找回密码
 立即注册

QQ登录

只需一步,快速开始

查看: 12765|回复: 0

nginx配合modsecurity实现WAF功能

[复制链接]
发表于 2017-10-19 16:53:31 | 显示全部楼层 |阅读模式
modsecurity原本是Apache上的一款开源waf,可以有效的增强web安全性,目前已经支持nginx和IIS,配合nginx的灵活和高效,可以打造成生产级的WAF,是保护和审核web安全的利器。
* Y1 J3 b, y6 e1 q1 l! y5 _; ^) q4 Z' ]3 y( `4 K" u
一.准备工作* d+ a* Y+ i- z+ E5 p) ]' W

; c% v' @( |6 n& C5 d$ a3 s* k7 P系统:centos 6.5 64位、 tengine 2.1.0, modsecurity 2.8.0
  w" e  {- R1 Y- N3 N; Y8 y( G% N; x* c: [  g6 \& Y
tengine : http://tengine.taobao.org/download/tengine-2.1.0.tar.gz
1 K/ N- Y$ s; A- D4 J$ h6 x2 ~4 T9 B4 i5 h7 v3 p7 A6 l
modsecurity for Nginx: https://www.modsecurity.org/tarball/2.8.0/modsecurity-2.8.0.tar.gz
+ E, [+ t1 w9 Z4 g, ?7 i
7 O; ~- U! Y) H1 @) _# r5 N& vOWASP规则集: https://github.com/SpiderLabs/owasp-modsecurity-crs: {; ?2 t1 c5 C+ P+ O: @% t
! B2 m% r* X0 J0 t* v, L+ Q
依赖关系:
* J  c* S" A- q; m* ?' f: ztengine(nginx)依赖: pcre 、zlib、 openssl, 这三个包centos 6.5 系统源里都有:
' V& [7 l" }2 I0 F+ l3 p. L( W* _  h4 Q& A$ L+ `$ H. L
yum install zlib zlib-devel openssl openssl-devel  pcre pcre-devel6 ], T! H: d/ ~
modsecurty依赖的包:pcre httpd-devel libxml2 apr
3 x" ^. U  S) N  v- w  X$ @# k
4 c8 P) K( l7 q2 E6 A3 H" Syum install httpd-devel apr apr-util-devel apr-devel  pcre pcre-devel  libxml2 libxml2-devel: H7 I8 w# H9 q4 {; I' u) r
二.启用standalone模块并编译
  I# _2 k+ O8 M  y) O  y) [" [+ w
下载modsecurity for nginx 解压,进入解压后目录执行:
! I2 f. k+ M8 f9 d- z! h0 ?: t6 G* E  R9 q
./autogen.sh
& L3 o2 A/ u: ]2 s./configure --enable-standalone-module --disable-mlogc
# b' m5 C4 q4 Omake / U4 r* A. x! T& G  o) p
三.nginx添加modsecurity模块. V  N6 e% i2 G- P0 E. r: [

! k* Z: e! ^9 N# J, y! G% R在编译standalone后,nginx编译时可以通过"--add-module"添加modsecurity模块:
5 n- |8 a! K6 @7 k0 M! g% Q6 M2 N) k1 c9 M: h
./configure --add-module=/root/modsecurity-2.8.0/nginx/modsecurity/  --prefix=/opt/tengine
  p5 I. q. Z: L9 H- K, Nmake && make install
7 H$ z% d/ s7 i9 M四.添加规则
# v2 O! g* o( a. l/ j- {% \1 I4 S* L7 g( P
modsecurity倾向于过滤和阻止web危险,之所以强大就在于规则,OWASP提供的规则是于社区志愿者维护的,被称为核心规则CRS(corerules),规则可靠强大,当然也可以自定义规则来满足各种需求。
5 p$ c; i. d0 i! }# l, `6 h
3 A5 D1 |5 X3 Q6 }, D* q5 b1.下载OWASP规则:% p0 H3 C1 \" A, R
* g" M: b2 C! ~6 G$ k) q
git clone https://github.com/SpiderLabs/owasp-modsecurity-crs
, K' C4 ^! O2 }5 V6 e- d' Z' a; }2 P7 |* A+ `
mv owasp-modsecurity-crs /opt/tengine/conf/
3 v" D0 v5 s8 s( f' r
. k# b' |# H, V$ ncd /opt/tengine/conf/owasp-modsecurity-crs && mv modsecurity_crs_10_setup.conf.example modsecurity_crs_10_setup.conf8 Q6 H5 x! k3 X! t- ]
2.启用OWASP规则:
4 @' \( y  ^4 X& z/ j9 p- P4 X% r  U/ A+ M, l
复制modsecurity源码目录下的modsecurity.conf-recommended和unicode.mapping到nginx的conf目录下,并将modsecurity.conf-recommended重新命名为modsecurity.conf。
0 l( D* L3 s& y2 s( g) H; B4 P0 y1 O7 ]& |  Z% _4 f
编辑modsecurity.conf 文件,将SecRuleEngine设置为 on) ]$ ~: h* m  \5 H: }" }* _
1 s0 ^& r8 D/ I4 l1 g$ ^& W
owasp-modsecurity-crs下有很多存放规则的文件夹,例如base_rules、experimental_rules、optional_rules、slr_rules,里面的规则按需要启用,需要启用的规则使用Include进来即可。
6 I9 N- }9 o& i
# a, ^& k) a( S* DInclude owasp-modsecurity-crs/modsecurity_crs_10_setup.conf
, T" M/ f4 X: d! uInclude owasp-modsecurity-crs/base_rules/modsecurity_crs_41_sql_injection_attacks.conf! W' V0 @) L7 E; q5 U& [/ {
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_41_xss_attacks.conf2 D# O* ?! J; Z5 c5 l1 p# k3 b
Include owasp-modsecurity-crs/base_rules/modsecurity_crs_40_generic_attacks.conf9 U; U8 F& b4 M$ B% W1 F. _& q0 i* z
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_dos_protection.conf6 t5 c/ |- V/ T5 \
Include owasp-modsecurity-crs/experimental_rules/modsecurity_crs_11_brute_force.conf/ d3 g9 Q5 o: X* n
Include owasp-modsecurity-crs/optional_rules/modsecurity_crs_16_session_hijacking.conf: Q. u' S& ]" @8 S# D3 h
五.配置nginx5 }4 r0 X7 ]2 g! S% P5 S0 l

8 T2 W5 ]; u5 o$ U3 N在需要启用modsecurity的主机的location下面加入下面两行即可:
1 ~. [9 T, X5 h; w8 w$ V* A( _& I$ I" X7 i7 D
ModSecurityEnabled on;  
! ?! j4 z# H7 D6 E# _" EModSecurityConfig modsecurity.conf;
7 F7 Z# P4 y+ |2 i2 ^下面是两个示例配置,php虚拟主机:$ b! Z: S3 m: l- y5 }  ~( L
: A) C/ u! e4 j7 w' \
server {: L9 }& q  G/ ~3 `8 e+ @
      listen      80;3 p6 }- i; D/ L* y0 H9 y
      server_name 52os.net www.52os.net;4 }" `& }3 I- w3 n& M- ]
     
: ]1 q( V6 }; U+ ^: o      location ~ \.php$ {; z- G. _1 B* P" d2 P6 t
      ModSecurityEnabled on;  ( R* q3 {1 _5 ?) e
      ModSecurityConfig modsecurity.conf;
( P; u2 e' R; z( R9 v# K; C* }$ o$ `; u& f5 U+ V
      root /web/wordpress;
8 E/ _; E6 {$ b$ A3 G% A& D/ P5 c      index index.php index.html index.htm;8 H: a4 ^% L$ k+ L) ~) s7 O
  
* r) l# h! v$ ?' `* s! ~      fastcgi_pass   127.0.0.1:9000;1 C. t4 O' ?  d- w# q
      fastcgi_index  index.php;
5 U+ R, U) Y1 g+ x* a      fastcgi_param  SCRIPT_FILENAME  $Document_root$fastcgi_script_name;
8 A0 r. t* [: w% Q. Z      include        fastcgi_params;
' }9 s: W$ j$ O. J      }
0 E. q2 Z# N+ H- W' u& z- @- @  }5 i4 m3 _( k4 t$ Z2 G; [6 H0 E" L/ m( Z9 `
upstream负载均衡:; Z* J1 f/ u9 e1 F
, i2 ?# p+ j  p  {, P, K
upstream 52os.net {1 R9 [+ b- V0 m1 ^7 S
    server 192.168.1.100:8080;
: b8 ~! L0 O4 a    server 192.168.1.101:8080 backup;
! W7 F7 b% r& w8 s3 O% c. P& K}
0 z1 N  l, \4 o' }7 p* ~! y& \5 Z# p/ y* c4 ]* u
server {
; L% m& G) ]1 V% [; r& Q( Ulisten 80;
% g. J& A& B) v; a/ L7 H: m8 rserver_name 52os.net www.52os.net;
& ?$ `* Z: |6 w" w# x& H' X
! A7 \/ l5 V+ {6 Elocation / {
- f9 \: H) h1 _% m    ModSecurityEnabled on;  % ^6 K; C1 ^. N. c! F, k
    ModSecurityConfig modsecurity.conf;  2 _6 e0 W. \6 e9 Z' {; i9 A

6 q) z0 b) ~7 S1 n( s        proxy_pass http://online;6 s  x# J% h( c
        proxy_redirect         off;1 t# }# }8 Z- F) G/ \8 g
        proxy_set_header Host $host;+ R( P' _, R3 H. J2 I
        proxy_set_header X-Real-IP $remote_addr;- x7 j- }" Z$ z( H% F% c% u9 j
        proxy_set_header  X-Forwarded-For $proxy_add_x_forwarded_for;
2 I; O- S, c% b6 [" j. J7 Z    }
- Z# C- ~) j) x$ h}
, L% r, n/ m5 G1 g1 q5 D六.测试
& Z, c6 _( X. }) u, R
& A# J9 q3 q8 J) Z% L, ~我们启用了xss和sql注入的过滤,不正常的请求会直接返回403。以php环境为例,新建一个phpinfo.php内容为:
$ w2 ^1 j# W& f, g! f5 q- V; N& ^* @7 Y$ x. ?
<?php
3 H4 H' e) v! C4 x    phpinfo();    6 y: R# Q& {* @4 d2 N) p8 i
?>, t5 D. ~( c# x/ L( c# g3 J* x
在浏览器中访问:
: y" `& R* r0 X* V
3 j4 n% N; A4 |  A# l* ]. S9 o9 ehttp://www.52os.net/phpinfo.php?id=1 正常显示。" G8 B. w. m- W0 U" s) p
http://www.52os.net/phpinfo.php?id=1 and 1=1  返回403。9 u* |4 Z# X0 O* _/ q
http://www.52os.net/phpinfo.php?search=<scritp>alert('xss');</script>  返回403。, i1 D+ d, Q0 v" K8 N# P
说明sql注入和xss已经被过滤了
! k* z% u  x  ^  @& N; ?+ H* `$ O4 z- }; Q" D( g
七、安装过程中排错
) q, ~! M/ w8 W- I3 X3 f$ y: \* d" f( g* i8 T  X
1.缺少APXS会报错
7 q! j( |! d& e3 \' z0 }' Z, x% H8 a9 S7 f" v. D* I8 D
configure: looking for Apache module support via DSO through APXS  o: h' b/ Q& `6 K
configure: error: couldn't find APXS
/ r8 I0 y) I% Z) Sapxs是一个为Apache HTTP服务器编译和安装扩展模块的工具,用于编译一个或多个源程序或目标代码文件为动态共享对象。- [: L/ c- n7 E4 i  o; A! J' N
解决方法:, k1 W$ n( H& L+ c- \6 b
6 X% W& v& {( L  p; t& w5 _4 ?
yum install httpd-devel' u# {) u6 ~) r; ?/ B
2.没有pcre. b0 ^+ j% V" ?5 N* k

7 C0 b$ P' W1 E- q) i3 n2 Iconfigure: *** pcre library not found.
( X7 C' v  y! O$ w* C/ b9 lconfigure: error: pcre library is required4 u! |1 e* G) p
解决方法:
' b: y  B; l6 t* @! M. G! Z4 H5 Q' m, X( i* e, _/ V
yum install pcre pcre-devel
) S' j* w; r* k1 M2 `3.没有libxml20 V$ `7 R' G% H* ~, ]. T
2 @" X& [) z8 D  d2 x+ C

' f/ }% N& V' t- Z  m/ T' \configure: *** xml library not found.! U5 K7 n' Z" \3 l; i7 f, D
configure: error: libxml2 is required: p1 V/ Q. |% Z3 T
解决方法:
. a) R' I- I9 Q: ~% h$ p. t- g/ G7 s9 G2 i" w7 X
yum install  libxml2 libxml2-devel. e) {0 ^, G8 H* V. t+ [4 y
4.执行 /opt/tengine/sbin/nginx -m 时有警告
! b# s; Z. w/ f- R5 e. R- a
/ M$ V- }* v. u) T6 ~Tengine version: Tengine/2.1.0 (nginx/1.6.2)
5 ]: O9 ]& R* [7 C( O, }4 @2 y' enginx: [warn] ModSecurity: Loaded APR do not match with compiled!& {; f3 \  [5 R( [4 D$ r- _% A
原因:modsecurity编译时和加载时的apr版本不一致造成的,并且会有以下error.log2 Y# ?8 H) m: X) Q$ V# N8 a

% Q( K% S- V- N$ t2015/01/26 02:04:18 [notice] 29036#0: ModSecurity for nginx (STABLE)/2.8.0 () configured.' k$ i: f1 ?7 n9 J; l0 B5 X. i5 y1 z: U
2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: APR compiled version="1.5.0"; loaded     version="1.3.9"( ]6 p# ?& K: D& Q3 w& e+ }. k$ J
2015/01/26 02:04:18 [warn] 29036#0: ModSecurity: Loaded APR do not match with compiled!
: U* b9 \$ |& z7 p& e2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: PCRE compiled version="7.8 "; loaded version="7.8 2008-09-05"
$ `+ X( }1 _. j' f& O7 q' ^2015/01/26 02:04:18 [notice] 29036#0: ModSecurity: LIBXML compiled version="2.7.6"  y( k) k& D& J, z' Z
2015/01/26 02:04:18 [notice] 29036#0: Status engine is currently disabled, enable it by set SecStatusEngine to On.
- W: B, g* ^/ A) ]  A9 M解决方法,移除低版本的APR (1.3.9)
* E; g. h0 n$ N, t  v9 x7 C
) o' K7 w1 I* c, c. tyum remove apr1 b; M/ l5 h6 s3 l
5.Error.log中有: Audit log: Failed to lock global mutex) |; [5 A5 l+ m* u0 f2 a+ k

+ R) {' G& r/ f7 T. ^2015/01/26 04:15:42 [error] 61610#0: [client 10.11.15.161] ModSecurity: Audit log: Failed to lock     
* g* q8 j) o7 b$ r3 rglobal mutex: Permission denied [hostname ""] [uri "/i.php"] [unique_id "AcAcAcAcAcAcAcA4DcA7AcAc"]
1 `: m* |$ k7 D) u: J$ L6 v2 V解决方法:$ X8 F/ v7 i/ }, [) N
编辑modsecurity.conf,注释掉默认的SecAuditLogType和SecAuditLog,添加以下内容:
" X  f, `7 |; m
, v' s8 h! l7 J5 G; J( i  gSecAuditLogDirMode 0777: L$ X! A' f1 z' Q5 M0 u
SecAuditLogFileMode 0550/ g% }. r7 |* I* Y
SecAuditLogStorageDir /var/log/modsecurity
; l3 b, `3 M6 |9 X; N: b. aSecAuditLogType Concurrent
( O8 a3 D8 Z7 O9 ^参考文章:
" y6 a8 `0 M" r" @, p  khttps://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual#Installation_for_NGINX# P9 J& R. ~9 L  d; h) H
http://drops.wooyun.org/tips/2614
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

QQ|Archiver|手机版|小黑屋|第一站论坛 ( 蜀ICP备06004864号-6 )

GMT+8, 2026-10-9 08:29 , Processed in 0.069673 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表