找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12784|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。% E& i- k2 X1 z4 v' |% L
  n$ I: g* a8 O2 `7 ^* b
一.准备工作
3 ^; I# C* v2 K" ^, Y- H5 i* z7 `1 E! s1 n3 \
系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
  G* {" X$ }, i1 V* a! y3 k) [' t4 U, n3 J+ ^
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
, T$ w- v9 P! G! V. E8 R. G" ?. j1 X7 f: N3 R. X
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz8 O; Z# U$ F: D) I4 P) ^

7 b, x5 C# b! z7 v2 jOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs
- A; `1 @1 C; S$ f" v$ ^6 g: ~0 w# Y8 G$ o; y6 n/ B
依赖关系:
! B! R4 P! n& T5 c! _tengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:7 M' M" I2 N8 }1 q9 |2 s5 d
- a% C0 V5 f" u! l6 L5 ~1 _
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel' f, b# l4 L" z! n
modsecurty依赖的包:pcre httpd-devel libxml2 apr' Y1 a7 s# S/ ]8 a7 p

! r+ \8 C* P$ Oyum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel
5 G1 i. C- S8 g二.启用standalone模块并编译
" [5 [4 Z" L0 i: T, w( R0 N$ F5 A
, o5 ]1 _2 R* i' n下载modsecurity for nginx 解压,进入解压后目录执行:! O. i% ]: D) O0 z& o) Q2 c: k% a. g
! z6 f0 ?- B$ ?$ ]5 c( M
./autogen.sh4 P7 z( j7 d$ x+ L
./configure --enable-standalone-module --disable-mlogc
/ o% ]$ k# u( j$ b5 zmake ( d2 @& v+ U; z1 k* ?& S* W
三.nginx添加modsecurity模块
) Z7 j% u0 M/ U4 t7 D
: F) ^  {+ Y$ a( M, |在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:9 b0 S) m$ f% _( [- J. G& y

* g% p/ B" _& I+ i7 G+ r/ [" y./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
+ M  L4 \+ V! |+ h: B4 mmake && make install: c7 g' G2 d# q6 n/ T# A  I6 h
四.添加规则
3 J" e+ _) F/ |  T
8 M4 E7 q- k, T4 I* ]' Emodsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。- W$ l; Z2 g. z8 G- D2 y/ l
$ o9 D' P4 v! {' [/ H
1.下载OWASP规则:
8 _' ?' p1 }0 d1 A# Q0 o3 q4 T) t' Y: ~* f, Q7 @0 x, u
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs7 @( l( t( \0 p- S
* d! n( _5 K7 o  Z, |- l: T- ?
mv owasp-modsecurity-crs /opt/tengine/conf/9 n. k7 D5 A$ c0 X- q, [5 u
- J7 k/ t' B4 [6 O  \! i1 c
cd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf* H& F, J( z( g: f  b
2.启用OWASP规则:
* y6 `( Q& _0 \3 }( N
* C# \# K; H( s) T0 B% {9 g复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
& g8 C  l3 r5 Y! m) K/ c
! ]: F; F; X! a) v9 k4 x/ D6 ~编辑modsecurity.conf 文件,将SecRuleEngine设置为 on5 H2 ~4 v; ?4 i  t# j
( W( |. w2 T' c
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
# l% u5 F( A0 W5 Y
  L; ^" X9 f, b' hInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
  w& i+ F$ K9 i: ~% nInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf
* I; K5 U  Q. sInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf! S5 S5 h" `9 G8 R6 Z5 v' R
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf7 u( y, ~( s2 Q( x
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf  Q0 h* N/ l4 _3 O& t. |% ?3 G
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf1 h3 S, c8 V, w# t. E  d* u
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf
% z+ E& q2 a% F5 }0 e7 C五.配置nginx
- b; n- @) R$ I6 N; n5 ^" c- c9 c+ S. z9 _( v2 W- H; G  w0 n
在需要启用modsecurity的主机的location下面加入下面两行即可:! t; a# p+ i# E, ]

( Z2 h2 |: t. `8 |" EModSecurityEnabled on;  
. A: v! o, D; j1 z* |6 \1 AModSecurityConfig modsecurity.conf;% c( \/ a& f5 m7 \$ c1 e3 |
下面是两个示例配置,php虚拟主机:
6 I( T& z) F' ^  E2 U) E( ~$ U7 Q0 R, G5 \8 R
server {
) r0 Q1 X3 v! }; J# A& u      listen      80;
  i% [/ I& K. g, v6 W      server_name 52os.net www.52os.net;# j1 m& f- B4 ]7 t. j
     6 |& a9 _' |- [& m
      location ~ \.php$ {
- n4 c0 l' r  G3 r8 k* z: L' A      ModSecurityEnabled on;  
3 k1 s. j' T4 N5 y; ]      ModSecurityConfig modsecurity.conf;
& b# g( o; A6 o% K* P& k: D  Y$ O6 ?6 U/ o3 Y1 @/ V
      root /web/wordpress;" q0 Y: p/ T7 p7 Q8 `4 Z
      index index.php index.html index.htm;1 P# ?3 ?& A" r' S+ b1 P; M
  8 e6 J5 h, W9 M* d0 N6 }3 A5 H( h
      fastcgi_pass   127.0.0.1:9000;& t6 I3 k% f" A6 d3 p$ c2 ~
      fastcgi_index  index.php;
" n. O1 G$ ~& [0 W( Y      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;; N8 O5 x0 I# K5 ~) u7 u: _" }9 v
      include        fastcgi_params;) R4 J1 ?' V" @; Z6 T' ?! F
      }9 o6 A& g5 B7 g$ X) R! V
  }
9 p) o1 n0 d  \" ?upstream负载均衡:
" f- K- u( l9 b0 M8 W! @7 b# V
) c4 w+ _& l1 Bupstream 52os.net {
+ V9 ?' {' I. j5 w) F8 p, Y    server 192.168.1.100:8080;
! a; D/ L3 e4 d9 i8 H: h) y    server 192.168.1.101:8080 backup;- ?; F5 z9 j/ K/ C1 i" o
}1 e: s5 F# D& j5 \
' C4 q) l5 J* Y$ `9 l0 ?
server {
2 m( D8 m/ E; p# _+ N  Elisten 80;- J$ R8 I% z& j1 O; I0 j: V/ @
server_name 52os.net www.52os.net;- q, E' c( ~) @

: C4 \8 f$ ]  X) Q7 ]6 W# _4 Tlocation / {
5 |" P( u/ M1 V3 o  z4 @- E3 a    ModSecurityEnabled on;  * f6 E8 [* g2 ]0 K8 N) W9 W
    ModSecurityConfig modsecurity.conf;  0 I" ]+ h! p- L" y# G

) @% X1 ]' ~: G7 [        proxy_pass http://online;" Y9 V( p2 `2 N/ N$ c, z5 h
        proxy_redirect         off;
1 K8 t; t0 i6 X8 \" @4 F        proxy_set_header Host $host;
6 c6 L9 M0 f/ J% s) L% a        proxy_set_header X-Real-IP $remote_addr;
: y) E3 Q2 I% y; J6 f- \- e6 u        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;9 A( D; L& _. j; _; U' F4 C$ X6 N
    }
% C3 W3 R, \. c7 n0 r- x& y}$ n8 F5 z0 a+ z; z, Q. v8 Y
六.测试
8 S( d* l+ n! L$ t; g# a( S# S# [1 D
我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:- r( Z* S7 r8 W* {7 r
) s  A5 o; ~$ d5 ~% o
<?php) \: x1 b1 x1 L
    phpinfo();   
& r" t% c0 L0 t" G4 K7 P?>; J& U. j! \! q6 {7 J/ x1 `: Q
在浏览器中访问:& I6 i5 C3 [/ ^" Z) C

. |3 H2 r/ }! C5 j4 Ghttp://www.52os.net/phpinfo.php?id=1 正常显示。; Y' ]) x' v2 P6 {! A4 _" m9 j  T
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。; i. X: e$ j" Z
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。& E$ {* H2 p0 n3 ~2 ?2 t# A) C2 O  O
说明sql注入和xss已经被过滤了, }/ u3 x* M. X/ n- K

: A) V+ v* I- o七、安装过程中排错
0 p, Q: ?: C1 G' p9 ^" D# r; L$ J' i1 G
1.缺少APXS会报错& F. |# l4 k0 r( T' c
% R6 t% S! l! x* c0 }
configure: looking for Apache module support via DSO through APXS
3 c% i* i9 S9 J  h) _0 econfigure: error: couldn't find APXS7 E" ?! Q$ X7 e8 e& R) C2 h& q
apxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。8 T- u6 S- @3 A) u5 A- p" w. o
解决方法:
: k' `" e; `8 E6 h7 a' M" K
9 U5 e6 B) k( _yum install httpd-devel
/ a3 k5 |3 O7 G; H2.没有pcre
5 Y2 [1 |) ^3 [8 k
) I6 s1 G4 _0 z# l3 a' Q; |configure: *** pcre library not found.
" N! z& K. H! R7 L  _- u" |6 Mconfigure: error: pcre library is required
: S3 n: f7 P: }3 U& s解决方法:  M& N9 k( N) n" N  O  F
4 o; n1 B) t" T3 \, r) ~$ x
yum install pcre pcre-devel
/ X3 [$ ]& C$ g# v; O7 u2 M' B7 u' j3.没有libxml2
" U/ e& y4 B+ ^/ S6 C$ F- n! A1 v* V2 ?8 \5 e& X+ ]4 t# H

6 X4 V; Z6 T# z  yconfigure: *** xml library not found." x3 K. z7 W* \
configure: error: libxml2 is required8 I! l- U9 A/ E! G3 T) h9 P5 ~+ I3 M7 g
解决方法:- A/ v5 M0 Y) W, a
  _6 t! c8 r# Y3 I
yum install  libxml2 libxml2-devel
. A: C  u+ N! \% v6 |4.执行 /opt/tengine/sbin/nginx -m 时有警告
8 r& U3 s$ @) t. d4 M# q6 q1 V& L' X5 ~9 b) }
Tengine version: Tengine/2.1.0 (nginx/1.6.2)" T5 f. t- c9 e* f! z
nginx: [warn] ModSecurity: Loaded APR do not match with compiled!9 i2 ~, L& ^& _+ F
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log5 {' C8 r4 _% O( @5 X0 O' k% k

$ b  H/ ]: t1 B0 v2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.8 [/ Z( M0 R5 f5 x
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"
% ?, }( t% @& p/ f2 v; h2 d2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!* x; w. M4 z* X0 Y; W
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"7 O) `8 f, B8 P0 Q
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"
% A) a6 }+ {% w: v" T+ @2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
, T/ j2 c; m$ s0 \, J解决方法,移除低版本的APR (1.3.9)
  X- \; p; X7 t
7 p9 @$ T" ]0 gyum remove apr
; C$ n* i- h; P# ~9 H( c3 v# E% a5.Error.log中有: Audit log: Failed to lock global mutex6 u+ B$ |4 a! I* a6 A

9 b. a) L% d. m- Y  j, C2 W* \# i2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     4 X8 B2 J' p+ \, c
global mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
; ^' @+ @- r  v$ k& n/ \. B9 x/ L2 {解决方法:% [2 F  R4 q+ k: J; [) g
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:. _) U4 S' X8 c+ N

9 l+ H. w1 n8 H4 ?, h6 GSecAuditLogDirMode 0777) a4 F+ X0 W& x+ K3 X# X& ^  C; @
SecAuditLogFileMode 0550
7 q7 \( k" e9 x) i- n' I# rSecAuditLogStorageDir /var/log/modsecurity
9 H- v: r4 o8 d4 h2 QSecAuditLogType Concurrent
# O( |% Z( X% P' D  [" Y参考文章:
* |1 R3 {4 U% ohttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX6 m- f- z2 a0 t% n7 s
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-11 12:33 , Processed in 0.069434 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表