找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12714|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。: N) D+ Y, k& w3 j5 l# r' e; m) r  F

" C; _+ k0 Q$ l7 h, h一.准备工作( i/ u$ w2 A- _" w7 w+ n7 n6 i6 P4 n
9 _& J% m& p& T, _
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0" b( e5 v! u" \8 t

' ~. Z, B: Z/ g0 [& G& b0 T' K3 @* @+ stengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz9 b, Q; I+ B# h

0 i0 _2 _+ c) m. b! }# T' kmodsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz) Y, `7 D7 x2 b1 G7 E
* u" d! o1 ~( O; d
OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
" T5 M# b: ]) a5 ~' ]( E7 T( c$ Y2 v2 F+ F7 i8 Y( z+ o
依赖关系:
2 g" G' s* F, V# W% j. ^tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:$ F3 ?3 d, q; W! ]- l- g
* r( [4 z+ J  f+ e, o. f
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel9 Y* v) Y5 X+ ~. H$ {" G
modsecurty依赖的包:pcre httpd-devel libxml2 apr
! e" S& f% k+ J3 H5 w$ x' o% P' n' V6 Y0 N8 M/ w
yum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
( A9 Q) z! g3 C/ W' Y7 J" `二.启用standalone模块并编译
0 \! U+ x9 o: g6 l! L2 z  J( J! R1 f' ]4 Z3 E  `
下载modsecurity for nginx 解压,进入解压后目录执行:
+ Z+ _4 Q' l; t% f# |1 U( m+ R3 G0 z
./autogen.sh
1 p  T0 F  v0 b2 H./configure --enable-standalone-module --disable-mlogc( x. y0 W3 P  k/ n2 p8 h
make
% Z# ]! K8 j' p  [三.nginx添加modsecurity模块
! f1 J8 g; z. t' o) Q  w6 l" f& d% G+ a) T5 X
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
  _' s4 Z8 J! a6 v4 }  W  S6 Z( m6 H4 E; c6 n
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine2 F7 S2 _4 s3 D5 \8 }7 Z) C
make && make install
) w$ @+ W6 J* g9 m四.添加规则% w$ t3 C) d; e
+ ]  Z2 q: y- ~: {
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。0 x. x5 A' }( S; I
# B) w* J4 m+ K1 G. [) {
1.下载OWASP规则:
/ G( h- B- w( R' `/ B. E/ c8 [# S# {6 g1 C4 h
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs" q, ?# j/ P! w, @( `' E9 n/ \3 K
8 h. {$ @) L9 @2 S1 |
mv owasp-modsecurity-crs /opt/tengine/conf/
0 y  @+ W( o5 [, x! w6 S% Q& g8 |( p! ]' x5 D' o* L
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf
0 a* j% i# B. w5 H2.启用OWASP规则:% Y! E1 _, y2 _# o2 g5 b* P8 O

: P0 m8 ~9 J& H0 j  X复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。  b) c5 {: J2 m& s/ r
3 ?; U# [: {, Q. @, B
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on. @+ M; H& }- |! F" F

* e+ S  e" f3 o' Lowasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
! x* @% c! y" a9 D. ?; g9 w% }2 O/ W$ [& e$ Z6 }  U% }! s- [
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
) v. w3 }# R. `" H. ?Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf6 @0 s; }8 P& J  ~; I
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf
$ P4 u& F. @' DInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf: i* Z) }/ j7 z/ [
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf) `7 f, A, w* n+ W, M7 b9 k7 ]
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf& w( Y* t$ I5 f* ]
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf% w% s1 y& ?+ a. T
五.配置nginx' r# J6 Z+ N- m0 X5 O' ^( l
; Z, L+ t# }$ L
在需要启用modsecurity的主机的location下面加入下面两行即可:
; s; x% ~" x* l, F8 P( u0 H( R2 C5 }, v  j1 A6 G& k
ModSecurityEnabled on;  
; [* z2 s! L0 J8 d* X) |& LModSecurityConfig modsecurity.conf;
. Y( Q3 Q$ a2 r' _% u+ P+ x下面是两个示例配置,php虚拟主机:
" @  P  S7 v) A) U  a2 {
6 [1 O* w9 m; n* d8 wserver {- F- g8 g& c; |* ]/ q5 B0 r
      listen      80;
6 L5 h2 F: _4 F      server_name 52os.net www.52os.net;
5 g0 n; |3 z) O* e) U% f     , ]: n, m  r/ y6 R5 l
      location ~ \.php$ {
7 f% u) |/ M3 U) Y) N0 ]( L0 q      ModSecurityEnabled on;    U% v- G8 e5 H( A/ ?5 ]
      ModSecurityConfig modsecurity.conf;3 ?) s% Q/ r" W, c6 r) T

3 }& O6 P- Y, J      root /web/wordpress;
9 Q# _4 F  ?- e) E6 }, {      index index.php index.html index.htm;
  F" Q: Y# f" y+ T  0 q- q2 W8 p7 H% b# Z6 d* g! A
      fastcgi_pass   127.0.0.1:9000;
& S: G. |  w  E8 x: [      fastcgi_index  index.php;
! S5 B: I' u4 I" G6 P      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
. H) x' Y! @6 r      include        fastcgi_params;
/ B9 `: `. W( f, N      }% N0 c. i% T! r& a, z
  }
# g+ k; {0 a; I% k9 Pupstream负载均衡:7 Z8 U" e4 y! Z: h7 ]
2 ]9 l: r( Q4 A1 {
upstream 52os.net {
5 l/ R4 o' |& ~5 `/ J9 V    server 192.168.1.100:8080;
7 @+ `% c% O1 U    server 192.168.1.101:8080 backup;
- t( h" m* P4 `* [6 J/ q* {+ H}3 F2 |# v' ~5 ]

$ \' w$ B3 S6 V1 i* Hserver {8 y, Y3 |+ R; ~0 P$ T' [3 N
listen 80;; e7 }% I; w3 ?- X
server_name 52os.net www.52os.net;
3 m4 E* _+ b7 e- p) Z" a, k1 c; p( [9 ]- |  y) j
location / {% k8 ~& Y& o) @# [* ^
    ModSecurityEnabled on;  % S( Q) M2 S4 Z5 v
    ModSecurityConfig modsecurity.conf;  
% I* Z8 B6 K9 |, h/ v! X2 ]
6 M% l0 k+ J$ O4 N0 K        proxy_pass http://online;+ ^* h) D) M  J/ s
        proxy_redirect         off;; m0 K& K4 p* f5 s
        proxy_set_header Host $host;
/ t/ V! U- r' E& o; H; c$ `$ i        proxy_set_header X-Real-IP $remote_addr;
( @( G# V9 N% ]8 J  F$ l$ J        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;% o* U* t% {  }7 j" K* V/ a
    }/ g, G' n* M4 d4 M
}# I+ H+ c8 i2 W+ V+ E8 J  t
六.测试
4 P% |- x. B4 |, Z* Y1 f* R# N  {$ U6 q
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
  @' V9 O; E, b  \5 Z6 w+ I# Q" _# q* ?, ]0 Y, h. h
<?php7 K' G. D4 [0 V  \/ j9 Q  e
    phpinfo();    2 A) L( B5 K  v  j! p% g
?>
+ ]9 N+ a4 N( S+ a5 Y- l% P0 }, C( `在浏览器中访问:4 o7 i6 Z& X% O' M" {* d9 S) b$ Q" T

9 S$ t  B. }4 bhttp://www.52os.net/phpinfo.php?id=1 正常显示。9 _1 j5 Y  ~9 l& @+ {, `2 H, D2 T
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。
6 R4 D3 J1 n" L+ {6 Whttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。
" k' K4 \% s  E说明sql注入和xss已经被过滤了
& f7 o; j. W/ t6 s" g3 s8 g$ m. @9 ]
) z' n. C: v6 G- h  x七、安装过程中排错
# Q' p8 n/ J5 @5 \; Y/ E' @: Z+ U
1.缺少APXS会报错: @/ l8 W- t" e( j2 \6 j* X

$ D7 v' ]9 Q* M9 X& b* ~$ cconfigure: looking for Apache module support via DSO through APXS
0 I( ]: z. W4 K* e) X! C7 V1 dconfigure: error: couldn't find APXS; D* B9 D2 v9 J. _0 d# v' f9 F
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。5 b+ r' C9 g& _1 o; o
解决方法:
' |) L  K( G6 |/ i7 @3 o0 J+ p
* D0 m( l+ U7 `) u" F" M7 h" Hyum install httpd-devel
, u5 W1 ~- }4 i4 |: `" e4 ]2.没有pcre
! n$ K- M2 N! @, |; b$ Q9 H5 A, V6 t. L1 H$ t) s/ {1 ]+ l/ ?; t
configure: *** pcre library not found.
( O7 u5 N' g% `+ I3 K/ hconfigure: error: pcre library is required
2 u- b3 s1 d3 {/ |* n2 f解决方法:
  h+ ~) A5 V0 n) u7 X& q
$ |, M/ ^, g; j" H; i/ }8 kyum install pcre pcre-devel
2 r2 _0 |- i( Q) v4 B3.没有libxml2% U4 o0 ]3 O& u$ |6 E- z0 I" r

6 r: ]! j3 q  _6 r3 p' y0 ]
1 {+ }" V. `5 d. t8 d. r& D8 bconfigure: *** xml library not found.
* V# S3 O4 W0 S. a3 ?) aconfigure: error: libxml2 is required- e0 w3 a  I  L3 Y, j
解决方法:& E4 X8 R# e3 E4 R1 e5 Z
: x8 ?( M7 ?4 b/ u5 s
yum install  libxml2 libxml2-devel
& c+ }; L: U3 N. ?4.执行 /opt/tengine/sbin/nginx -m 时有警告& D$ c& }( |; H( ?: r

/ B2 b) I/ j8 x6 v) T7 XTengine version: Tengine/2.1.0 (nginx/1.6.2)1 q2 O6 `8 f0 _9 @9 \
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!
2 w( f4 [- i! D& V3 d原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
- C9 I  L2 Z" W- e# j% b' s8 U! D/ @5 H+ ^0 H' U4 r
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.' k5 x: M  e  |" @
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"& n$ |: _( {6 H/ z* M
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
0 m) @% O. f8 S% i4 W8 {& w$ b2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"7 t+ K& y6 s; [+ i9 b8 e/ V
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
5 X  m5 F/ o% o5 l( C' E9 _2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
0 l) b/ C/ f5 T& M; o% U解决方法,移除低版本的APR (1.3.9)) A+ |- B0 s+ D% l) x
. O1 |+ V% x5 q" }0 f) i
yum remove apr$ Y' B% g  ?& @1 q8 \3 f% G. }
5.Error.log中有: Audit log: Failed to lock global mutex2 T/ B4 l) E" a

( L( x4 A  c5 X7 d/ R2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     # J' h  y  a" C
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
. w+ d; r( k6 d, y7 B$ {解决方法:2 B7 l, B; f' u4 Z
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:( Z# H. k- L: t: R3 a0 b* D

9 ]. M' r- q& `; v5 \0 CSecAuditLogDirMode 0777( u0 I9 A. A2 Y5 N' D  C8 I
SecAuditLogFileMode 0550, ^) \' r% _2 z  B- f
SecAuditLogStorageDir /var/log/modsecurity
) ]( E) t) h- J  E% x; v- L5 ]SecAuditLogType Concurrent
8 V6 R+ W( v2 B) u: `. w参考文章:9 c9 h0 _& H. U: Y( j9 c% y) V
https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX% ~8 m' [! L1 e! R" U
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-3 01:57 , Processed in 0.069063 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表