|
|
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。' \; ?7 m$ `& T; _" H1 G
2 v' f+ V3 X0 }# K- s一.准备工作, L# H% p/ K8 W7 m
' R& x! H" d/ H J1 s% d系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.08 G! J# ]+ J" _5 s4 d
- o6 F: f: H% K( ?* d1 _
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz9 \6 h U( ?. B; o
: j5 N2 c) z+ M1 e
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
1 H& o9 \' K+ ]7 a7 [9 q- O
" l$ d4 s8 H8 m% S+ Z; r; \OWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs$ H; B) s7 k& T
: D: b' Y! \! i: ]" I4 `
依赖关系:
5 a5 ?% W2 d7 j! j8 X! V9 Xtengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:3 G B" } R B$ \
) u5 F6 J/ p5 I8 s7 I9 e+ z6 u N
yum install zlib zlib-devel openssl openssl-devel pcre pcre-devel
8 x( a8 E0 [/ C$ {# u' f% Smodsecurty依赖的包:pcre httpd-devel libxml2 apr
) V2 L0 n, j& `1 A( ~
" t# H) j- e! P$ g# C- W* ]1 Vyum install httpd-devel apr apr-util-devel apr-devel pcre pcre-devel libxml2 libxml2-devel4 M+ e& j/ f0 a: r. i2 C
二.启用standalone模块并编译
+ \; g# s/ {& W( }' U
. Y6 r: [; M c. }4 p# z" U3 a下载modsecurity for nginx 解压,进入解压后目录执行:
% H( S$ c n i2 b/ {" C
6 B! l& t7 b# `' x/ \, N./autogen.sh) @, Q, R0 s; `# T1 ^
./configure --enable-standalone-module --disable-mlogc& I; k( {( l z: J$ f# n) ]
make
C6 W3 _! P) H% |: l/ X: a! z三.nginx添加modsecurity模块8 @4 f) i4 ?$ V O+ _% {
/ g$ R2 @7 V$ \8 P
在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:* K5 M) X2 H7 p0 L; S. X
. O, Y' V" g) a' y. ~% d. T./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/ --prefix=/opt/tengine3 v/ Q* R! ~% \0 e T ?: b- a
make && make install
" u( E- I2 r4 D" u( x i# @6 _四.添加规则5 \: }+ K( T, |- K; Z8 ~, j0 k) l
& I2 M: L3 J0 c( |6 f4 ?+ kmodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。# k8 `: h. D+ Y4 N$ w! K
$ ?5 g" W1 k* M& b$ L: U+ m3 N& d/ n1.下载OWASP规则:% q' O8 j e" C. u! t* ~, z5 k
9 F5 V+ C& G9 _+ i5 i5 x& k0 ]
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs5 V$ M ]- q# H z# P' Q+ Y
- i- G$ N+ ] p9 K& Y; I
mv owasp-modsecurity-crs /opt/tengine/conf/5 P8 B$ ~. @! Z) `) E/ d! A
" t! d% T4 _9 y( L( Q0 `
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf6 |6 n, e& s% F* c
2.启用OWASP规则:
6 Z; [ ~9 \" s# }& l, `- U5 a+ F' D
. x4 q R% h4 A! P9 h" P+ Q复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
; J# }% {, C; X6 D
( n u! Q, K2 N& F* \4 M# I3 c2 G编辑modsecurity.conf 文件,将SecRuleEngine设置为 on o8 |4 m ?2 [2 R" v: B
0 I* c* e0 `5 c$ C* d
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。' x! L1 r5 [: c# ^- c
, l$ |3 T1 Z* p5 u) [$ w
Include owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
; y: f8 p2 Q1 s; A0 C4 iInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf/ r8 R" V" ]7 v9 R, O
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf- w* n' [* k4 W) `/ {
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf
/ y! F% h+ g3 |% ?8 Z& a( BInclude owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf, ]. F" x# U/ b) [2 S
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf
: V- t% e6 H7 I, bInclude owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf4 G* \' l" d. ?9 A9 r, L
五.配置nginx
" ?1 X& }& \3 R3 m. J7 G! S" p. \ F6 P+ `# Z4 O: w4 C$ H4 B
在需要启用modsecurity的主机的location下面加入下面两行即可:) T- N( b2 c3 {$ }
, n* v9 M; s+ z" A3 N% t5 @( y4 Q
ModSecurityEnabled on; 2 {2 g8 z. h: g! {4 r a
ModSecurityConfig modsecurity.conf;
) v0 R7 f6 g8 [% U: G下面是两个示例配置,php虚拟主机:
+ Z. z3 i8 d; _& J( G& ?" c) W; z+ ?1 M
server {) b; e; P& C: y! S- D* E
listen 80;) T6 ^/ ~, m _" z9 J
server_name 52os.net www.52os.net;' m1 h3 u# h2 t6 o4 _) n
_/ }, W: d0 l, B& ]
location ~ \.php$ {
: Z H# w1 ^% F: C ModSecurityEnabled on; $ r& \! L7 a3 t/ ?8 f+ w
ModSecurityConfig modsecurity.conf;; E7 r. g7 e" k5 l! H- M9 J/ x
* j, x2 h0 `. `3 s7 j+ U
root /web/wordpress;
( S6 ~+ c1 h+ M9 S$ I index index.php index.html index.htm; z" N1 l; Q- M+ p, X+ ^$ [
4 H% H- g& U1 v! W' t1 ?! P' C# K
fastcgi_pass 127.0.0.1:9000;
% O2 n6 ]( v1 _9 s) X w$ r fastcgi_index index.php;5 x4 ^( l5 E0 w" I& f
fastcgi_param SCRIPT_FILENAME $Document_root$fastcgi_script_name;
" U8 ]% B' q5 T' u$ I! I include fastcgi_params;/ q! {( L, V, K' _, ?' H
}2 `% ]5 p/ K U. m$ s+ z" C
}* \* G% M0 k8 S4 Y; D$ f9 O
upstream负载均衡:
1 P3 _' W }8 i% v$ a
8 m# L: d4 `2 ~upstream 52os.net {
, K& I1 W- p+ l I# A6 ~ server 192.168.1.100:8080;
! @, c1 ~3 d8 a4 F7 m server 192.168.1.101:8080 backup;8 j* e* H8 K# q0 V P( q$ P( W
}
7 r* d/ t, g+ `$ S* n
2 |8 Z/ h1 k5 k% l+ Kserver {
7 j: D7 f! V# N+ v% g. klisten 80;
0 S5 v8 h& I. p% lserver_name 52os.net www.52os.net;( _/ ]; V9 i9 S6 k4 t7 u; @# J' `
. u- d9 }8 \% G6 mlocation / {! d/ J5 `8 t. g- v* ~& u
ModSecurityEnabled on;
9 v; q$ P# \0 Y3 a& T& _3 p ModSecurityConfig modsecurity.conf; 4 Y# \# F( J3 X
! t, p7 H$ n0 J( E" C proxy_pass http://online;
# L/ X7 x& J3 J4 B( {9 L2 q9 \1 ?8 C proxy_redirect off;
/ @9 Q! B1 Q a+ @5 _- ?' [! I" r proxy_set_header Host $host;: e/ u1 C' G" z) A3 a
proxy_set_header X-Real-IP $remote_addr;2 Q" e# G) u7 _/ u6 m
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;; f- O( `7 M) B C! k
}" L% b, \3 f) }& \4 U
}. n7 h, e5 \' G& b( A% G/ [# z
六.测试
[0 J3 ]! N, P% B0 y4 t9 U1 Q# _5 E Y2 F% Q+ r) l; t
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
7 |! H9 s1 z8 k, |8 J8 X7 j) \
" R6 c3 i; x( v: g9 x6 K<?php4 n" u% T0 t6 o8 [/ N* |
phpinfo();
' U9 e7 `" U' X3 F: _% m- Q9 L3 |?>
) ~' i5 w6 h) z0 i在浏览器中访问:1 l- S1 }. f: g, W# d! [
' x# |$ t( b o s5 e5 R
http://www.52os.net/phpinfo.php?id=1 正常显示。
* i: p7 c5 b1 C: I- i: Uhttp://www.52os.net/phpinfo.php?id=1 and 1=1 返回403。
# ~; K4 v: y2 v. Q9 N: Phttp://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script> 返回403。/ L5 E8 L3 B) ]9 o
说明sql注入和xss已经被过滤了/ G3 ]/ K- |4 ~: I- Y
: w" F+ P- |8 g; Z3 x
七、安装过程中排错- s' @! d8 B9 W# r
7 g' v' f* V7 p( f9 U1.缺少APXS会报错
/ `( B) w8 \$ ]( q& s
: |) Q f- g- z3 U! \ c+ rconfigure: looking for Apache module support via DSO through APXS
+ ^* @+ _: Z7 Y) s8 vconfigure: error: couldn't find APXS
& g4 h. Z* r1 W7 ~" ^2 z9 w% v kapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。3 K) }1 f! m' N U7 _7 _3 X
解决方法:' e* x' n) @" Y3 [7 `9 k- b
1 M# y! j* q7 q8 q% d7 Q+ m6 A
yum install httpd-devel4 S/ B# e+ O' f4 f( t* Y
2.没有pcre( f2 V% W5 A1 E8 d% S% f
- n- ?6 g# g- \1 H2 a; r
configure: *** pcre library not found.) w( p1 W a2 z7 H6 _4 o, |
configure: error: pcre library is required1 t1 S2 u" H/ E1 v4 r# O
解决方法:
. C r0 H" P4 ]& f o' y% q: P4 H9 Y
" W6 t! [: U, N; qyum install pcre pcre-devel" W4 U# m" S8 Z1 |
3.没有libxml2
4 O* ~2 r# a9 C& q# _, ?
* q) N1 ^! i& l+ j7 _1 g! y% a. ]* i, l
configure: *** xml library not found.8 @6 l: ^, ], U
configure: error: libxml2 is required7 L( p# b* X% K
解决方法:, j6 b0 ^. \* H6 Y! D
% F+ @/ D( a. D: ]6 N) p& O$ k" nyum install libxml2 libxml2-devel" P3 n4 r" m/ d" ]( |
4.执行 /opt/tengine/sbin/nginx -m 时有警告" R! y4 v6 B. b* S* l
1 g2 p4 M: J6 tTengine version: Tengine/2.1.0 (nginx/1.6.2)* M0 U; b' x/ e% I) q
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!4 {& ^7 l$ R" H( l m5 E- Z
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log
) M$ }- G3 N) C9 ?: v
2 S# l0 x r. ]- b2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.0 y( L% E% a9 j) w/ T
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded version="1.3.9"# g% P6 T$ }3 u; x
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!( N/ G3 f2 t# B( z- |
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"6 L/ T1 v2 R; e& O6 D5 `; {, U! {
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
4 c; G: c, i, Y- W4 ?2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
% r. `7 |4 f6 F) T( C解决方法,移除低版本的APR (1.3.9)7 b7 O+ x& q& ^. w7 h
0 n' [; e) |7 i K9 tyum remove apr; n/ [- m1 ~9 i$ L
5.Error.log中有: Audit log: Failed to lock global mutex
- j; G- O6 Z, C9 e2 K7 B; H7 F" q! s
2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock : H) x7 |4 c' B( B1 b- X
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
, k5 ^) L( q" a' j) T+ b解决方法:* J- D N) B5 ~- b/ G; l# U& U; H
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:/ B# d4 [, l8 s2 y2 w
2 G1 I& k. l1 C6 E a- \SecAuditLogDirMode 0777
* W! Z5 r7 P3 [$ S/ dSecAuditLogFileMode 0550
- m4 t! k) s* E! L4 C7 [. e/ p3 w7 q) hSecAuditLogStorageDir /var/log/modsecurity5 e+ T# X$ e5 ^
SecAuditLogType Concurrent
% Z, @5 E& I% P3 x参考文章:
) G- A0 m2 E& \( Phttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX
0 I5 T: l5 C# o- V) Jhttp://drops.wooyun.org/tips/2614 |
|