ModSecurityEnabled on;  5 i+ x9 C9 B8 K8 {
    ModSecurityConfig modsecurity.conf;  % `; k; {+ M; s: O2 n
5 k2 {  Y; {9 [
        proxy_pass http://online;8 _! f$ @9 P; j- K2 x
        proxy_redirect         off;" u2 @/ o3 w4 i
        proxy_set_header Host $host;5 M1 O/ |: d- J4 K1 V7 b
        proxy_set_header X-Real-IP $remote_addr;
  H( o" E* }7 ]        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;$ d% W* y1 V4 O. I, G  i
    }
3 M, [( ^# N( U) a}/ F3 }$ i& [1 [( d; I5 Z
六.测试
+ y+ _% u  E( Y, Y7 \  H
/ \/ Z/ I+ F8 g7 i  D  |4 I我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:* \6 M) N) r7 k' L# t6 A! f  F
8 z+ j4 r$ _: Z8 k' X( e8 m' p
<?php+ v- [: f4 S$ z# B5 `, s2 V; r) p
    phpinfo();   
/ u' D- f! c3 ^* t3 E?>& K2 I. d3 k0 z* J
在浏览器中访问:. y2 d7 y, E  U6 M' U0 R2 W
0 D3 e) I4 N) {5 e4 S) f* ?* p' c8 V& m
http://www.52os.net/phpinfo.php?id=1 正常显示。
/ \) m$ D) V' q& jhttp://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
2 J# W6 u7 E3 W6 Uhttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。7 m; H1 D+ m. R. ~" V( c
说明sql注入和xss已经被过滤了
9 b, S# M1 \" {7 n% T$ R
; q6 N2 S& M; t* X' B: W0 B七、安装过程中排错
" \8 R# Z3 j, ^- u7 X; X
! A9 B" f! z9 K; _1.缺少APXS会报错1 ~8 a. j* q" l# U# H8 Q/ H
- v% v- m& q6 ?7 |: y
configure: looking for Apache module support via DSO through APXS$ X) d' j% B7 U" `7 d' ]9 G
configure: error: couldn't find APXS
( k$ Z7 N- t. b( q* Japxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。0 R4 d* e+ V, R( Z
解决方法:$ ?( ~9 b4 Y1 w+ {2 A4 n% T. @

& B* F% v9 D9 S, U/ uyum install httpd-devel
) o: d3 b! F4 O4 @2.没有pcre
- B  i+ |) R& d, {3 r7 a& w0 k1 ^: q) b
configure: *** pcre library not found.
& |1 n& p& a3 ~) w! H; o9 Nconfigure: error: pcre library is required
1 x# Y4 o) s2 a; ^2 s% |解决方法:8 `6 g6 w3 S3 A

0 U' }4 k" F' e3 F; syum install pcre pcre-devel' H" ]$ N2 I- z/ u9 m
3.没有libxml24 `; c5 y3 V" P& d( r
2 `/ K) k1 v; b  r0 T6 r6 f

6 S1 \  f1 E  \" R: u+ Qconfigure: *** xml library not found.% W, K6 U3 B- Q  M( d* p! i. e2 Y* U+ t
configure: error: libxml2 is required" b  \5 I, x4 w) X8 Q
解决方法:# |/ L$ s( o9 z0 T. e5 {1 T
+ j% m# x, D2 b0 o" z6 e3 G
yum install  libxml2 libxml2-devel
9 z3 H, S# s! }1 X2 k% B! m. p* g4.执行 /opt/tengine/sbin/nginx -m 时有警告+ {: Z/ {9 I) X/ Y  H

# j+ C5 N% _9 N3 k# _! rTengine version: Tengine/2.1.0 (nginx/1.6.2)
+ d/ a/ m" M( h* I2 Q* ]$ {nginx: [warn] ModSecurity: Loaded APR do not match with compiled!. I2 A+ X* j3 E# }0 z
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
/ N. m  B9 l  d" l+ t3 _' I* ^5 D4 Z) Z" |! s! r1 B
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.* N$ ?8 {" x8 v& G& q
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
$ G5 o% y5 ~9 r' R' }  |0 y) n0 X$ T2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!" T, e5 {1 x# S* ~2 w, j* j
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"7 ?+ g' n3 K: O4 A0 ?) E! U( m' b
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"2 Z( ?% h0 D9 _$ h2 E7 f9 X
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
# i5 @9 l4 t" s4 ]解决方法,移除低版本的APR (1.3.9)3 i  c3 ]  P" P* x4 k
* U& a+ h  N3 ?, G% r
yum remove apr
' u, T% y' R5 ?/ L7 e5.Error.log中有: Audit log: Failed to lock global mutex6 L" t; B- h( w6 l: c* ~

  L3 K5 R9 R; H- `2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
8 z1 I* Q& Z9 V7 bglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]: c: q$ L* n  q3 g) A8 o
解决方法:9 W- n  {+ e+ L  F1 @
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
! n  s' V$ }5 [
+ o& R7 s! q. g4 @$ E$ r3 c/ q( ySecAuditLogDirMode 0777
! b! v& [: W# o. _8 |  G& A  U  ?SecAuditLogFileMode 0550
+ E/ A  b" v0 f, c9 G& @; jSecAuditLogStorageDir /var/log/modsecurity
+ Z" b; E" ]# d& r7 _4 wSecAuditLogType Concurrent- A9 g7 z3 B* ^9 t; P: i: x1 m
参考文章:
5 u) E9 Y- S# L' Thttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX2 r1 i- J2 v( S
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-2 09:31 , Processed in 0.058015 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表